Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add RBraga01/Quality-Engineering-Skills --skill supplier-scargit clone --depth 1 https://github.com/RBraga01/Quality-Engineering-SkillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rbraga01/quality-engineering-skills/supplier-scar)<a href="https://agentmods.dev/skills/rbraga01/quality-engineering-skills/supplier-scar"><img src="https://agentmods.dev/badge/skills/rbraga01/quality-engineering-skills/supplier-scar/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/rbraga01/quality-engineering-skills/supplier-scar"><img src="https://agentmods.dev/badge/skills/rbraga01/quality-engineering-skills/supplier-scar.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00099 | $0.02469 |
| Opus 5 | $0.00049 | $0.01234 |
| Sonnet 5 | $0.00020 | $0.00494 |
| Haiku 4.5 | $0.00010 | $0.00247 |
Grade A, and why
supplier-scar scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 232 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Supplier Corrective Action Request (SCAR)
When to use
Use this skill when:
- A supplier NCR requires a formal corrective action (beyond simple return/replacement)
- A supplier has delivered the same non-conformance twice or more
- A non-conformance has caused a production line stoppage, customer complaint, or field failure
- A supplier's quality performance score falls below the defined threshold
- An OEM customer issues a concern that is traced to a sub-supplier
- Preparing a SCAR, evaluating a supplier's 8D response, or conducting an effectiveness review
Prerequisites
- Non-conformance documented (NCR or equivalent) with: part number, description, quantity, measured evidence
- Supplier code, contact name, and corrective action coordinator identified
- SCAR response timeline agreed (typically 24h for D3, 30 days for full 8D)
- Historical data: previous SCARs, PPM trend, quality score for this supplier
Workflow
Step 1 — Escalation criteria: when does an NCR become a SCAR?
Issue a SCAR when any of the following conditions are met:
| Trigger | Description |
|---|---|
| Severity — Critical | Non-conformance affects safety, regulatory compliance, or field function |
| Severity — Customer impact | Non-conformance reached the end customer or caused a production line stop |
| Recurrence | Same defect or same part rejected for the second time within 12 months |
| Volume | Rejection of an entire lot or >5% of a delivery |
| Systemic risk | Evidence that the supplier's process or system is inadequate (missing controls, no inspection, operator error on SC characteristic) |
| Customer escalation | An OEM customer has issued a concern traceable to this supplier |
Do NOT issue a SCAR for every NCR — use NCR + return for minor first-occurrence issues and reserve SCAR for systemic or high-risk situations.
Step 2 — Write the SCAR
The SCAR document must contain:
Header:
- SCAR number (unique, traceable)
- Date issued
- Supplier name, supplier code, contact person
- Issued by (supplier quality engineer name)
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 232 lines · 99 tokens per session scan A dbab37446da7
supplier-scar is a skill published in the GitHub repository RBraga01/Quality-Engineering-Skills (28 stars, last pushed 2d ago), licensed MIT. It adds 99 tokens to every session and 2,469 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
aqe-ruflo
Add optional Ruflo development-time orchestration to an Agentic QE workflow. Use when a task benefits from coordinated swarms, persistent cross-session memory, routing, or Ruflo hooks. Do not use for a one-shot edit, and never add Ruflo to shipped AQE runtime dependencies.
aqe-plan-work
Build dependency-aware execution plans for complex Agentic QE, Ruflo, integration, migration, or multi-stream engineering programs. Use when Codex must turn research or requirements into phased work, select a small AQE fleet, map critical paths and parallel streams, define acceptance gates, or sequence risky changes.…
aqe-research
Conduct evidence-first technical research for Agentic QE, Ruflo, related ruvnet projects, or external tools. Use when Codex must investigate a repository, compare current upstream changes, trace dependencies and history, distinguish verified facts from inference, or synthesize findings into actionable engineering…
aqe-plan-quality
Create risk-based quality and test plans for Agentic QE changes. Use when scoping a feature, translating requirements into verification work, selecting QE specialties, assessing testability, or deciding which .claude/agents/v3/qe-.md capabilities should inform a task. Do not use merely to execute an already-defined…
aqe-test-change
Design, implement, and run durable tests for Agentic QE code changes. Use when adding tests, reproducing a defect, filling a coverage gap, selecting affected Vitest suites, checking CLI/MCP parity, or verifying a fix in this repository. Do not use for a read-only quality review with no requested edits.
aqe-review-quality
Review Agentic QE changes and issue an evidence-backed quality verdict. Use for code review, regression-risk assessment, release readiness, quality-gate evaluation, security/performance/testability review, or checking whether a change has sufficient verification. Do not use when the user primarily asks to implement a…