Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add rodolfochicone/rc-project --skill rc-qa-executiongit clone --depth 1 https://github.com/rodolfochicone/rc-projectWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/rodolfochicone/rc-project/rc-qa-execution)<a href="https://agentmods.dev/skills/rodolfochicone/rc-project/rc-qa-execution"><img src="https://agentmods.dev/badge/skills/rodolfochicone/rc-project/rc-qa-execution/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/rodolfochicone/rc-project/rc-qa-execution"><img src="https://agentmods.dev/badge/skills/rodolfochicone/rc-project/rc-qa-execution.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00082 | $0.02725 |
| Opus 5 | $0.00041 | $0.01362 |
| Sonnet 5 | $0.00016 | $0.00545 |
| Haiku 4.5 | $0.00008 | $0.00272 |
Grade A, and why
rc-qa-execution scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
5. When the project has a Web UI surface, start the dev server in the background using the discovered start command. Confirm readiness by waiting for the server to respond (e.g., `curl -sf -o /dev/null http://localhost:< This is a copy
89% identical to qa-execution — 10 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 113 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Systematic Project QA
Required Inputs
- qa-output-path (optional): Directory where QA artifacts (issues, screenshots, verification reports) are stored. When provided, create the directory if it does not exist and use it for all QA outputs. When omitted, fall back to repository conventions or
/tmp/codex-qa-<slug>.
Procedures
Step 1: Discover the Repository QA Contract
- Read root instructions, repository docs, and CI/build files before running commands.
- Execute
python3 scripts/discover-project-contract.py --root .to surface candidate install, verify, build, test, lint, start commands, Web UI signals, and E2E signals. - Read
references/project-signals.mdwhen command ownership is ambiguous or when multiple ecosystems are present. - Read
references/e2e-coverage.mdto decide whether the repository already supports public-surface automated coverage and how strong that support is. - Prefer repository-defined umbrella commands such as
make verify,just verify, or CI entrypoints over language-default commands. - Identify the changed surface and the regression-critical surface before choosing scenarios.
- Determine whether the project has a Web UI surface. Indicators include: a
startordevcommand that launches a web server, framework config files (next.config.*,vite.config.*,nuxt.config.*,angular.json,svelte.config.*), or HTML/template entry points. Record the dev server URL (defaulthttp://localhost:3000unless the project specifies otherwise). - Record the E2E contract in working notes: support detected or not, harness name, canonical command, known spec locations, and blockers.
- Resolve the QA artifact directory. If the user provided a
qa-output-pathargument, use that path. Otherwise, use repository conventions. If neither exists, fall back to/tmp/codex-qa-<slug>. Create theqa/subdirectory under the resolved path if it does not exist. Store all issues, screenshots, and verification reports under<qa-output-path>/qa/.
What ships with it
7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 113 lines · 82 tokens per session scan A 491e0dc128d1
rc-qa-execution is a skill published in the GitHub repository rodolfochicone/rc-project (19 stars, last pushed 1mo ago), licensed MIT. It adds 82 tokens to every session and 2,725 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). It is 89% identical to qa-execution, differing in 10 lines, and is treated as a copy.
Other skills, from other repositories
atf-testing
Build ServiceNow Automated Test Framework tests and suites — impersonation, form steps, assertions, server-side script steps, test parameters, and execution via snowcreateatftest / snowexecuteatftest.
acceptance
A skill for writing, running, and repairing human-written acceptance checks stored in an `acceptance/ACCEPTANCE.md` file. Acceptance checks are executable tests of whether the finished result matches the requested outcome.
rpi-explore-release
Run independent fresh-context exploratory charters against a fixed authorized release candidate, preserving the eight-maneuver safety and evidence contract.
e2e-runner
End-to-end testing specialist using Playwright. Use PROACTIVELY for generating, maintaining, and running E2E tests. Manages test journeys, quarantines flaky tests, uploads artifacts (screenshots, videos, traces), and ensures critical user flows work.
axiom-axe-ref
Use when automating iOS Simulator UI interactions beyond simctl capabilities. Reference for AXe CLI covering accessibility-based tapping, gestures, text input, screenshots, video recording, and UI tree inspection.
playwright-stability
Make a Playwright E2E suite stable and realistic — kill flaky tests and authenticate like a real user via storageState (login once, reuse). Use when E2E tests are flaky, slow, re-login in every test, mock auth instead of using it, or when hardening a suite before relying on it.