Agent skill

Quality Scan

by diegosouzapw in diegosouzapw/OmniRoute

Runs a scoped, read-only quality scan on a repository candidate and reports exact evidence, failures and frozen debt, without treating a static scan as release acceptance.

MITAuto-check passedTesting & QA

Install Quality Scan

skills CLI
$ npx skills add diegosouzapw/OmniRoute --skill quality-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install diegosouzapw/OmniRoute quality-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/diegosouzapw/OmniRoute.git skills-src && mkdir -p .claude/skills && cp -r skills-src/config/quality/skill-templates/quality-scan .claude/skills/quality-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
quality-scan
GitHub stars
74k
Token cost
~748 tokens
SKILL.md length
342 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Runs a scoped, read-only quality scan on a repository candidate and reports exact evidence, failures and frozen debt, without treating a static scan as release acceptance.

  • Sweeping a branch's quality gates before a release
  • SKILL.md covers Choose the scope, Execute and preserve evidence and Report the result
  • Calls npm
  • Reporting which gates ran, failed or were skipped on a candidate commit

What it does

The skill picks a scope first: the default static quality-scan profile, a fast profile that must report which gates it omitted, a single named npm alias, a base status check that inspects remote evidence only, or full release and PR acceptance, which means inspecting the relevant workflow lanes. When present, config/quality/gate-manifest.json defines profile membership and package.json holds the commands. The agent measures the current inventory instead of quoting a remembered count, and on older branches without the manifest it labels the inventory provisional.

It pins the base and candidate SHAs in an isolated worktree, runs the real npm entrypoints, and records the command, working directory, versions, timings, exit status, scope and log path. Missing dependencies, timeouts, cancellation and unavailable artifacts count as incomplete evidence, not a pass. A scan may write logs and reports but does not update baselines, change product code or contact live providers unless that is scoped.

The report names the profile and SHA, the executed, failed and not-run counts, the raw logs and the remaining acceptance lanes, and a pass applies only to the executed scope. Frozen debt is listed apart from new findings, and a nonzero exit shows a failed run, not that the contributor caused it.

When your agent uses it

  • Sweeping a branch's quality gates before a release
  • Reporting which gates ran, failed or were skipped on a candidate commit
  • Separating new findings from known frozen debt

Example prompts

  • “Run the quality-scan profile on this branch and report what failed and what was not run.”
  • “Do the fast quality scan and list the gates it omits.”
  • “Check base health for the main branch from remote CI evidence only.”

Requirements

  • Node.js and npm, to run the repository's quality scripts
  • Git, for the isolated worktree

What it can do on your machine

Read from SKILL.md and the folder at commit 8ad6b1c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Quality Scan loads about 748 tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 342 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~748

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from diegosouzapw/OmniRoute at commit 8ad6b1c, republished under its MIT licence (© diegosouzapw). 342 words, ~748 tokens.

Download SKILL.mdSave it as .claude/skills/quality-scan/SKILL.md (or your agent's skills folder).
name
quality-scan
description
Run a scoped, read-only quality scan and report exact-candidate evidence, failures and frozen debt. Use for an ad-hoc gate sweep or release preparation; a static scan is not full release acceptance.

Quality scan

Choose the scope

Read ../_shared/base-green.md before interpreting base or PR health.

  • Default: the static quality-scan profile.
  • Fast: quality-scan-fast; explicitly report omitted gates.
  • A named npm alias: that alias only.
  • Base status: inspect remote evidence; no local suite is implied.
  • Full release/PR acceptance: inspect the applicable workflow lanes and use ../validate-release-green/SKILL.md for the local observer's limited scope.

When present, config/quality/gate-manifest.json owns static profile membership and the npm-alias inventory. package.json owns commands and runtimes. Use npm run check:gate-manifest and the scan's --list mode to measure the current inventory. An alias, workflow job, matrix instance and test case are different units. Never substitute a remembered count for this inventory.

If the candidate predates the manifest, inspect its actual package scripts, aggregator and workflows; label the inventory provisional. Do not invent a missing command or claim manifest enforcement on an older branch.

Execute and preserve evidence

Pin the base and candidate SHAs in an isolated worktree. Run the actual npm entrypoints: direct file invocation can change the required Node/Bun runtime. Record command, cwd, versions, start/end, exit/signal, selected scope and log path. Use the gate process supervisor when the candidate provides it. Otherwise capture the command's own exit before displaying a summary, for example:

bash
scan_log=$(mktemp)
if npm run quality:scan >"$scan_log" 2>&1; then
  scan_exit=0
else
  scan_exit=$?
fi
tail -n 30 "$scan_log"
printf 'scan_exit=%s log=%s\n' "$scan_exit" "$scan_log"

Missing dependencies, timeout, cancellation and unavailable artifacts are incomplete evidence, not PASS. A scan may write logs/reports; it does not update baselines, mutate product code or contact live providers unless explicitly scoped.

Report the result

Report the selected profile and SHA, executed/failed/not-run counts, raw logs and the remaining acceptance lanes. PASS applies only to the executed scope. List frozen debt separately from new findings. A nonzero exit proves a failed execution, not that the contributor introduced it: use the causal comparison in the shared base-green protocol.

If the tracked skill-contract checker exists, npm run check:quality-skill-contract compares these private instructions with the versioned templates. Missing private skills are NOT_INSTALLED, not evidence that their instructions were validated.

Stop after the report for scan-only requests. Fixes require a change request; baseline changes require their own reviewed justification. Preserve existing thresholds and assertions throughout recovery.

© diegosouzapw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in config/quality/skill-templates/quality-scan of diegosouzapw/OmniRoute.

Open the folder on GitHubat commit 8ad6b1c

Compare with similar skills

Quality Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Quality Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Quality Scan this skilldiegosouzapw/OmniRoute74k—~748Automated safety check: PassMIT
CI Triageandymai/brepjs114—~3.7kAutomated safety check: PassApache-2.0
Knowledge Engineering Quality And DeliveryechoVic/blade-code180—~1.4kAutomated safety check: PassMIT
Sonarcloud APIaehrc/pathling137—~1.2kAutomated safety check: PassApache-2.0
Actions CI Tuningmizchi/skills356—~2.6kAutomated safety check: PassNone
Eval SkillsLeoYeAI/openclaw-master-skills2.2k—~4.3kAutomated safety check: PassMIT

Similar skills

  • CI Triage

    andymai/brepjs

    This skill should be used when a brepjs GitHub Actions job is red or behaving oddly on github.com (a remote CI run, not a local pre-commit/pre-push hook) — "CI failed", "ci-pass is failing", "npm ci…

    114 GitHub stars~3.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • 覆盖 Blade Code 跨测试、构建、资格验证、发布与双语文档的工程质量闭环. An agent skill from echoVic/blade-code.

    180 GitHub stars~1.4k tokensUpdated 10 days ago
    Testing & QAAuto-check passed
  • Sonarcloud API

    aehrc/pathling

    Expert guidance for using the SonarCloud API to interact with code quality analysis, projects, issues, quality gates, and metrics.

    137 GitHub stars~1.2k tokensUpdated today
    Testing & QAAuto-check passed
  • Actions CI Tuning

    mizchi/skills

    A skill your agent uses when auditing or improving GitHub Actions workflows for a project.

    356 GitHub stars~2.6k tokensUpdated 5 days ago
    Testing & QAAuto-check passed
  • Eval Skills

    LeoYeAI/openclaw-master-skills

    AI Agent Skill unit testing framework. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.3k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed
  • Qcsd Cicd Swarm

    proffesor-for-testing/agentic-qe

    A skill your agent uses when enforcing CI/CD quality gates before release, running regression analysis, detecting flaky tests, or assessing deployment readiness in the QCSD Verification phase.

    494 GitHub stars~2.3k tokensUpdated 3 days ago
    Testing & QAAuto-check passed

More from diegosouzapw/OmniRoute

All 50 skills in this repo
  • OmniRoute Backup and Sync CLI

    diegosouzapw/OmniRoute

    Backup and restore OmniRoute data from the CLI. Trigger incremental snapshots, sync to cloud storage, manage backup schedules, and restore from archive files.

    74k GitHub stars~948 tokensUpdated yesterday
    Auto-check passed
  • OmniRoute Settings API

    diegosouzapw/OmniRoute

    Read and update global application settings: system prompts, thinking budget, IP filters, payload rules, combo defaults, and require-login configuration.

    74k GitHub starsUsed in 1 repo~3.6k tokens
    Auto-check passed
  • OmniRoute Database Backups

    diegosouzapw/OmniRoute

    Trigger system backups, restore from backup files, and manage the SQLite database lifecycle. Supports export, import, and incremental snapshot strategies.

    74k GitHub starsUsed in 1 repo~395 tokens
    Auto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    74k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • OmniRoute LLM Cache

    diegosouzapw/OmniRoute

    Documents OmniRoute's cache endpoints for reading cache statistics and clearing entries, statistics or the reasoning cache, with notes on TTL and similarity settings.

    74k GitHub starsUsed in 1 repo~529 tokens
    Auto-check passed
  • OmniRoute RTK Context Filters

    diegosouzapw/OmniRoute

    Controls the RTK filter set and context-handling settings in OmniRoute, with endpoints to try compression on sample text and read back retained output.

    74k GitHub starsUsed in 1 repo~618 tokens
    Auto-check passed

Works with

Questions about Quality Scan

What does Quality Scan do?

Runs a scoped, read-only quality scan on a repository candidate and reports exact evidence, failures and frozen debt, without treating a static scan as release acceptance. The skill picks a scope first: the default static quality-scan profile, a fast profile that must report which gates it omitted, a single named npm alias, a base status check that inspects remote evidence only, or full release and PR acceptance, which means inspecting the relevant workflow lanes.json holds the commands.

When should I use Quality Scan?

Quality Scan fits situations like: sweeping a branch's quality gates before a release; reporting which gates ran, failed or were skipped on a candidate commit; separating new findings from known frozen debt.

How do I install Quality Scan in Claude Code?

Run `npx skills add diegosouzapw/OmniRoute --skill quality-scan -a claude-code`. Or copy the skill folder (config/quality/skill-templates/quality-scan in diegosouzapw/OmniRoute) into .claude/skills/quality-scan in your project. Claude Code loads it when a task matches its description.

How do I install Quality Scan in Codex?

Run `npx skills add diegosouzapw/OmniRoute --skill quality-scan -a codex`. Or copy the skill folder (config/quality/skill-templates/quality-scan in diegosouzapw/OmniRoute) into .agents/skills/quality-scan in your project. Codex loads it when a task matches its description.

Can I use Quality Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add diegosouzapw/OmniRoute --skill quality-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/quality-scan, .gemini/skills/quality-scan, .github/skills/quality-scan and .opencode/skills/quality-scan in your project.

What does Quality Scan need to run?

Going by SKILL.md and its folder, Quality Scan needs the command-line tools its instructions call (npm). Our summary lists: Node.js and npm, to run the repository's quality scripts; Git, for the isolated worktree.

Does Quality Scan access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Quality Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Quality Scan use?

Quality Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Quality Scan use?

About 748 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Quality Scan?

Skills that share tags, products or a category with Quality Scan: CI Triage (andymai/brepjs, 114 stars), Knowledge Engineering Quality And Delivery (echoVic/blade-code, 180 stars), Sonarcloud API (aehrc/pathling, 137 stars) and Actions CI Tuning (mizchi/skills, 356 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Quality Scan?

diegosouzapw (a GitHub user) maintains it in diegosouzapw/OmniRoute, which has 73,701 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 6, 2026.

Source: diegosouzapw/OmniRoute on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.