Agent skill

QA Methodology

by magnus919 in magnus919/agent-skills

Design and apply QA methodology for software teams: test strategy, regression testing, CI failure triage, test automation, quality gates and metrics, risk-based testing, exploratory testing, test…

MITAuto-check passedTesting & QA

Install QA Methodology

skills CLI
$ npx skills add magnus919/agent-skills --skill qa-methodology -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install magnus919/agent-skills qa-methodology --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/qa-methodology .claude/skills/qa-methodology && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
qa-methodology
GitHub stars
116
Token cost
~3.2k tokens
SKILL.md length
1,132 words
Files
40 (incl. scripts, references, assets)
Skills in repo
130
Repo updated
First seen
Licence
MIT

At a glance

Design and apply QA methodology for software teams: test strategy, regression testing, CI failure triage, test automation, quality gates and metrics, risk-based testing, exploratory testing, test…

  • Root-cause debugging of production incidents
  • SKILL.md covers Ownership, Core Principles, Loading Guide and Agent-driven UI navigation, plus 4 more sections
  • Calls python3
  • Security implementation

What it does

QA Methodology is an agent skill from magnus919/agent-skills. Design and apply QA methodology for software teams: test strategy, regression testing, CI failure triage, test automation, quality gates and metrics, risk-based testing, exploratory testing, test design techniques, AI code quality gates (independent verification, artifact provenance, spec-first oracles, AI-review-comment triage, acceptance-criteria testability for Spec-Driven Development), mutation-guided test hardening and review evidence (surviving mutants, weak assertions, diff-aware mutation testing), agentic…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 42 other files, including scripts, reference files and assets (for example `README.md`, `assets/qa-definition-of-done.md` and `assets/risk-matrix-grid.md`). Compatibility notes: Platform-agnostic methodology. Scripts require Python 3.8+ (stdlib only). No CI platform, test framework, or AI agent mandate.

It sits in Testing & QA, covering QA and bug reports, Spec-driven development and Debugging. It works with Playwright. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.

When your agent uses it

  • Root-cause debugging of production incidents
  • Security implementation
  • Threat modeling
  • Evaluation framework governance and statistical analysis — route those to systematic-debugging

Example prompts

  • “/qa-methodology”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Platform-agnostic methodology. Scripts require Python 3.8+ (stdlib only). No CI platform, test framework, or AI agent mandate.

What it can do on your machine

Read from SKILL.md and the folder at commit c545c2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Platform-agnostic methodology. Scripts require Python 3.8+ (stdlib only). No CI platform, test framework, or AI agent mandate.

    From compatibility in the SKILL.md frontmatter.

Context cost

QA Methodology loads about 3.2k tokens when it runs, and up to ~46k if it reads all its reference files. Until then it costs about 253 tokens; SKILL.md has 1,132 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~253
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~46k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from magnus919/agent-skills at commit c545c2b, republished under its MIT licence (© magnus919). 1,132 words, ~3,179 tokens.

Download SKILL.mdSave it as .claude/skills/qa-methodology/SKILL.md (or your agent's skills folder). This skill also uses 39 other files; get the full folder from GitHub.
name
qa-methodology
description
Design and apply QA methodology for software teams: test strategy, regression testing, CI failure triage, test automation, quality gates and metrics, risk-based testing, exploratory testing, test design techniques, AI code quality gates (independent verification, artifact provenance, spec-first oracles, AI-review-comment triage, acceptance-criteria testability for Spec-Driven Development), mutation-guided test hardening and review evidence (surviving mutants, weak assertions, diff-aware mutation testing), agentic eval design (dataset test design, judge-as-system-under-test, flaky-eval discipline), QA career levels (Senior/Staff/Principal), and SDET engineering (test infrastructure, gTAA, CI/CD integration). Do not use for root-cause debugging of production incidents, security implementation or threat modeling, or evaluation framework governance and statistical analysis — route those to systematic-debugging, secure-software-engineering, and agent-evals-and-observability respectively.
compatibility
Platform-agnostic methodology. Scripts require Python 3.8+ (stdlib only). No CI platform, test framework, or AI agent mandate.
license
MIT
metadata.source_repo
hermes-profiles
metadata.skill_version
2.0.0
metadata.tags
qa, testing, quality-assurance, test-automation, regression, CI, quality-gates, risk-based-testing, exploratory-testing, mutation-testing, SDET…

QA Methodology

Senior-to-principal QA and SDET methodology: test strategy, automation, regression, risk-based prioritization, exploratory testing, quality gates, AI code quality gates for agentic Spec-Driven Development, agentic eval design, career leveling, and SDET engineering.

Ownership

You ownYou don't own
Test strategy — what to test, at what level, with what priorityRoot-cause debugging — route to systematic-debugging
Test automation — framework selection, parallelism, flaky managementSecurity implementation and threat modeling — route to secure-software-engineering
E2E automation strategy and coverage decisionsOperating a browser test tool (Playwright) — authoring/running specs, selectors, network mocking, scraping — route to playwright
Regression suites — selection, impact analysis, suite evolutionSpec pipeline mechanics and gate verdicts — route to spec-driven-development
Quality gates — blocking vs advisory, metrics, DORAEval framework governance and statistics — route to agent-evals-and-observability
Risk-based testing — P×I scoring, prioritization, registersVerification verdicts against explicit criteria — route to verification-methodology
Exploratory testing — SBTM charters, heuristics, toursFeature implementation — that's the developer
AI code quality gates — independent verification, AC testabilityProduction monitoring and incident response — that's SRE
Mutation-guided test hardening — bounded mutation review evidence and survivor triageVerification verdicts against explicit criteria — route to verification-methodology
Agentic eval design — dataset design, judge bias, flaky-eval discipline
QA career levels — Senior/Staff/Principal scope progression
SDET engineering — test infrastructure, gTAA, CI/CD integration

Core Principles

If it isn't tested, it's broken. Untested code is code whose failure mode hasn't been discovered yet.

Quality is a property of the process, not the artifact. Testing at the end doesn't create quality. Quality is designed in through strategy, automation, and gating throughout the cycle.

Test behavior, not implementation. Tests coupled to behavior survive refactoring; tests coupled to implementation break on it.

Risk drives priority. Not everything deserves equal test investment. Score probability × impact, then allocate accordingly.

Flaky tests are worse than no tests. A nondeterministic failure trains teams to ignore all failures. Quarantine on detection; rerun once, never twice.

Independent verification is non-negotiable. The implementing agent (or developer) must not self-verify. Separate session, fresh context, no shared priors.

Loading Guide

FileLoad when
references/test-strategy.mdDesigning a test strategy — pyramid shape, shift-left/right, cost-of-failure, coverage as diagnostic
references/test-automation.mdSelecting frameworks, parallelism/sharding, flaky quarantine, predictive ML test selection, mutation-guided hardening
references/quality-gates-and-metrics.mdDesigning quality gates (blocking vs advisory), DORA metrics, vanity-vs-actionable metrics, mutation testing
references/regression-testing.mdBuilding regression suites — impact analysis, selection math, suite evolution, shift-right feedback
references/test-data-management.mdTest data strategy — fixtures, factories, time-travel, masking, GDPR/PII rules
references/performance-testing.mdLoad/stress/soak testing — k6/Locust/Gatling/JMeter, SLO thresholds, CI cadence
references/security-testing.mdSecurity testing — OWASP Top 10:2025, STRIDE, SAST/DAST/SCA, supply chain/SBOM
references/ci-failure-triage.mdCI is red — exit-code taxonomy (1/2/126/127/137/139/143), git bisect, flake-vs-failure protocol
references/test-debugging.mdA test that should pass is failing — CI-vs-local divergence, ordering/shared state, mock binding
references/risk-based-testing.mdPrioritizing by risk — P×I formula, 5×5 matrix, risk workshop, register, reassessment triggers
references/exploratory-testing.mdExploratory testing — SBTM, charter writing, SFDIPOT/HICCUPPS heuristics, tours
references/test-design-techniques.mdChoosing test design techniques — EP, BVA, decision tables, state transition, pairwise, error guessing
references/qa-career-levels.mdQA career growth — Senior/Staff/Principal scope, leveling mechanics, archetypes, misconceptions
references/sdet-engineering.mdSDET role and skills — gTAA/TAF architecture, POM, SOLID for tests, build-vs-buy, testability
references/ai-code-quality-gates.mdReviewing AI-generated code — independent verification, AC testability, agent-test quality, human-in-the-loop
references/ai-test-artifact-evidence.mdProvenance, spec-first oracle review, generated-review triage, workflow evidence, and emergency exceptions for AI-assisted QA
references/agent-ui-navigation.mdAgent navigation/replay strategy, independent oracles, bounded repairs and complete coverage
templates/agent-ui-run-record.mdRecording navigation, replay, independent checks and missing evidence
references/agentic-eval-design.mdDesigning agent evals — dataset test design, judge bias, flaky-eval discipline, CI gate tiers, replay
templates/test-strategy.mdProducing a test strategy document — fill in scope, risk tiers, level allocation, automation targets
templates/risk-register.mdRecording risk assessment results — fill in items, P×I scores, owners, mitigations
templates/exploratory-charter.mdWriting an SBTM charter — fill in target, resources, discovery goal, timebox
templates/bug-report.mdFiling a structured bug report — fill in reproduction steps, expected vs actual, severity
templates/verification-plan.mdPlanning independent verification — fill in AC-to-method traceability, verifier assignment, exit criteria
templates/mutation-review.mdRecording bounded mutation review scope, classifications, survivor tests, and independent evidence
templates/ai-assisted-verification-note.mdRecording AI-assisted test/review provenance, independent oracle checks, and evidence disposition
assets/risk-matrix-grid.mdScoring risks during a workshop — 5×5 P×I grid with zone thresholds
assets/test-design-techniques-checklist.mdSelecting techniques for a feature — quick-reference checklist mapping scenario type to technique
assets/qa-definition-of-done.mdDefining release readiness — QA contribution to definition of done
scripts/risk-prioritize.pyComputing P×I rankings from a risk-items JSON file
scripts/check-ac-testability.pyChecking acceptance criteria for vague verbs and missing observable outcomes
evals/evals.jsonRunning output-quality evals for this skill (schema v1, 21 cases)
Show full SKILL.md (427 more words)Show less

Agent-driven UI navigation

For live navigation, replay or locator repair, read references/agent-ui-navigation.md and fill templates/agent-ui-run-record.md. Freeze independent exact oracles and required case IDs before execution; never let the navigator weaken assertions or skip required coverage. Recheck persistence, account identity and effect count on every path. Reuse System One for optional bounded text decisions; tool skills own operation and verification-methodology owns evidence verdicts.

Scripts

ScriptInvocationPurpose
risk-prioritizepython3 scripts/risk-prioritize.py --json <input.json>Reads risk items (probability, impact), computes P×I scores, emits ranked JSON
check-ac-testabilitypython3 scripts/check-ac-testability.py <spec.md>Scans acceptance criteria for untestable language, exits non-zero if any are flagged

Triggers

Load this skill when the task involves:

  • Test strategy — designing what/how/priority to test for a project or feature
  • Regression testing — building, selecting, or evolving regression suites
  • CI triage — diagnosing CI failures, exit codes, flake-vs-real classification
  • Test automation — framework selection, parallelism, flaky quarantine, ML selection
  • Quality gates — gate design, blocking vs advisory, metrics, DORA
  • Mutation-guided test hardening — diff-aware mutation scope, surviving mutants, weak assertions, and review evidence
  • Risk-based testing — P×I scoring, risk registers, prioritization workshops
  • Exploratory testing — SBTM charters, oracle heuristics, session debriefs
  • Agentic evals — eval dataset design, judge bias, flaky-eval discipline, CI tiers
  • SDD gate review — QA ownership at spec-driven gates, AC testability, independent verification
  • SDET — test infrastructure engineering, gTAA, CI/CD integration, career scope

When not to use

Route to the named sibling skill instead:

  • spec-driven-development — writing specs, running the SDD pipeline, gate verdict format, revision loops
  • agent-evals-and-observability — eval framework governance, statistical comparisons, telemetry and privacy controls, grader implementation
  • verification-methodology — collecting evidence and rendering verdicts against explicit pass/fail criteria
  • release-engineering — composing test evidence into release-candidate readiness, promotion, go/no-go, production rollout, and rollback decisions; QA owns test strategy and gate semantics
  • systematic-debugging — root-cause analysis of production incidents, bug reproduction, fault localization
  • secure-software-engineering — security implementation, threat modeling, secure defaults, dependency evaluation
  • playwright — operating the Playwright tool itself: authoring and running E2E specs, selector robustness, network mocking, headless scraping, and headed debugging

Stop and Exit Conditions

  • Test strategy complete when: strategy document names risk tiers, level allocation, automation targets, and exit criteria for each tier.
  • Risk assessment complete when: every identified risk has a P×I score, an owner, and a mitigation or acceptance decision recorded in the register.
  • CI triage complete when: failure is classified (flake vs real, env vs code), root cause is localized, and a fix or escalation path is identified.
  • Gate review complete when: every acceptance criterion maps to a verification method, the verifier is independent of the implementer, and evidence is attached.
  • Bounded escalation: stop after three non-converging diagnostic passes and report the evidence collected so far.

© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 39 other files (scripts, references, assets) in qa-methodology of magnus919/agent-skills.

  • SKILL.md
  • README.md
  • assets/qa-definition-of-done.md
  • assets/risk-matrix-grid.md
  • assets/test-design-techniques-checklist.md
  • evals/evals.json
  • pytest.ini
  • references/agent-ui-navigation.md
  • references/agentic-eval-design.md
  • references/ai-code-quality-gates.md
  • references/ai-test-artifact-evidence.md
  • references/ci-failure-triage.md
  • references/exploratory-testing.md
  • references/performance-testing.md
  • references/qa-career-levels.md
  • references/quality-gates-and-metrics.md
  • references/regression-testing.md
  • references/risk-based-testing.md
  • … and 22 more

Open the folder on GitHubat commit c545c2b

Compare with similar skills

QA Methodology next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

QA Methodology compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
QA Methodology this skillmagnus919/agent-skills116—~3.2kAutomated safety check: PassMIT
Dogfoodredf0x1/camofox-browser412—~1.2kAutomated safety check: PassMIT
QA Manual Istqbfugazi/test-automation-skills-agents247—~3.6kAutomated safety check: PassMIT
Replica TestJakeschincariol/replica-skill1.2k—~819Automated safety check: PassMIT
Browser Bug Testing Workflowsandgardenhq/sgai137—~3.7kAutomated safety check: PassCustom licence
QA LeadIbrahim-3d/orchestrator-supaconductor381—~2.5kAutomated safety check: PassAGPL-3.0

Similar skills

  • Dogfood

    redf0x1/camofox-browser

    QA testing workflow for CamoFox Browser — systematic testing with console capture, error detection, and Playwright tracing.

    412 GitHub stars~1.2k tokensUpdated 17 days ago
    Testing & QAAuto-check passed
  • QA Manual Istqb

    fugazi/test-automation-skills-agents

    Create QA artifacts from requirements: test plans, test conditions/cases, bug reports, regression suites, traceability, and exploratory charters.

    247 GitHub stars~3.6k tokensUpdated 6 days ago
    Testing & QAAuto-check passed
  • Replica Test

    Jakeschincariol/replica-skill

    Clicks through every flow of an app clone and tests it for bugs: a test plan generated from the recon flows with happy paths and edge cases, Playwright end-to-end tests where possible, a browser…

    1.2k GitHub stars~819 tokensUpdated 6 days ago
    Testing & QAAuto-check passed
  • You must use this skill when debugging web UI bugs or testing interactive components that require multi-step browser interactions.

    137 GitHub stars~3.7k tokensUpdated 18 days ago
    Testing & QAAuto-check passed
  • QA Lead

    Ibrahim-3d/orchestrator-supaconductor

    Quality assurance consultation for Conductor orchestrator. An agent skill from Ibrahim-3d/orchestrator-supaconductor.

    381 GitHub stars~2.5k tokensUpdated 12 days ago
    Testing & QAAuto-check passed
  • Activitypub Testing

    Microck/ordinary-claude-skills

    Testing patterns for PHPUnit and Playwright E2E tests. An agent skill from Microck/ordinary-claude-skills.

    404 GitHub stars~712 tokensUpdated 1 mo ago
    Testing & QAAuto-check passed

More from magnus919/agent-skills

All 130 skills in this repo
  • Artifact Pyramids

    magnus919/agent-skills

    Organize durable agent research outputs as summaries, analysis, and evidence dossiers.

    116 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Ascii City Engine

    magnus919/agent-skills

    Build portable, first-person colored ASCII city engines and small GIS-derived city packs.

    116 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Color Management

    magnus919/agent-skills

    Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.

    116 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Data Scientist

    magnus919/agent-skills

    A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

    116 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Docker Compose

    magnus919/agent-skills

    Use Docker Compose to define, run, debug, and harden multi-container applications.

    116 GitHub stars~2k tokensUpdated yesterday
    Auto-check: notes
  • Fpga Development

    magnus919/agent-skills

    Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.

    116 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about QA Methodology

What does QA Methodology do?

Design and apply QA methodology for software teams: test strategy, regression testing, CI failure triage, test automation, quality gates and metrics, risk-based testing, exploratory testing, test…. QA Methodology is an agent skill from magnus919/agent-skills.

When should I use QA Methodology?

QA Methodology fits situations like: root-cause debugging of production incidents; security implementation; threat modeling; evaluation framework governance and statistical analysis — route those to systematic-debugging.

How do I install QA Methodology in Claude Code?

Run `npx skills add magnus919/agent-skills --skill qa-methodology -a claude-code`. Or copy the skill folder (qa-methodology in magnus919/agent-skills) into .claude/skills/qa-methodology in your project. Claude Code loads it when a task matches its description.

How do I install QA Methodology in Codex?

Run `npx skills add magnus919/agent-skills --skill qa-methodology -a codex`. Or copy the skill folder (qa-methodology in magnus919/agent-skills) into .agents/skills/qa-methodology in your project. Codex loads it when a task matches its description.

Can I use QA Methodology in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill qa-methodology -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qa-methodology, .gemini/skills/qa-methodology, .github/skills/qa-methodology and .opencode/skills/qa-methodology in your project.

What does QA Methodology need to run?

Going by SKILL.md and its folder, QA Methodology needs the command-line tools its instructions call (python3). Our summary lists: Python 3. Compatibility (from SKILL.md): Platform-agnostic methodology. Scripts require Python 3.8+ (stdlib only). No CI platform, test framework, or AI agent mandate..

Does QA Methodology access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is QA Methodology safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does QA Methodology use?

QA Methodology is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does QA Methodology use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 42k tokens, read only when the agent opens those files.

What are the alternatives to QA Methodology?

Skills that share tags, products or a category with QA Methodology: Dogfood (redf0x1/camofox-browser, 412 stars), QA Manual Istqb (fugazi/test-automation-skills-agents, 247 stars), Replica Test (Jakeschincariol/replica-skill, 1.2k stars) and Browser Bug Testing Workflow (sandgardenhq/sgai, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains QA Methodology?

magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 116 GitHub stars. The repository holds 130 skills in this directory. The repository was last updated on October 8, 2026.

Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.