Agent skill

Quality Nonconformance

by diegosouzapw in diegosouzapw/awesome-omni-skills

Quality & Non-Conformance Management workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

MITAuto-check passedDevelopment

Install Quality Nonconformance

skills CLI
$ npx skills add diegosouzapw/awesome-omni-skills --skill quality-nonconformance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install diegosouzapw/awesome-omni-skills quality-nonconformance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/diegosouzapw/awesome-omni-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills_omni/quality-nonconformance .claude/skills/quality-nonconformance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
quality-nonconformance
GitHub stars
159
Token cost
~3.9k tokens
SKILL.md length
1,728 words
Files
21 (incl. scripts, references, assets)
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Quality & Non-Conformance Management workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

  • Works in 8 steps: Establish the review frame → Control the nonconformance before… → Triage risk and decide investigation depth → …
  • The user needs codified expertise for quality control
  • SKILL.md covers Overview, When to Use This Skill, Operating Table and Workflow, plus 4 more sections
  • Nonconformance investigation

What it does

Quality Nonconformance is an agent skill from diegosouzapw/awesome-omni-skills. Quality & Non-Conformance Management workflow skill. Use this skill when the user needs codified expertise for quality control, nonconformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing, with clear review criteria, evidence expectations, and provenance-aware handoff discipline.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 24 other files, including scripts, reference files and assets (for example `ATTRIBUTION.md`, `OMNI_ENHANCED.json` and `ORIGIN.md`).

It sits in Development, covering Root cause analysis. The repository describes itself as: Public repository of AI coding skills, curated improved best-practice skills, and runtime surfaces for CLI, API, MCP, and A2A. The licence is MIT.

When your agent uses it

  • The user needs codified expertise for quality control
  • Nonconformance investigation
  • Root cause analysis
  • Corrective action

Example prompts

  • “/quality-nonconformance”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Establish the review frame
  2. Control the nonconformance before investigating cause
  3. Triage risk and decide investigation depth
  4. Investigate cause using evidence, not just narrative
  5. Decide NCR only vs CAPA escalation
  6. Review supplier implications explicitly
  7. Define corrective action and verification expectations
  8. Judge closure quality

What it can do on your machine

Read from SKILL.md and the folder at commit c3af004. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • ecfr.gov
    • fda.gov
    • database.ich.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Quality Nonconformance loads about 3.9k tokens when it runs, and up to ~44k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 1,728 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~44k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from diegosouzapw/awesome-omni-skills at commit c3af004, republished under its MIT licence (© diegosouzapw). 1,728 words, ~3,902 tokens.

Download SKILL.mdSave it as .claude/skills/quality-nonconformance/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.
name
quality-nonconformance
description
Quality & Non-Conformance Management workflow skill. Use this skill when the user needs codified expertise for quality control, nonconformance investigation, root cause analysis, corrective action, and supplier quality management in regulated manufacturing, with clear review criteria, evidence expectations, and provenance-aware handoff discipline.
version
0.0.1
category
development
tags
quality-nonconformance, quality, nonconformance, capa, root-cause, supplier-quality, regulated-manufacturing, omni-enhanced
complexity
advanced
risk
caution
tools
codex-cli, claude-code, cursor, gemini-cli, opencode
source
omni-team
author
Omni Skills Team
date_added
2026-04-15
date_updated
2026-04-19

Quality & Non-Conformance Management

Overview

Use this skill to review, structure, or improve nonconformance handling in regulated manufacturing environments where product disposition, investigation quality, CAPA escalation, supplier controls, and closure evidence matter.

This skill is designed for analysis and review work, not for issuing legal or regulatory sign-off. It helps the operator:

  • distinguish immediate containment from deeper investigation
  • decide whether an issue should remain an NCR/nonconformance or escalate to CAPA
  • assess whether supplier escalation is required
  • judge whether a closure package is evidence-based or too weak to accept
  • preserve provenance and decision rationale before merge, handoff, or audit preparation

The workflow is intentionally risk-based. It should be applied only after identifying the governing quality framework for the record under review.

When to Use This Skill

Use this skill when the task involves one or more of the following:

  • reviewing a nonconforming product event, deviation, NCR, or MRB packet
  • deciding whether a case needs containment only, formal investigation, CAPA escalation, supplier action, or reopening
  • checking whether root-cause claims are supported by objective evidence
  • evaluating whether repeated defects indicate a broader process, validation, measurement, or supplier-control problem
  • assessing closure quality for CAPA, SCAR, rework, concession, or deviation records
  • preparing a review packet for quality leadership, audit response, or cross-functional handoff

Do not use this skill as a substitute for:

  • legal advice
  • formal regulatory reporting decisions that require authorized personnel
  • product release authority
  • changing approved procedures without controlled change management

Before using detailed criteria, identify the applicable regime, for example:

  • FDA medical device / QMSR-harmonized device context
  • pharma or biopharma quality system using ICH / GxP expectations
  • aerospace, automotive, or internal QMS controls
  • internal quality review with no direct regulated submission impact

If the governing framework is unknown, stop and ask for it before prescribing record content or closure standards.

Operating Table

SituationStart hereWhy it matters
New case intakeConfirm product, lot/serial scope, location, release status, and distribution statusYou cannot judge severity, containment, or reporting impact without scope
Regulated reviewIdentify governing regime, risk class, market status, and who owns release/disposition authorityTerms and evidence expectations differ by context
Suspect nonconforming productSeparate containment and disposition from root-cause workTeams often jump to RCA before securing inventory or documenting control
Recurrent or high-risk issueCheck trend history, complaints, prior NCRs, prior CAPAs, validation status, and detectability weaknessRecurrence often means the problem is systemic, not isolated
Supplier-linked eventCheck supplier status, item criticality, inspection history, prior SCARs, and quality agreement referencesSupplier events may require more than return-to-vendor handling
Weak investigationTest whether evidence supports the claimed root cause, or only a plausible storyPremature closure is a common failure mode
Closure reviewUse references/review-criteria.mdProvides decision criteria for NCR vs CAPA vs supplier escalation vs reopen
Training or audit prepUse examples/review-example.mdShows a realistic NCR-to-CAPA review with weak vs acceptable closure logic

Workflow

1) Establish the review frame

Start by collecting the minimum context needed to make a safe judgment:

  • product or process affected
  • lot, batch, serial, or unit scope
  • where affected material is now located
  • whether any product was released or distributed
  • detection point: incoming, in-process, final release, complaint, service, audit, or stability/monitoring
  • applicable quality system or regulatory context
  • assigned record owner and disposition authority

If any of these are missing, call out the gap before concluding anything.

2) Control the nonconformance before investigating cause

Treat containment and disposition as a distinct stage.

Check whether the record shows:

  • identification of affected material or records
  • segregation or administrative control where practical
  • hold status and access restriction
  • preliminary scope assessment
  • documented disposition path or hold-for-investigation status
  • rework or reinspection requirements if applicable
  • authorized approval for the chosen disposition under local procedure

Common disposition paths include:

  • use as is
  • rework
  • repair
  • return to supplier
  • scrap
  • concession or deviation
  • hold for investigation

Do not accept a packet that explains root cause in detail but cannot clearly show what happened to the affected product.

If product has already shipped, add review of traceability, customer impact, field status, and whether separate reporting or market action processes must be considered by authorized personnel.

3) Triage risk and decide investigation depth

Scale the investigation to risk rather than applying the same depth everywhere.

Review at least these factors:

  • severity of potential impact
  • occurrence or recurrence pattern
  • detectability and control weakness
  • distribution status
  • complaint, adverse event, or reportability linkage
  • multi-lot, multi-line, or multi-site scope
  • confidence in the available data

Also test for bias:

  • blaming operator error before checking system factors
  • blaming the supplier before checking incoming controls and specifications
  • accepting the first plausible cause without ranking evidence
  • closing because action was completed, not because effectiveness was demonstrated

Document why the chosen level of investigation is proportionate.

4) Investigate cause using evidence, not just narrative

A good investigation distinguishes:

  • symptom: what failed
  • containment: how exposure was controlled
  • direct cause: what immediately produced the event
  • root cause: why the system allowed it
  • contributing factors: conditions that increased likelihood or reduced detection

Minimum evidence checks:

  • compare actual records, not recollections alone
  • review recent trend data and prior similar events
  • check change history, maintenance, calibration, setup, tooling, and environment where relevant
  • review inspection method adequacy and measurement-system confidence
  • for supplier events, review specifications, quality agreements, inspection plans, and supplier change visibility
  • for repeated process defects, review process validation or continued process verification evidence instead of defaulting to retraining

Be cautious with conclusions such as "operator error," "supplier issue," or "isolated incident" unless corroborated by records.

5) Decide NCR only vs CAPA escalation

Not every NCR requires CAPA, but some should not remain local.

Typical escalation triggers include:

  • recurrence after prior correction
  • high-severity or patient/customer safety impact
  • distributed product or complaint linkage
  • evidence of broader process or system failure
  • validation failure or loss of validated state
  • repeated supplier escapes or ineffective SCAR history
  • multi-lot or multi-line impact
  • poor detectability suggesting controls are weak
  • prior closure later shown to be ineffective

If one or more of these are present, require a clear rationale if the issue is not escalated.

Use references/review-criteria.md when you need a compact decision aid during live review.

Show full SKILL.md (722 more words)Show less
6) Review supplier implications explicitly

When a nonconformance involves purchased material, outsourced processing, or supplier-provided services, check more than the defect itself.

Review whether the packet addresses:

  • approved supplier status
  • criticality of the supplied item or service
  • quality agreement or communicated specification clarity
  • incoming acceptance method and whether it was capable of detection
  • supplier history and prior SCARs
  • whether the issue indicates supplier qualification, oversight, or change-notification weakness

A supplier-caused defect does not automatically prove supplier-only root cause. Internal receiving controls, specification quality, and escalation timeliness may also be involved.

7) Define corrective action and verification expectations

Corrective actions should match the verified cause and risk.

Weak actions often include:

  • retraining only, without evidence the knowledge gap was primary
  • updating a form without changing the failing control
  • adding inspection where process weakness remains unaddressed
  • closing immediately after implementation with no effectiveness window

Stronger action plans usually specify:

  • what process, control, specification, equipment, supplier control, or workflow will change
  • who owns implementation
  • what records will prove implementation
  • how effectiveness will be measured
  • what time window or production volume will be reviewed
  • what would trigger reopen or further escalation
8) Judge closure quality

Do not accept closure based only on completed tasks.

A credible closure shows:

  • implemented actions match the defined cause and scope
  • impacted documents, training, controls, or supplier requirements were updated as needed
  • verification or validation was completed where required
  • effectiveness was checked over a defined period or sample
  • no significant unintended consequences were introduced
  • management or quality leadership visibility occurred when risk or recurrence justified it

If recurrence occurs after closure, reopen the logic chain:

  • was the root cause truly demonstrated?
  • was containment scope too narrow?
  • was the monitoring window too short?
  • did changes create new failure modes?
  • was the issue systemic but treated as local?

Troubleshooting

The record jumps straight to root cause with poor containment evidence
  • Ask where all suspect inventory, WIP, and released units are.
  • Require product control status before accepting detailed RCA.
  • Check whether affected documentation and traceability records were also controlled.
The investigation concludes "operator error" with no corroboration
  • Ask for objective evidence: training records, work-instruction clarity, human factors, error-proofing status, supervision, and recurrence history.
  • Review process design, tooling, inspection detectability, and workload/context before accepting a person-only explanation.
The same defect recurs after retraining
  • Treat training-only correction as suspect.
  • Review process capability, validation status, setup controls, maintenance, environmental conditions, measurement system, and recent changes.
  • Escalate if recurrence indicates the process is not in a controlled state.
Supplier repeated the same defect after SCAR closure
  • Review supplier qualification, prior similar escapes, process-change visibility, incoming sampling adequacy, and whether the specification was unambiguous.
  • Consider requalification, tighter controls, or supplier status escalation if evidence shows repeated ineffectiveness.
Multiple plausible causes remain open
  • Rank hypotheses by evidence strength.
  • Keep containment active while confidence is low.
  • Prefer targeted data collection over premature closure.
Product was already distributed before detection
  • Expand review to traceability, customer impact, complaint linkage, field status, and whether separate reporting or market action review is required by authorized functions.
  • Do not let the NCR close as a purely internal event if distribution materially changes risk.
CAPA was closed, but the defect returned
  • Recheck whether the issue should have been treated as systemic.
  • Verify effectiveness criteria, monitoring duration, and whether the action changed the actual control point.
  • Review for unintended consequences or incomplete implementation.

Examples

For a worked example of NCR review, CAPA escalation logic, supplier considerations, and weak vs acceptable closure rationale, see:

  • examples/review-example.md

Use the example to compare the packet you are reviewing against a realistic good-enough standard rather than an abstract checklist.

Additional Resources

Use primary sources for final policy interpretation. This skill helps structure review judgment; it does not replace approved procedures or authorized quality/regulatory decisions.

Use a different or additional skill when the work shifts into:

  • complaint handling or post-market surveillance
  • regulatory reporting assessment
  • process validation protocol design or statistical study design
  • supplier qualification or audit program design
  • change control or document-control execution
  • detailed manufacturing process engineering outside the nonconformance workflow

© diegosouzapw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 20 other files (scripts, references, assets) in skills_omni/quality-nonconformance of diegosouzapw/awesome-omni-skills.

  • SKILL.md
  • ATTRIBUTION.md
  • OMNI_ENHANCED.json
  • ORIGIN.md
  • agents/omni-import-router.md
  • assets/omni-import-source-manifest.json
  • examples/omni-import-operator-packet.md
  • examples/omni-import-prompt-template.md
  • examples/review-example.md
  • metadata.json
  • references/communication-templates.md
  • references/decision-frameworks.md
  • references/edge-cases.md
  • references/omni-import-checklist.md
  • references/omni-import-playbook.md
  • references/omni-import-rubric.md
  • references/omni-import-source-summary.md
  • … and 4 more

Open the folder on GitHubat commit c3af004

Compare with similar skills

Quality Nonconformance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Quality Nonconformance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Quality Nonconformance this skilldiegosouzapw/awesome-omni-skills159—~3.9kAutomated safety check: PassMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone
OpenLogi macOS Permissions TriageAprilNEA/OpenLogi23k—~2.5kAutomated safety check: NotesApache-2.0
Bug Finder for daisyUIsaadeghi/daisyui43k—~2.3kAutomated safety check: PassMIT
Root Cause Debugginggarrytan/gstack136k—~1.4kAutomated safety check: PassMIT
Review PRapache/shardingsphere21k—~6.4kAutomated safety check: PassApache-2.0

Similar skills

  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Decides whether an OpenLogi device problem on macOS is a privacy-permission (TCC) problem, using agent log lines, and says which identity needs which grant.

    23k GitHub stars~2.5k tokensUpdated 5 days ago
    DevelopmentAuto-check: notes
  • Bug Finder for daisyUI

    saadeghi/daisyui

    Investigates suspected bugs in the daisyUI monorepo through read-only analysis, then writes a decision-ready fix plan in tmp/bugs without changing any product code.

    43k GitHub stars~2.3k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Review PR

    apache/shardingsphere

    Review Apache ShardingSphere or user-authorized downstream pull requests and PR discussions from public or authorized repository evidence.

    21k GitHub stars~6.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Graph-Based Bug Tracing

    tirth8205/code-review-graph

    Traces a bug through a code knowledge graph, following callers, callees and execution flow before opening source files, within a small token budget.

    32k GitHub starsUsed in 1 repo~287 tokens
    DevelopmentAuto-check passed

More from diegosouzapw/awesome-omni-skills

All 39 skills in this repo
  • Content Creator

    diegosouzapw/awesome-omni-skills

    Content Creator workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4k tokensUpdated 3 mo ago
    Auto-check passed
  • Helm Chart Scaffolding

    diegosouzapw/awesome-omni-skills

    Helm Chart Scaffolding workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Prompt Engineering

    diegosouzapw/awesome-omni-skills

    Prompt Engineering Patterns workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~3.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Prompt Engineering Patterns

    diegosouzapw/awesome-omni-skills

    Prompt Engineering Patterns workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4k tokensUpdated 3 mo ago
    Auto-check passed
  • Prompt Library

    diegosouzapw/awesome-omni-skills

    📝 Prompt Library workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~3.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Protocol Reverse Engineering

    diegosouzapw/awesome-omni-skills

    Protocol Reverse Engineering workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~3.8k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Quality Nonconformance

What does Quality Nonconformance do?

Quality & Non-Conformance Management workflow skill. An agent skill from diegosouzapw/awesome-omni-skills. Quality Nonconformance is an agent skill from diegosouzapw/awesome-omni-skills. Quality & Non-Conformance Management workflow skill.

When should I use Quality Nonconformance?

Quality Nonconformance fits situations like: the user needs codified expertise for quality control; nonconformance investigation; root cause analysis; corrective action.

How do I install Quality Nonconformance in Claude Code?

Run `npx skills add diegosouzapw/awesome-omni-skills --skill quality-nonconformance -a claude-code`. Or copy the skill folder (skills_omni/quality-nonconformance in diegosouzapw/awesome-omni-skills) into .claude/skills/quality-nonconformance in your project. Claude Code loads it when a task matches its description.

How do I install Quality Nonconformance in Codex?

Run `npx skills add diegosouzapw/awesome-omni-skills --skill quality-nonconformance -a codex`. Or copy the skill folder (skills_omni/quality-nonconformance in diegosouzapw/awesome-omni-skills) into .agents/skills/quality-nonconformance in your project. Codex loads it when a task matches its description.

Can I use Quality Nonconformance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add diegosouzapw/awesome-omni-skills --skill quality-nonconformance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/quality-nonconformance, .gemini/skills/quality-nonconformance, .github/skills/quality-nonconformance and .opencode/skills/quality-nonconformance in your project.

What does Quality Nonconformance need to run?

SKILL.md names no scripts, command-line tools or credentials: Quality Nonconformance is instructions for the agent only.

Does Quality Nonconformance access the network?

SKILL.md names 3 domains. As links in the text: ecfr.gov, fda.gov and database.ich.org. This is read from the text; nothing was executed.

Is Quality Nonconformance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Quality Nonconformance use?

Quality Nonconformance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Quality Nonconformance use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 40k tokens, read only when the agent opens those files.

What are the alternatives to Quality Nonconformance?

Skills that share tags, products or a category with Quality Nonconformance: Code Design Rationale Investigator (cursor/plugins, 10k stars), OpenLogi macOS Permissions Triage (AprilNEA/OpenLogi, 23k stars), Bug Finder for daisyUI (saadeghi/daisyui, 43k stars) and Root Cause Debugging (garrytan/gstack, 136k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Quality Nonconformance?

diegosouzapw (a GitHub user) maintains it in diegosouzapw/awesome-omni-skills, which has 159 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on July 8, 2026.

Source: diegosouzapw/awesome-omni-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.