Agent skill

QA CLI MCP API

by fastrepl in fastrepl/anarlog

Select and run explicitly requested, risk-based QA for Anarlog's CLI, webhooks, stdio MCP, hosted Cloud API, and remote MCP.

MITAuto-check passedBackend & APIs

Install QA CLI MCP API

skills CLI
$ npx skills add fastrepl/anarlog --skill qa-cli-mcp-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fastrepl/anarlog qa-cli-mcp-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fastrepl/anarlog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/qa-cli-mcp-api .claude/skills/qa-cli-mcp-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
qa-cli-mcp-api
GitHub stars
9.4k
Token cost
~3.3k tokens
SKILL.md length
1,747 words
Files
1
Skills in repo
32
Repo updated
First seen
Licence
MIT

At a glance

Select and run explicitly requested, risk-based QA for Anarlog's CLI, webhooks, stdio MCP, hosted Cloud API, and remote MCP.

  • Works in 2 steps: A standalone meeting whose title… → Two meetings in the same recurring series.
  • Tasks that involve Webhooks
  • SKILL.md covers Choose the scope first, Safety and evidence, Comprehensive QA Fixture and Comprehensive Automated Baseline, plus 7 more sections
  • Calls cargo, pnpm and supabase; reaches api.anarlog.so

What it does

QA CLI MCP API is an agent skill from fastrepl/anarlog. Select and run explicitly requested, risk-based QA for Anarlog's CLI, webhooks, stdio MCP, hosted Cloud API, and remote MCP. Test only affected lanes unless comprehensive coverage is requested.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks and MCP servers. It works with Model Context Protocol. The repository describes itself as: Open source Granola AI Alternative. The licence is MIT.

When your agent uses it

  • Tasks that involve Webhooks
  • Tasks that involve MCP servers

Example prompts

  • “/qa-cli-mcp-api”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. A standalone meeting whose title contains a unique run marker such as
  2. Two meetings in the same recurring series.

What it can do on your machine

Read from SKILL.md and the folder at commit 259a04e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • pnpm
    • supabase

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.anarlog.so

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

QA CLI MCP API loads about 3.3k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 1,747 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from fastrepl/anarlog at commit 259a04e, republished under its MIT licence (© fastrepl). 1,747 words, ~3,347 tokens.

Download SKILL.mdSave it as .claude/skills/qa-cli-mcp-api/SKILL.md (or your agent's skills folder).
name
qa-cli-mcp-api
description
Select and run explicitly requested, risk-based QA for Anarlog's CLI, webhooks, stdio MCP, hosted Cloud API, and remote MCP. Test only affected lanes unless comprehensive coverage is requested.

QA: CLI, MCP, and API

Default to the smallest set of programmatic-interface lanes that can prove the change. Automated tests are necessary but do not replace a live smoke test when the changed boundary is only exercised by a real client or deployment.

This QA workflow is independent from releasing. A release request alone does not invoke it, and its results do not approve or block a release.

Choose the scope first

Inspect the exact branch, commit, or diff and map changed code to its direct consumers before creating fixtures or credentials. In a GitButler workspace, use but status and but show <commit-or-branch>; do not use the synthetic workspace HEAD as the candidate or combine unrelated applied branches.

Find the original reproduction in the current or past Codex task, linked issue, PR, support report, or regression test. State the selected lanes and the reason for each before testing.

Targeted regression mode (default)

Select lanes by behavior, not by the existence of this checklist:

  • CLI parsing, output, or local DB access → CLI plus the closest contract tests.
  • Webhook endpoints, signing, or delivery retries → the webhook cases only.
  • Shared agent-access DTOs, exports, filtering, or pagination → every direct consumer, including hosted REST or remote MCP when affected, plus cross-surface parity only for the changed fields.
  • Hosted auth, snapshots, entitlements, isolation, purge, or Supabase policy → the affected hosted REST lifecycle and negative cases.
  • Local or remote MCP protocol/tool changes → that MCP lane and its direct transport/contract dependency.
  • Shared hosted REST/MCP behavior → both hosted consumers, but not unrelated local surfaces.

Run the closest affected automated tests, the original live reproduction, and only credible boundary cases. A Rust or shared-crate change does not trigger all lanes unless every lane consumes the changed behavior. Create only the minimum non-sensitive fixture required for the selected checks. If a required deployment, account, fixture, or client is unavailable, mark that check BLOCKED; do not substitute unrelated lanes. Stop when the mapped risks are covered.

Comprehensive Interface QA

Run every fixture, baseline, live lane, lifecycle case, privacy check, and cross-surface comparison below only when the user explicitly requests full or comprehensive programmatic-interface QA.

Safety and evidence

  • Use a dedicated QA account and non-sensitive fixture meetings.
  • Use a Pro or trialing account for the hosted lane and a separate free or expired test account for entitlement checks.
  • Never put API keys, JWTs, webhook secrets, database credentials, or personal meeting content in commands, screenshots, reports, or repository files. Load secrets into environment variables without echoing them.
  • Store transient response bodies in a directory created with mktemp -d. Remove that directory and revoke all generated keys after the run.
  • Record the exact candidate commit, app version, API deployment, Supabase migration version, operating system, and client versions.
  • In a GitButler workspace, identify the selected branch tip with but status and inspect it with but show <branch>; do not use the synthetic workspace HEAD as the candidate identity.
  • Mark a lane BLOCKED, not PASS, when its required deployment, account, fixture, or client is unavailable.

Comprehensive QA Fixture

Create two completed QA meetings through the desktop app:

  1. A standalone meeting whose title contains a unique run marker such as agent-access-2026-07-28T120000Z.
  2. Two meetings in the same recurring series.

The fixture must include:

  • a note and at least one generated summary;
  • two participants and one action item;
  • enough transcript words to require two pages when requested with a small limit;
  • punctuation and non-ASCII text;
  • a later edit to the title, note, or summary;
  • one meeting that will be deleted during lifecycle testing.

Record the meeting IDs and expected visible values. Do not seed SQLite or Postgres directly for the live happy-path tests.

Comprehensive Automated Baseline

Run from the repository root:

bash
cargo test -p anarlog-cli
cargo test -p tauri-plugin-local-api
cargo test -p api-cloud
cargo test -p api openapi::tests
cargo check -p api-client
supabase test db
pnpm -F desktop exec vitest run \
  src/cloud-api/client.test.ts \
  src/settings/developers/index.test.tsx
pnpm -F desktop typecheck
pnpm exec dprint check

Require the CLI and MCP contract snapshots, OpenAPI composition tests, authentication tests, desktop account-switch tests, and database policy tests to pass without updating snapshots or generated clients during the run.

If the change touches a shared DTO or generated client, regenerate it using the repository command that owns the artifact, then require a clean second generation. A generated diff after the second run is a failure.

Local CLI

Build the candidate CLI with cargo build -p anarlog-cli, then use the built binary for every step.

  1. Run anarlog --json doctor.
    • PASS when it exits 0, reports schema_version: "1", uses command doctor, reports ready: true, and resolves the intended QA database.
  2. Run meetings list with JSON output.
    • Verify default ordering, the unique title query, exact series filtering, limit/offset pagination, and an empty result.
  3. For the recorded meeting ID, run:
    • meetings get ID
    • meetings note ID --kind note
    • meetings note ID --kind summary
    • meetings note ID --kind all
    • meetings transcript ID with at least two pages
    • meetings history ID with at least two pages
    • meetings export ID --format markdown
    • meetings export ID --format json
  4. Require every JSON response to have the correct schema_version, command, data, and pagination fields. Following next_offset must produce no duplicates or gaps.
  5. Export to a temporary file. A second export without --force must fail without changing the file; --force must replace it.
  6. A missing meeting ID and an unreadable or incompatible database must return machine-readable errors, a nonzero exit, and no panic or partial export.

Webhooks

Launch the exact desktop candidate and add a temporary receiver under Settings → Developers → Webhooks.

  1. Adding an endpoint must return a whsec_ secret exactly once, and a non-HTTP URL must be rejected.
  2. Trigger a test delivery, a meeting completion, and a note enhancement.
    • Verify the event name, delivery ID, timestamp, body, and HMAC-SHA256 signature over the exact raw body.
    • Verify retry behavior with one deliberate transient failure.
  3. Confirm the last-delivery status shown in settings matches the receiver.
  4. Delete the webhook and prove that no later delivery arrives.
  5. Quit the desktop app, complete no further work, and confirm no deliveries are queued or replayed on the next launch.

Local stdio MCP

Start anarlog mcp through a real MCP client over stdio. Do not validate this lane by invoking server handlers directly.

  1. Connect with the current MCP lifecycle and run tools/list. Repeat the handshake with a legacy 2025-11-25 client.
  2. Require exactly these tools:
    • list_meetings
    • get_meeting
    • get_meeting_transcript
    • get_recurring_meeting_history
    • export_meeting
    • propose_summary_edit
    • propose_memo_edit
    • list_proposals
    • get_proposal
    • decline_proposal
  3. Call every tool against the fixture. Verify query and series filters, two-page transcript/history traversal, missing IDs, and invalid arguments.
  4. Run resources/list, resources/templates/list, and resources/read for a meeting, transcript page, and recurring series.
  5. Require read-only, non-destructive, and idempotent tool annotations.
  6. Compare the returned values with the CLI lane.
  7. Capture stdout and stderr separately. Stdout must contain only MCP protocol frames; diagnostics belong on stderr. Client shutdown must terminate the server without leaving a process behind.
Show full SKILL.md (635 more words)Show less

Hosted Cloud API

Use the deployed candidate API and Supabase migration with the Pro QA account. Begin with Cloud API & Connectors disabled.

  1. Before opt-in, confirm there are no server-readable snapshot rows for the account and a previously valid key returns 403 cloud_api_not_enabled.
  2. Enable the feature in the desktop UI and wait for backfill to finish.
  3. Create a short-lived cloud key and exercise the same read endpoints, filters, pagination, error cases, and exports as the CLI lane.
  4. Require:
    • no key, malformed key, and revoked key → 401;
    • free or expired account → 403 subscription_required;
    • disabled account → 403 cloud_api_not_enabled;
    • invalid input → 400 invalid_request;
    • missing meeting → 404 not_found;
    • request burst above the documented quota → 429 with retry-after.
  5. Edit the fixture locally and confirm the hosted result changes. Delete the lifecycle fixture and confirm the hosted endpoint returns 404.
  6. Sign the desktop into another account before a queued upload or retry can complete. No snapshot from the first account may appear in the second.
  7. Disable the feature.
    • PASS when all server-readable snapshots are purged, the cloud key returns cloud_api_not_enabled, local data remains, and normal encrypted sync data is unchanged.
  8. Re-enable and confirm a fresh backfill restores only currently existing meetings. Revoke the QA key when finished.

Remote MCP

Connect a real Streamable HTTP MCP client to the deployed /mcp endpoint.

  1. Use server/discover with MCP 2026-07-28, list tools without creating a session, and require exactly list_meetings, get_meeting, get_meeting_transcript, get_recurring_meeting_history, and export_meeting. Verify the required protocol metadata and standard HTTP headers on every modern request. Repeat discovery with a legacy 2025-11-25 stateless client to prove compatibility.
  2. Call every tool and traverse at least two transcript/history pages.
  3. Compare its structured results with the hosted REST responses.
  4. Repeat initialization or a tool call with no credential, a malformed key, a revoked key, an expired account, and after opt-out. Unauthenticated MCP requests must return WWW-Authenticate pointing at https://api.anarlog.so/.well-known/oauth-protected-resource/mcp.
  5. When OAuth is affected, complete MCP OAuth 2.1 discovery and consent from at least one documented host (Claude Code, Cursor, ChatGPT/Codex, or Copilot). Confirm the consent screen is Anarlog's /oauth/consent route, the issued token is bound to https://api.anarlog.so/mcp, and a tool call then reads the marked meeting. Repeat with a static anl_ key for hosts that cannot complete OAuth.
  6. Connect at least one supported agent client using the documented setup and ask it to identify the marked meeting, summarize it, and cite a transcript detail. Verify the answer against the fixture.
  7. Close the client and confirm the server releases the session cleanly.

Cross-surface parity

For the marked meeting, compare CLI, local MCP, hosted REST, and remote MCP:

FieldRequired parity
MeetingID, title, kind, status, timestamps, timezone, language, series
Documentscanonical note, summary titles and markdown
Peopleparticipants and organizations
Actionstext, assignee, completion state
Transcripttext, word order, timestamps, speakers, page boundaries
HistoryIDs, newest-first ordering, pagination
Errorsstable code, appropriate protocol status, no secret leakage

Local and hosted values must match after backfill settles. Hosted payloads must not contain local paths, audio paths, file paths, control characters, secrets, or fields outside the disclosed server-readable copy.

Reporting

For targeted mode, report the candidate branch/commit, base, selected lane and risk, PASS/FAIL/BLOCKED, and a one-line evidence note. List unrelated lanes once as NOT APPLICABLE, and say explicitly that the result is not comprehensive interface QA.

For comprehensive mode, produce one table with rows for:

  • automated baseline;
  • CLI;
  • webhooks;
  • local stdio MCP;
  • hosted REST;
  • remote MCP;
  • lifecycle and account isolation;
  • privacy purge;
  • cross-surface parity.

Use PASS, FAIL, or BLOCKED with a one-line evidence note. Include the candidate and deployment identifiers, fixture marker, clients tested, and redacted response artifact locations. List every skipped negative case.

Any required FAIL or BLOCKED result means comprehensive QA did not pass. Report that outcome without inferring release approval or blocking.

© fastrepl, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/qa-cli-mcp-api of fastrepl/anarlog.

Open the folder on GitHubat commit 259a04e

Compare with similar skills

QA CLI MCP API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

QA CLI MCP API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
QA CLI MCP API this skillfastrepl/anarlog9.4k—~3.3kAutomated safety check: PassMIT
Zalo AgentPhucMPham/zalo-agent-cli161—~2.3kAutomated safety check: PassMIT
X Twitter ScraperXquik-dev/x-twitter-scraper209—~2.6kAutomated safety check: PassMIT
Yolfi Paymentsyolfinance/yolfi-agent178—~1.2kAutomated safety check: PassMIT
Frontmcp Channelsagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0
E2a Doctortokencanopy/e2a192—~994Automated safety check: PassApache-2.0

Similar skills

  • Zalo Agent

    PhucMPham/zalo-agent-cli

    Automate Zalo messaging, Official Account (OA), and MCP server integration via zalo-agent-cli.

    161 GitHub stars~2.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • X Twitter Scraper

    Xquik-dev/x-twitter-scraper

    Use Xquik to fetch X (Twitter) data or act through a connected account: search, profiles, followers, replies, threads, timelines, media downloads, bulk exports, trends, monitors, signed webhooks…

    209 GitHub stars~2.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Yolfi Payments

    yolfinance/yolfi-agent

    Add Yolfi crypto checkout, payment links, and webhook handling to an app through @yolfi/agent or the Yolfi MCP server.

    178 GitHub stars~1.2k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Frontmcp Channels

    agentfront/frontmcp

    A skill your agent uses when pushing real-time notifications or events into Claude Code (or another MCP client) sessions, or building two-way chat bridges.

    146 GitHub stars~3.7k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • E2a Doctor

    tokencanopy/e2a

    A skill your agent uses when an existing e2a MCP connection, inbox, custom domain, protection policy, webhook, or message delivery is failing or unclear.

    192 GitHub stars~994 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • GitLab MCP Skill

    zereight/gitlab-mcp

    A skill your agent uses when working with the GitLab MCP server tools for merge requests, issues, repositories, pipelines, work items, variables, dependency proxy, vulnerabilities, webhooks, search…

    2k GitHub stars~2k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from fastrepl/anarlog

All 32 skills in this repo
  • But

    fastrepl/anarlog

    Use only in the Anarlog repository when the active checkout branch is exactly gitbutler/workspace.

    9.4k GitHub stars~5.8k tokensUpdated today
    Auto-check passed
  • Create PRs

    fastrepl/anarlog

    Use only in the Anarlog repository when the active checkout branch is exactly gitbutler/workspace.

    9.4k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Fix Ready PRs

    fastrepl/anarlog

    Inspect every open non-draft PR for CI failures and unresolved Cursor Bugbot findings, then fix them on the existing PR branches.

    9.4k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • No Use Effect

    fastrepl/anarlog

    Avoid direct React useEffect usage when writing or reviewing React components and hooks.

    9.4k GitHub stars~825 tokensUpdated today
    Auto-check passed
  • QA Critical UX

    fastrepl/anarlog

    QA Anarlog's critical Pro user journey on a signed staging candidate — onboarding, responsive launch, microphone and system-audio capture, automated summaries, and cloud sync.

    9.4k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Reactive Sqlite UI

    fastrepl/anarlog

    Build SQLite-backed reactive UI in apps/desktop using stable patterns for reads, selection, forms, writes, and loading states.

    9.4k GitHub stars~699 tokensUpdated today
    Auto-check passed

Categories

Questions about QA CLI MCP API

What does QA CLI MCP API do?

Select and run explicitly requested, risk-based QA for Anarlog's CLI, webhooks, stdio MCP, hosted Cloud API, and remote MCP. QA CLI MCP API is an agent skill from fastrepl/anarlog. Select and run explicitly requested, risk-based QA for Anarlog's CLI, webhooks, stdio MCP, hosted Cloud API, and remote MCP.

When should I use QA CLI MCP API?

QA CLI MCP API fits situations like: tasks that involve Webhooks; tasks that involve MCP servers.

How do I install QA CLI MCP API in Claude Code?

Run `npx skills add fastrepl/anarlog --skill qa-cli-mcp-api -a claude-code`. Or copy the skill folder (.agents/skills/qa-cli-mcp-api in fastrepl/anarlog) into .claude/skills/qa-cli-mcp-api in your project. Claude Code loads it when a task matches its description.

How do I install QA CLI MCP API in Codex?

Run `npx skills add fastrepl/anarlog --skill qa-cli-mcp-api -a codex`. Or copy the skill folder (.agents/skills/qa-cli-mcp-api in fastrepl/anarlog) into .agents/skills/qa-cli-mcp-api in your project. Codex loads it when a task matches its description.

Can I use QA CLI MCP API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fastrepl/anarlog --skill qa-cli-mcp-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qa-cli-mcp-api, .gemini/skills/qa-cli-mcp-api, .github/skills/qa-cli-mcp-api and .opencode/skills/qa-cli-mcp-api in your project.

What does QA CLI MCP API need to run?

Going by SKILL.md and its folder, QA CLI MCP API needs the command-line tools its instructions call (cargo, pnpm and supabase).

Does QA CLI MCP API access the network?

SKILL.md names 1 domain. In commands or code: api.anarlog.so; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is QA CLI MCP API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does QA CLI MCP API use?

QA CLI MCP API is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does QA CLI MCP API use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to QA CLI MCP API?

Skills that share tags, products or a category with QA CLI MCP API: Zalo Agent (PhucMPham/zalo-agent-cli, 161 stars), X Twitter Scraper (Xquik-dev/x-twitter-scraper, 209 stars), Yolfi Payments (yolfinance/yolfi-agent, 178 stars) and Frontmcp Channels (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains QA CLI MCP API?

fastrepl (a GitHub organization) maintains it in fastrepl/anarlog, which has 9,445 GitHub stars. The repository holds 32 skills in this directory. The repository was last updated on October 7, 2026.

Source: fastrepl/anarlog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.