Vercel Composition Patterns
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
Run OpenClaw-wide autonomous QA and live/stress campaigns across independent subsystem lanes, with verified fixes and a resumable evidence report.
$ npx skills add openclaw/openclaw --skill auto-qa -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openclaw/openclaw auto-qa --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/auto-qa .claude/skills/auto-qa && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "auto-qa" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/auto-qa into .claude/skills/auto-qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auto-qa", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openclaw/openclaw/tree/main/.agents/skills/auto-qaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openclaw/openclaw --skill auto-qa -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openclaw/openclaw auto-qa --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/auto-qa .agents/skills/auto-qa && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "auto-qa" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/auto-qa into .agents/skills/auto-qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auto-qa", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/openclaw --skill auto-qa -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openclaw/openclaw auto-qa --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/auto-qa .cursor/skills/auto-qa && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "auto-qa" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/auto-qa into .cursor/skills/auto-qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auto-qa", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openclaw/openclaw.git --path .agents/skills/auto-qa--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openclaw/openclaw --skill auto-qa -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openclaw/openclaw auto-qa --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/auto-qa .gemini/skills/auto-qa && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "auto-qa" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/auto-qa into .gemini/skills/auto-qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auto-qa", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openclaw/openclaw auto-qaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openclaw/openclaw --skill auto-qa -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/auto-qa .github/skills/auto-qa && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "auto-qa" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/auto-qa into .github/skills/auto-qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auto-qa", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/openclaw --skill auto-qa -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openclaw/openclaw auto-qa --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/auto-qa .opencode/skills/auto-qa && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "auto-qa" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/auto-qa into .opencode/skills/auto-qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "auto-qa", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auto-qaRun OpenClaw-wide autonomous QA and live/stress campaigns across independent subsystem lanes, with verified fixes and a resumable evidence report.
Auto QA is an agent skill from openclaw/openclaw. Run OpenClaw-wide autonomous QA and live/stress campaigns across independent subsystem lanes, with verified fixes and a resumable evidence report.
Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `agents/openai.yaml`, `references/campaign-evidence.md` and `references/evidence-ledger.md`).
It sits in Development. The repository describes itself as: The AI that really does things. Any OS. Any Platform. The lobster way. 🦞. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 3193e15. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitcodexFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Auto QA loads about 4.3k tokens when it runs, and up to ~8.4k if it reads all its reference files. Until then it costs about 39 tokens; SKILL.md has 2,296 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openclaw/openclaw at commit 3193e15, republished under its MIT licence (© openclaw). 2,296 words, ~4,304 tokens.
.claude/skills/auto-qa/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Run a continuous, current-main OpenClaw product campaign. Treat a reviewer finding as a hypothesis, a passing test as evidence only for its actual head, and a merge as complete only when the canonical repository confirms it. Always prefer a clean, appropriately scoped root-cause refactor over a quick fix or smaller diff. Repair the actual root cause in its canonical owner; a patch is not acceptable when it leaves sibling paths, lifecycle invariants, or the defective abstraction intact.
AGENTS.md, then each scoped guide for the lanes under inspection. Read the current skill for a specialized workflow instead of reproducing stale instructions:$openclaw-repair-sweep for bug acceptance and duplicate handling.$openclaw-testing for actual test and CI selection.$openclaw-qa-testing for QA Lab, scenario catalogs, and real provider lanes.$control-ui-e2e for browser and Control UI proof.$crabbox for remote, Docker, packaged, cross-platform, and live proof.$autoreview for fresh independent review before publishing or landing.$openclaw-pr-maintainer for authorized maintainer-side GitHub actions.main checkout; a desktop or linked worktree can have a different detached HEAD. Check git -C <verified-canonical-main-checkout> status -sb and record git -C <verified-canonical-main-checkout> rev-parse HEAD. When network access is authorized, let only the orchestrator refresh origin/main, record its full SHA, and prove the canonical checkout matches before inspecting source. Give every read-only reviewer the absolute clean checkout or its own verified exact-head worktree. Before inspection and immediately before accepting results, require both the exact git -C <worker-checkout> rev-parse HEAD and empty output from git --no-optional-locks -C <worker-checkout> status --porcelain=v1 --untracked-files=all --ignore-submodules=none; alternatively, read immutable files directly from the frozen Git object. Discard the complete wave item when either verification fails. Keep intentionally modified implementation worktrees separate from read-only frozen-source review. For offline work, disclose that remote freshness is unverified. Never pull, rebase, or switch another agent's checkout.codex/ worktree per implementation task. Keep reviewer workers read-only. Serialize all shared origin/main refreshes through the orchestrator; pause worker fetches before repository-native PR review, preparation, or landing. After a successful landing, fetch origin/main again, verify the recorded merge commit is an ancestor of that fetched ref, and only then broadcast its full immutable SHA and resume workers. Revalidate candidates against each new head without changing a sibling's active worktree. When offline, disclose that remote freshness is unverified.When independent worker execution is authorized, keep at least ten materially different subsystem investigations in flight throughout the active campaign. Replace completed, failed, or stale workers promptly. Network authorization separately determines whether a lane may fetch, invoke an externally hosted model, or contact a provider; it does not prohibit authorized local subagents. If independent workers are unavailable or forbidden, record the concurrency requirement as blocked rather than claiming sequential reviews are concurrent. Start with the OpenClaw-specific lane map in references/subsystem-lanes.md. Split a large area into narrow, independent ownership surfaces instead of giving one worker the entire gateway, provider, UI, or app tree.
Use first-class subagents when available and bounded codex exec --sandbox read-only --ephemeral reviewers when agent slots are exhausted; verify the installed CLI's supported options with codex exec --help. Keep CLI workers under an actually surviving parent session or durable supervisor; background children started by a shell that immediately exits are not active workers. Independently check the exact child PIDs and command identity with ps -p <pid-list>, and record the observation time. Give each worker the absolute verified checkout, initial and final exact-SHA and clean-content guards, frozen SHA, one subsystem and its scoped guide, a bounded duration, and the required evidence shape. Record running, successfully completed, failed, timed-out, and stale-guarded workers separately; replace finished workers before claiming continued concurrency. Ask for source, at least one caller and callee, sibling behavior, regression tests, current-main reproduction, upstream dependency proof when relevant, severity, and duplicate references. Do not disclose a proposed diagnosis to an independent verifier. When independent workers are unavailable, disclose the actual limitation; never represent launched, planned, finished, shell-discarded, or stale workers as running.
Observe CPU, memory pressure, disk, open ports, actual worker count, and gateway health between waves. Scale to the machine and operator-authorized load rather than mechanically starting 64 workers or treating a brief load-average spike as failure. Reduce campaign concurrency for sustained memory pressure, gateway failures, process starvation, or an actual operator limit. Keep remote proofs serialized per Testbox lease; never reclaim, sync, or launch another command while that lease has an active command. When a local process session disappears, recover the authoritative remote job and exact exit before retrying or claiming a pass. Use bounded retries and timeouts. Stop only campaign-owned processes.
Read references/live-proof-routing.md before invoking a provider, private QA build, remote lease, packaged install, or native app.
agents.list, selected existing agent, canonical openai/<model>, and a real model response. Prove both the delivered model-final path and the separately persisted transcript or session; one passing route does not establish the other. An unavailable provider, unknown agent, mock, skipped test, fallback response, or an earlier head is not live proof.GatewayRequestError, UNKNOWN_AGENT, or an equivalent gateway error even when browser navigation, the HTTP status, or the image-capture command succeeds.qa/scenarios/index.yaml and scenario YAML. Inspect the actual harness and generated summary. Count a scenario only when the requested run reports a nonzero total, zero failures, and the exact model, provider mode, and relevant behavior.origin/main, current open and merged GitHub work, and sibling root causes. Count one broken invariant once, even when it produces multiple model, platform, route, lifecycle, or UI symptoms.$openclaw-testing host routing: trusted development checks run locally; remote proof needs an environment or source-isolation reason. Use the existing specialized workflow when that capability is required. Inspect actual exit status, nonzero scenario counts, and artifacts.$autoreview on the complete final refactor. Require the reviewer to compare owner boundaries and sibling implementations, confirm this is the best clean root-cause solution, and reject quick-fix residue even when tests pass. Resolve verified actionable findings and re-review substantive changes or unresolved concerns. Address actual human/bot findings and keep the PR body current; mechanical head movement and bot scores do not require another review pass.scripts/pr review, artifact, prepare, and merge workflow for authorized main landing.Hold a merge only for a concrete, nameable reason: an open defect; pending, skipped, stale, conflicting, or failing proof; an uncertain diagnosis; a product, public-contract, or design choice the maintainer has not made yet; or a security or authentication change that needs its listed owner. When the maintainer has already chosen the design (in chat or a recorded decision) and review and exact-head proof are green, land it autonomously; size, persistent state, or refactor breadth alone are not reasons to stop. Never park a ready PR, or write a PR body, that only asks for sign-off. If a review bot asks for approval of a decision the maintainer already made, record that decision through the native path (for example @clawsweeper approve) and continue. Mark genuinely undecided changes user review required with the specific question, and keep them outside the accepted-bug count.
Update the requested report throughout the campaign, not only at the end. Follow references/campaign-evidence.md for campaign and active-lane evidence and references/evidence-ledger.md for verified bug states. Separate discovered hypotheses, reproduced bugs, review-required PRs, exact-head validated fixes, and actually merged fixes. Report the frozen main SHA, worker lanes, resource use, live model and gateway proof, soak timestamps, actual failures, independent review, CI run IDs, PR links, and canonical merge SHAs.
Count only distinct, verified, authorized, actually merged low-risk root-cause fixes toward the operator's current explicit target. Never count the Auto QA skill PR, observations, pending PRs, skipped checks, existing unrelated merges, individual symptoms of the same defect, hypotheses, or review-required fixes. Keep iterating on this skill from real OpenClaw campaign evidence in a separate skill-only worktree and PR.
© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in .agents/skills/auto-qa of openclaw/openclaw.
Open the folder on GitHubat commit 3193e15
Auto QA next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Auto QA this skillopenclaw/openclaw | 392k | — | ~4.3k | Automated safety check: Pass | MIT | |
| Vercel Composition Patternssupabase/supabase | 111k | 58 repos | ~726 | Automated safety check: Pass | MIT | |
| Finishing a Development Branchobra/superpowers | 297k | 5 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Typescript Advanced Typesrolling-scopes/rsschool-app | 10k | 25 repos | ~4.2k | Automated safety check: Pass | MPL-2.0 | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 4 repos | ~1.1k | Automated safety check: Pass | MIT |
supabase/supabase
React composition patterns that scale. An agent skill from supabase/supabase.
obra/superpowers
Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.
rolling-scopes/rsschool-app
Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
onyx-dot-app/onyx
Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.
openclaw/openclaw
Summarize CodexBar local cost logs by model for Codex or Claude, including current or full breakdowns.
openclaw/openclaw
Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.
openclaw/openclaw
Feishu document read/write workflows. An agent skill from openclaw/openclaw.
openclaw/openclaw
Control tmux sessions/panes for interactive CLIs: list, capture output, send keys, paste text, monitor prompts.
openclaw/openclaw
Review, triage, repair, or land OpenClaw issues and pull requests with current-source evidence and the native maintainer workflow.
openclaw/openclaw
A skill your agent uses when controlling web pages with the OpenClaw browser tool, especially multi-step flows, login checks, tab management, or recovery from stale refs/timeouts.
Categories
Run OpenClaw-wide autonomous QA and live/stress campaigns across independent subsystem lanes, with verified fixes and a resumable evidence report. Auto QA is an agent skill from openclaw/openclaw. Run OpenClaw-wide autonomous QA and live/stress campaigns across independent subsystem lanes, with verified fixes and a resumable evidence report.
Auto QA fits situations like: development work in your project.
Run `npx skills add openclaw/openclaw --skill auto-qa -a claude-code`. Or copy the skill folder (.agents/skills/auto-qa in openclaw/openclaw) into .claude/skills/auto-qa in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openclaw/openclaw --skill auto-qa -a codex`. Or copy the skill folder (.agents/skills/auto-qa in openclaw/openclaw) into .agents/skills/auto-qa in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/openclaw --skill auto-qa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auto-qa, .gemini/skills/auto-qa, .github/skills/auto-qa and .opencode/skills/auto-qa in your project.
Going by SKILL.md and its folder, Auto QA needs the command-line tools its instructions call (git and codex). Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Auto QA is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Auto QA: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openclaw (a GitHub organization) maintains it in openclaw/openclaw, which has 391,562 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 10, 2026.
Source: openclaw/openclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.