Senior QA
nicepkg/auto-company
Comprehensive QA and testing skill for quality assurance, test automation, and testing strategies for ReactJS, NextJS, NodeJS applications.
Produce a risk matrix or heatmap that quantifies what could break by business impact × probability, runs failure mode analysis on the top items, and maps test coverage to risk zones.
$ npx skills add petrkindlmann/qa-skills --skill risk-based-testing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install petrkindlmann/qa-skills risk-based-testing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/risk-based-testing .claude/skills/risk-based-testing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "risk-based-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/risk-based-testing into .claude/skills/risk-based-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "risk-based-testing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/petrkindlmann/qa-skills/tree/main/skills/risk-based-testingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add petrkindlmann/qa-skills --skill risk-based-testing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install petrkindlmann/qa-skills risk-based-testing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/risk-based-testing .agents/skills/risk-based-testing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "risk-based-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/risk-based-testing into .agents/skills/risk-based-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "risk-based-testing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add petrkindlmann/qa-skills --skill risk-based-testing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install petrkindlmann/qa-skills risk-based-testing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/risk-based-testing .cursor/skills/risk-based-testing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "risk-based-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/risk-based-testing into .cursor/skills/risk-based-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "risk-based-testing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/petrkindlmann/qa-skills.git --path skills/risk-based-testing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add petrkindlmann/qa-skills --skill risk-based-testing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install petrkindlmann/qa-skills risk-based-testing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/risk-based-testing .gemini/skills/risk-based-testing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "risk-based-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/risk-based-testing into .gemini/skills/risk-based-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "risk-based-testing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install petrkindlmann/qa-skills risk-based-testingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add petrkindlmann/qa-skills --skill risk-based-testing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/risk-based-testing .github/skills/risk-based-testing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "risk-based-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/risk-based-testing into .github/skills/risk-based-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "risk-based-testing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add petrkindlmann/qa-skills --skill risk-based-testing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install petrkindlmann/qa-skills risk-based-testing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/risk-based-testing .opencode/skills/risk-based-testing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "risk-based-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/risk-based-testing into .opencode/skills/risk-based-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "risk-based-testing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
risk-based-testingProduce a risk matrix or heatmap that quantifies what could break by business impact × probability, runs failure mode analysis on the top items, and maps test coverage to risk zones.
Risk Based Testing is an agent skill from petrkindlmann/qa-skills. Produce a risk matrix or heatmap that quantifies what could break by business impact × probability, runs failure mode analysis on the top items, and maps test coverage to risk zones. Includes stakeholder interview frameworks and continuous reassessment. Run this BEFORE test-strategy or test-planning. Use when: "risk assessment," "risk matrix," "risk heatmap," "what could break," "critical paths," "failure modes," "where to focus testing." Not for: multi-quarter QA direction — use test-strategy. Not for: a single…
Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/examples.md`).
It sits in Testing & QA, covering Test strategy, Legal risk assessment and Test coverage. The repository describes itself as: 50 QA and test-automation skills for Claude Code, Codex, Cursor, and any Agent Skills Standard runtime. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b3bb61b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
satisfice.comdevelopsense.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Risk Based Testing loads about 5.3k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 181 tokens; SKILL.md has 2,225 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from petrkindlmann/qa-skills at commit b3bb61b, republished under its MIT licence (© petrkindlmann). 2,225 words, ~5,335 tokens.
.claude/skills/risk-based-testing/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.<objective>
Equal coverage across all features wastes effort on low-risk areas while leaving critical paths under-tested — a 90% coverage target on a settings page is effort stolen from checkout. This skill discovers risk, quantifies it as impact × probability, maps test density to risk zones, and keeps the assessment current as the product evolves. Output is a scored risk matrix that feeds `test-strategy` and `test-planning`.
</objective>
| Situation | Start at |
|---|---|
| New product, no risk model yet | Phase 1 (Identification) → run the full 6 phases |
| Post-incident reassessment | Phase 6 (Reassessment triggers), then re-score the affected items in Phase 2 |
| AI/LLM feature to assess | Phase 3 (AI/LLM failure classes), score each class in Phase 2 |
| Sprint refresh of an existing matrix | Phases 4–5 (Heatmap + Coverage alignment) on changed features |
| Verify an old heatmap is still true | Phase 6 signals + Anti-Pattern "Risk Theater" |
Check .agents/qa-project-context.md first — if it exists, use it as the foundation and skip questions already answered there. Gather the rest from stakeholders across engineering, product, and operations.
1. Identify → 2. Classify → 3. Analyze → 4. Heatmap → 5. Coverage → 6. Reassess → (repeat)
↑
score ≥ 10 only; skip to 4 if no items reach thresholdEnumerate everything that could go wrong. Cast a wide net. Sources include:
git log --stat <file> is for per-commit inspection of a specific suspect, not for ranking.Use HTSM v6.3 (Heuristic Test Strategy Model, Bach) as a Phase-1 lens — its state-based and boundary heuristics surface risks a pure feature-list misses. Download: https://www.satisfice.com/download/heuristic-test-strategy-model
Output: a raw list of risk items, each describing what could fail and what the consequence would be.
Categorize each risk item along two axes.
Impact categories (how bad is it):
| Score | Level | Definition | Examples |
|---|---|---|---|
| 5 | Catastrophic | Revenue loss, data breach, legal action, user safety | Payment processing fails, PII exposed |
| 4 | Major | Significant user impact, SLA violation, major feature broken | Login broken for segment, data corruption |
| 3 | Moderate | Workflow disrupted, workaround exists | Search returns wrong results, export fails |
| 2 | Minor | Cosmetic or minor UX issue | Alignment bug, slow non-critical page |
| 1 | Negligible | No user impact, internal only | Admin tooltip wrong, log format issue |
Probability categories (how likely is it):
| Score | Level | Definition | Indicators |
|---|---|---|---|
| 5 | Frequent | Expected in most releases | High code churn, no tests, complex logic |
| 4 | Likely | Will probably happen within a quarter | Recent changes, partial coverage, known tech debt |
| 3 | Possible | Could happen, has happened before | Moderate complexity, some coverage |
| 2 | Unlikely | Improbable but not impossible | Stable code, good coverage, simple logic |
| 1 | Rare | Requires exceptional circumstances | Well-tested, rarely changed, simple |
Composite score = Impact × Probability. Frequent changes indicate defect probability, so a Moderate-impact (3) feature under heavy churn scores Probability 5 → Risk score: 15 → CRITICAL zone, despite "only" moderate impact. The composite score drives priority, not impact alone.
For each high-risk item (score ≥ 10), perform a detailed failure mode analysis.
Feature/Component: [name]
Risk Score: [impact × probability]
Failure Mode 1: [what specifically can fail]
Trigger: [what causes this failure]
Blast Radius: [users affected, systems affected, data affected]
Detection Method: [how would we know -- monitoring, user report, test]
Current Mitigation: [existing tests, monitoring, feature flags, fallbacks]
Gap: [what is missing from current mitigation]
Failure Mode 2: ...Example — E-commerce Checkout (Risk Score 20, Impact 5 × Probability 4):
Failure Mode 1: Payment charge succeeds but order not recorded
Trigger: Race condition between payment API callback and order write
Blast Radius: Individual users; money charged but no order confirmation
Detection Method: Payment reconciliation job (runs hourly), user complaint
Current Mitigation: Idempotency key on payment, retry on order write
Gap: No automated test for the race condition; reconciliation delay is 1 hour
Failure Mode 2: Discount code applies incorrect amount
Trigger: Percentage discount on already-discounted item
Blast Radius: All users with stacked discounts; revenue leakage
Detection Method: Margin monitoring alert (>5% deviation)
Current Mitigation: Unit tests for single discounts
Gap: No tests for discount stacking; no tests for rounding edge cases
Failure Mode 3: Inventory not reserved during checkout
Trigger: Concurrent purchases of last-stock item
Blast Radius: Oversold items, fulfillment failure, customer trust
Detection Method: Fulfillment team discovers during packing
Current Mitigation: Database-level stock check on order creation
Gap: No load test simulating concurrent last-item purchasesFor AI/LLM features, classify against these CT-GenAI classes and score Impact and Probability independently like any other risk. The mitigation is the existence of an automated eval suite, not a single manual test.
AI/LLM-specific failure classes (from ISTQB CT-GenAI v1.1, effective 27 April 2026):
- Hallucination / reasoning error — Impact: moderate to major; Probability: high without explicit prompt-eval coverage. Detection: golden-dataset evals, fact-check assertions (see
ai-system-testing).- Bias — Impact: catastrophic in regulated industries (finance, healthcare, hiring). Probability: dataset-dependent. Detection: counterfactual evals, demographic-parity checks.
- Prompt injection / jailbreak — Impact: major (data exfiltration, prompt extraction). Probability: high for any externally-facing LLM feature. Detection: Garak, PyRIT, Promptfoo redteam.
- Privacy leak — Impact: catastrophic under GDPR/CCPA/EU AI Act. Probability: dataset-dependent. Detection: PII scanning of training data and prompts.
- AI Act / regulatory non-compliance — Impact: catastrophic (fines, ban). Probability: high for EU-facing AI features. Detection: see
compliance-testing.Tool freshness (mid-2026): PyRIT now lives at microsoft/PyRIT — the old Azure-hosted repo was archived March 2026, so do not point new redteam work at the legacy Azure path. Promptfoo was acquired by OpenAI (March 2026) but remains MIT-licensed. Garak is current and unchanged.
Reference frameworks: CT-GenAI v1.1 (ISTQB, effective 27 April 2026) codifies the AI/LLM classes above. WQR 2025-26 (Capgemini, 17th edition, Nov 2025) gives the adoption-stage framing for AI risk planning.
Plot all risk items on a 5×5 matrix to communicate priorities and drive coverage decisions.
PROBABILITY
Rare(1) Unlikely(2) Possible(3) Likely(4) Frequent(5)
+----------+-----------+-----------+----------+-----------+
Catastrophic(5) | 5 MED | 10 HIGH | 15 CRIT | 20 CRIT | 25 CRIT |
+----------+-----------+-----------+----------+-----------+
Major(4) | 4 LOW | 8 MED | 12 HIGH | 16 CRIT | 20 CRIT |
I +----------+-----------+-----------+----------+-----------+
M Moderate(3) | 3 LOW | 6 MED | 9 MED | 12 HIGH | 15 CRIT |
P +----------+-----------+-----------+----------+-----------+
A Minor(2) | 2 LOW | 4 LOW | 6 MED | 8 MED | 10 HIGH |
C +----------+-----------+-----------+----------+-----------+
T Negligible(1) | 1 LOW | 2 LOW | 3 LOW | 4 LOW | 5 MED |
+----------+-----------+-----------+----------+-----------+Zone boundaries and action mapping:
| Zone | Score Range | Color | Testing Action |
|---|---|---|---|
| CRITICAL | 15-25 | Red | Automate fully + monitor in production + load test + manual exploratory |
| HIGH | 10-14 | Orange | Automate fully + periodic manual review |
| MEDIUM | 5-9 | Yellow | Automate happy path + key error cases |
| LOW | 1-4 | Green | Manual testing on release or skip entirely |
Populated example (where each named risk lands):
Rare(1) Unlikely(2) Possible(3) Likely(4) Frequent(5)
Catastrophic(5) Auth bypass Payments fail Checkout crash
Major(4) Data export Search broken User upload
Moderate(3) Report fmt Email deliver Profile edit
Minor(2) Footer link Tooltip text Theme switch
Negligible(1) Admin labelMap test density to risk level. Every zone gets a prescribed approach.
| Risk Zone | Unit Tests | Integration Tests | E2E Tests | Manual Testing | Monitoring |
|---|---|---|---|---|---|
| CRITICAL (15-25) | 90%+ branch coverage | All service boundaries | Full user journey + error paths | Exploratory each release | Real-time alerts, synthetic checks |
| HIGH (10-14) | 80%+ branch coverage | Key interactions | Happy path + top 3 error paths | Spot checks | Dashboard + daily review |
| MEDIUM (5-9) | 70%+ branch coverage | Happy path only | Happy path only | On major changes | Weekly review |
| LOW (1-4) | Basic happy path | None required | None required | On initial build | None required |
Compare current coverage against required coverage per risk zone:
Feature: [name]
Risk Zone: [CRITICAL / HIGH / MEDIUM / LOW] Risk Score: [number]
Required Coverage:
Unit: [target %] Current: [actual %] Gap: [delta]
Integration: [required?] Current: [exists? y/n] Gap: [missing scenarios]
E2E: [required?] Current: [exists? y/n] Gap: [missing flows]
Monitoring: [required?] Current: [exists? y/n] Gap: [missing alerts]
Priority: [P0 / P1 / P2 / P3]
Estimated Effort: [hours / story points]
Owner: [name] Target Sprint: [sprint number]A churn signal forces this worksheet open: a module that changed 47 times in 3 months (Probability → 5) with only 40% branch coverage and no integration tests jumps zones (e.g. MEDIUM → HIGH), and the new coverage target is justified by the churn, not picked arbitrarily.
See references/examples.md for four fully-scored examples (checkout, media platform, third-party API, auth) showing the path from risk score to prescribed coverage.
Risk assessment is not a one-time activity. Build reassessment into the team's rhythm.
Reassessment triggers:
Continuous risk signals to monitor:
git log --since="3 months ago" --name-only --format= | grep -v '^$' | sort | uniq -c | sort -rn | head -20Applying the same coverage target to every feature regardless of risk. A 90% target on a settings page wastes effort that should go to payments or auth. Let the risk model drive allocation.
Creating a matrix during planning and never updating it. The product, team, and dependencies all change. A model from 6 months ago is outdated and out of date the moment a dependency, feature, or incident shifts the picture — it does not reflect today. Schedule reassessment and enforce it.
Treating bugs caught in staging as pure successes. If a critical bug was caught only by manual testing, the automated safety net has a gap. Document near-misses and adjust the model.
Going through the motions (filling matrices, drawing heatmaps) without changing test allocation. If the heatmap exists but coverage does not align to it, the exercise was wasted. Verify alignment quarterly. Bolton's "Quality Engineering Is Not Testing" (2026-04-20) warns of exactly this — building a heatmap and calling it "QE done." Reference: https://developsense.com/blog/2026/04/quality-engineering-is-not-testing
Over-weighting past incidents and under-weighting new vectors. A module that failed 2 years ago and was since rewritten may no longer be high risk; a brand-new third-party integration has unknown risk that deserves attention.
Severity is how bad a failure is; priority is how urgently to test it. A catastrophic-but-rare failure (earthquake destroys data center) can be lower priority than a moderate-but-frequent one (search occasionally wrong). Use the composite score, not impact alone.
Prove the matrix is real and aligned before calling it done — smallest check first:
git ls-files | grep -E 'risk-matrix|qa-project-context' returns the file. An untracked draft on someone's laptop is not a risk model..agents/qa-project-context.md risk section or a committed risk-matrix.md), with every in-scope feature scored on impact (1-5) and probability (1-5)references/)© petrkindlmann, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/risk-based-testing of petrkindlmann/qa-skills.
Open the folder on GitHubat commit b3bb61b
Risk Based Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Risk Based Testing this skillpetrkindlmann/qa-skills | 165 | — | ~5.3k | Automated safety check: Pass | MIT | |
| Senior QAnicepkg/auto-company | 192 | 3 repos | ~1.1k | Automated safety check: Notes | None | |
| Designing TestsCloudAI-X/opencode-workflow | 275 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Automated Test Planningtestdouble/han | 279 | — | ~6.7k | Automated safety check: Pass | MIT | |
| QA LeadIbrahim-3d/orchestrator-supaconductor | 380 | — | ~2.5k | Automated safety check: Pass | AGPL-3.0 | |
| Manual Test Planningtestdouble/han | 279 | — | ~2.9k | Automated safety check: Pass | MIT |
nicepkg/auto-company
Comprehensive QA and testing skill for quality assurance, test automation, and testing strategies for ReactJS, NextJS, NodeJS applications.
CloudAI-X/opencode-workflow
Guides test strategy, TDD/BDD approaches, test coverage planning, and testing best practices.
testdouble/han
Produce a standalone test plan by analyzing code for test coverage gaps and edge cases.
Ibrahim-3d/orchestrator-supaconductor
Quality assurance consultation for Conductor orchestrator. An agent skill from Ibrahim-3d/orchestrator-supaconductor.
testdouble/han
Produce a plain-language manual test plan from the context supplied to it — an executive summary, a high-level list of named tests, and a detail section per test with the steps a person follows by…
einverne/dotfiles
Testing methodologies, test-driven development (TDD), unit and integration testing, and testing best practices across multiple frameworks.
petrkindlmann/qa-skills
Test for WCAG 2.2 AA compliance with axe-core + Playwright, keyboard navigation audits, screen reader testing, ARIA pattern validation, and legal compliance mapping (ADA, EAA, Section 508).
petrkindlmann/qa-skills
Goal-driven E2E testing where a browser agent (Playwright MCP / computer-use) reads a natural-language goal and explores the app via the accessibility tree to assert outcomes — no pre-written script.
petrkindlmann/qa-skills
Use AI to write NEW test code from specs, PRDs, user stories, code diffs, bug reports, or OpenAPI specs.
petrkindlmann/qa-skills
Test REST and GraphQL APIs with Playwright APIRequestContext, Supertest, or standalone HTTP clients.
petrkindlmann/qa-skills
Design CI/CD pipelines that run test suites. An agent skill from petrkindlmann/qa-skills.
petrkindlmann/qa-skills
Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…
Categories
Produce a risk matrix or heatmap that quantifies what could break by business impact × probability, runs failure mode analysis on the top items, and maps test coverage to risk zones. Risk Based Testing is an agent skill from petrkindlmann/qa-skills. Produce a risk matrix or heatmap that quantifies what could break by business impact × probability, runs failure mode analysis on the top items, and maps test coverage to risk zones.
Risk Based Testing fits situations like: : risk assessment; what could break; where to focus testing. Not for: multi-quarter QA direction — use test-strategy.
Run `npx skills add petrkindlmann/qa-skills --skill risk-based-testing -a claude-code`. Or copy the skill folder (skills/risk-based-testing in petrkindlmann/qa-skills) into .claude/skills/risk-based-testing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add petrkindlmann/qa-skills --skill risk-based-testing -a codex`. Or copy the skill folder (skills/risk-based-testing in petrkindlmann/qa-skills) into .agents/skills/risk-based-testing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add petrkindlmann/qa-skills --skill risk-based-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/risk-based-testing, .gemini/skills/risk-based-testing, .github/skills/risk-based-testing and .opencode/skills/risk-based-testing in your project.
Going by SKILL.md and its folder, Risk Based Testing needs the command-line tools its instructions call (git).
SKILL.md names 2 domains. As links in the text: satisfice.com and developsense.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Risk Based Testing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Risk Based Testing: Senior QA (nicepkg/auto-company, 192 stars), Designing Tests (CloudAI-X/opencode-workflow, 275 stars), Automated Test Planning (testdouble/han, 279 stars) and QA Lead (Ibrahim-3d/orchestrator-supaconductor, 380 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
petrkindlmann (a GitHub user) maintains it in petrkindlmann/qa-skills, which has 165 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on June 10, 2026.
Source: petrkindlmann/qa-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.