QA Test and Fix
garrytan/gstack
Tests a site or service for bugs, fixes what it finds with one atomic commit per fix, and reports fix evidence and a ship-readiness summary at one of three depths.
Reads your git diff, decides whether the change needs browser QA, API checks or repo tests, runs that validation and reports pass or fail with evidence.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add Skyvern-AI/skyvern --skill qa -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Skyvern-AI/skyvern qa --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skyvern/cli/skills/qa .claude/skills/qa && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "qa" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skyvern/cli/skills/qa into .claude/skills/qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qa", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Skyvern-AI/skyvern/tree/main/skyvern/cli/skills/qaType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Skyvern-AI/skyvern --skill qa -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Skyvern-AI/skyvern qa --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skyvern/cli/skills/qa .agents/skills/qa && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "qa" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skyvern/cli/skills/qa into .agents/skills/qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qa", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Skyvern-AI/skyvern --skill qa -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Skyvern-AI/skyvern qa --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skyvern/cli/skills/qa .cursor/skills/qa && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "qa" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skyvern/cli/skills/qa into .cursor/skills/qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qa", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Skyvern-AI/skyvern.git --path skyvern/cli/skills/qa--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Skyvern-AI/skyvern --skill qa -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Skyvern-AI/skyvern qa --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skyvern/cli/skills/qa .gemini/skills/qa && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "qa" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skyvern/cli/skills/qa into .gemini/skills/qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qa", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Skyvern-AI/skyvern qaInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Skyvern-AI/skyvern --skill qa -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .github/skills && cp -r skills-src/skyvern/cli/skills/qa .github/skills/qa && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "qa" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skyvern/cli/skills/qa into .github/skills/qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qa", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Skyvern-AI/skyvern --skill qa -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Skyvern-AI/skyvern qa --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Skyvern-AI/skyvern.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skyvern/cli/skills/qa .opencode/skills/qa && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "qa" agent skill from https://github.com/Skyvern-AI/skyvern/tree/main/skyvern/cli/skills/qa into .opencode/skills/qa/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "qa", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
qaReads your git diff, decides whether the change needs browser QA, API checks or repo tests, runs that validation and reports pass or fail with evidence.
The /qa command starts from git diff, comparing against the last commit or the working tree, and reads every changed file that affects behavior: routes, components, visible text, forms, schemas, endpoints, validators and the tests that changed. It then classifies the diff as frontend or browser, backend API, backend-internal or mixed.
Frontend changes get browser QA against the dev server, backend API changes get the backend started locally and targeted requests run, backend-internal changes use the repo's own validation, and mixed changes get both. It accepts an explicit frontend URL or a short instruction such as validating a particular API. It is not a general site crawler and should not invent API checks unrelated to the diff; when the diff is empty there is nothing to QA. The result is a pass or fail report with concrete evidence.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 94c7ee1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitcurlngroknpmgoFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, curl and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Diff-Driven QA loads about 4.7k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 1,860 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
onnect(cdp_url="wss://<ngrok-subdomain>.ngrok-free.app/devtools/browser/<id>")Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Skyvern-AI/skyvern at commit 94c7ee1, republished under its AGPL-3.0 licence (© Skyvern-AI). 1,860 words, ~4,700 tokens.
.claude/skills/qa/SKILL.md (or your agent's skills folder).Read the diff, classify what changed, and run the right validation path: browser QA for frontend/browser changes, API validation for backend surface changes, repo-native validation for backend-internal changes, and both for mixed changes.
<!-- NOTE: .agents/skills/qa/SKILL.md is the repository canonical source.
Keep both synchronized copies in sync with it:
1. skyvern/cli/skills/qa/SKILL.md (bundled with the pip package)
2. skyvern/cli/mcp_tools/prompts.py (QA_TEST_CONTENT for the MCP prompt) -->
You changed code. This skill is diff-driven first: it reads what changed, understands the affected behavior, and validates that behavior with the right tools. It is not a generic website crawler, and it should not invent random API checks that are unrelated to the diff.
/qa # Diff-based: choose the right validation path automatically
/qa http://localhost:3000 # Same, explicit frontend URL
/qa -- validate the workflow filters APIgit difffrontend/browser, backend API, backend-internal, or mixed# What files changed?
git diff --name-only HEAD~1 # vs last commit (if changes are committed)
git diff --name-only # vs working tree (if uncommitted)
# Full diff for context
git diff HEAD~1 # or git diff for uncommittedPick whichever diff has content. If both are empty, there is nothing diff-driven to QA.
Read the full contents of every changed file that affects behavior:
.tsx, .jsx, .ts, .js, .css, .htmlLook for:
| Mode | Trigger | Primary validation |
|---|---|---|
| Frontend/browser | UI/routes/components/styles changed | Browser QA against the dev server |
| Backend API | Route handlers, request/response schemas, or externally visible API behavior changed | Start backend locally and run targeted API requests |
| Backend-internal | Services/workers/business logic changed without public API surface changes | Repo-native fast checks plus targeted tests |
| Mixed | Frontend/browser and backend changed together | Backend validation first, then frontend/browser QA |
Use these rules:
Mixed.backend-internal.Use browser automation against the dev server. Validate the specific UI changes plus 1-2 adjacent regression checks.
Use the repo's documented local startup and auth instructions, start the backend if needed, identify the changed endpoint(s), and run targeted HTTP requests to validate the changed contract.
Run the repo's fast verification commands first, then targeted unit/integration/scenario tests for the changed logic. Only start the backend and do live API calls if the change affects exposed behavior.
Validate the backend first, then run frontend/browser QA against the flow that depends on it. If the backend contract is broken, frontend results are not trustworthy.
If the user provided a URL, use it. Otherwise auto-detect common local ports:
5173, 3000, 3001, 8080, 8000, 4200If none respond, start the most direct repo-documented local command for the changed surface. If the diff needs both frontend and backend running together and the repo provides a combined frontend/backend dev script, prefer that. Only ask the user to start something manually if the repo has no documented command or startup fails.
Try these in order:
skyvern_browser_session_create(local=true, headless=false, timeout=15)Use local=true so the browser can reach localhost.
If local session creation fails because the MCP server is remote, the cloud browser cannot reach
localhost. Tell the user to run:
# Terminal 1: Launch a local browser with CDP exposed
skyvern browser serve --port 9222
# Terminal 2: Tunnel it to the internet
ngrok http 9222Then connect:
skyvern_browser_session_connect(cdp_url="wss://<ngrok-subdomain>.ngrok-free.app/devtools/browser/<id>")The user can get the browser ID from the skyvern browser serve output or by calling the
ngrok URL's /json endpoint.
skyvern_browser_session_create(timeout=15)Only works for publicly reachable URLs. localhost URLs will not work here.
For each changed frontend file, create targeted checks. Examples:
Test 1: Settings page renders the new "Retry failed run" button
- Navigate to /settings/runs
- Assert: button with text "Retry failed run" exists
- Click it
- Assert: success toast appears
Test 2: Adjacent regression
- Verify the existing "Delete run" action still works or is still visibleBe specific. Do not write "verify the page works."
For each test case:
skyvern_navigate(url="http://localhost:<port>/<route>")Health gate after navigation:
In extension mode, use this health gate. Do not call skyvern_evaluate. Before each skyvern_navigate to a route under test, call skyvern_get_errors(clear=True), skyvern_console_messages(clear=True), skyvern_handle_dialog(clear=True), and skyvern_network_requests(clear=True); discard what they return.
skyvern_tab_list()
skyvern_get_errors()
skyvern_console_messages(level="error")
skyvern_get_html(selector="body")
skyvern_find(by="role", value="alert")
skyvern_find(by="role", value="dialog")
skyvern_handle_dialog()PASS requires the active tab URL to match the expected route, with no unexpected login redirect.
The body must contain the expected page content, not only scripts or an empty app container.
Require no unexpected error text, visible alerts, visible dialogs, JavaScript errors, console errors, or JavaScript dialog events.
skyvern_handle_dialog reads dialog history; JavaScript dialogs are auto-dismissed by default.
If a call fails or evidence is incomplete, record FAIL and stop this test. Do not treat missing evidence as PASS.
Outside extension mode, use this health gate:
skyvern_evaluate(expression="(() => {
const errors = [];
const body = document.body?.innerText || '';
if (body.includes('Something went wrong')) errors.push('error_message');
if (body.includes('Cannot read properties')) errors.push('js_error_in_ui');
if (/\\bundefined\\b/.test(body) && !/\\bif\\b|\\btypeof\\b|\\bdocument|tutorial|example/i.test(body) && body.length < 5000) errors.push('undefined_text');
if (body.includes('connection refused')) errors.push('connection_refused');
if (/sign.?in|log.?in|auth/i.test(window.location.pathname)) errors.push('auth_redirect');
if (document.querySelector('[role=\"alert\"]')) errors.push('alert_element');
if (!document.querySelector('main, [role=\"main\"], nav, header, h1, h2, [class*=\"layout\" i], [class*=\"page\" i], [class*=\"app\" i]'))
errors.push('blank_page');
return JSON.stringify({ pass: errors.length === 0, errors });
})()")In extension mode, use skyvern_find, skyvern_get_html, skyvern_get_value, or skyvern_tab_list for assertions.
skyvern_find(by="role", value="button")
skyvern_get_html(selector="h1")
skyvern_tab_list()Outside extension mode, prefer deterministic DOM assertions:
skyvern_evaluate(expression="!!document.querySelector('button')")
skyvern_evaluate(expression="document.querySelector('h1')?.textContent?.trim()")
skyvern_evaluate(expression="window.location.pathname")Use interaction tools when needed:
skyvern_act(prompt="Click the 'Retry failed run' button")
skyvern_act(prompt="Fill the email field with 'test@example.com' and click Submit")
skyvern_validate(prompt="The page shows the success toast and the form is no longer loading")
skyvern_screenshot()In extension mode, call skyvern_network_requests() and inspect captured requests for failures or HTTP status codes of 400 or greater.
If capture is unavailable or incomplete, report the network check as unverified.
Outside extension mode, check for failed network requests once per page:
skyvern_evaluate(expression="(() => {
const entries = performance.getEntriesByType('resource').filter(e => e.responseStatus >= 400);
return JSON.stringify({ failed: entries.map(e => ({ url: e.name, status: e.responseStatus })).slice(0, 5) });
})()")Before starting the server or sending requests, read the repo's local instructions:
README, AGENTS.md, CLAUDE.md, Makefile, package.json, pyproject.tomlDo not guess the startup command if the repo already documents one.
If the backend is not already responding on the expected local port:
If the repo requires background processes, start them in the background and keep notes on how you did it.
Use the diff to answer:
Do not stop at the route file. Read the full handler, schema, and any changed tests.
For each changed endpoint, create targeted checks:
Examples:
Test 1: GET /api/runs returns the new field in the response body
Test 2: GET /api/runs?status=missing returns an empty list, not a 500
Test 3: POST /api/runs rejects invalid payload with a 4xx validation error
Test 4: PATCH /api/runs/:id updates the record and a follow-up GET shows the changeUse the repo's documented auth scheme and local base URL. Use curl, the repo SDK, or a small
one-off client if that is clearer than shell quoting. Prefer simple, inspectable commands.
Examples:
curl -sS -H "Authorization: Bearer <token>" \
"http://localhost:<port>/api/..."
curl -sS -X POST \
-H "Content-Type: application/json" \
-H "<auth-header>: <token>" \
-d '{"example":"value"}' \
"http://localhost:<port>/api/..."Capture:
If the endpoint is authenticated and you cannot obtain local credentials from repo docs, say so clearly and stop rather than faking coverage.
If the diff is backend-only but does not change an exposed endpoint or UI flow:
Examples of appropriate checks:
pytest, npm test, go test, or equivalentExamples of inappropriate checks:
## QA Report
### Validation Mode
- Mode: Backend API
- Scope: `routes/runs.py`, `schemas/run_response.py`
### Changes Tested
- Added `retryable` field to run responses
- Updated `status` filter handling
### Results
| # | Test | Result | Evidence |
|---|------|--------|----------|
| 1 | GET /api/runs returns `retryable` for valid runs | PASS | HTTP 200, field present in response |
| 2 | GET /api/runs?status=missing returns empty list | PASS | HTTP 200, `[]` |
| 3 | GET /api/runs?status=invalid returns validation error | PASS | HTTP 422 |
| 4 | Frontend runs page still renders filter state | PASS | screenshot_3 |
### Issues Found
1. `retryable` is missing from one branch of the response serializer.
### Verdict
3/4 tests passed. 1 issue found.Report the evidence that actually matters:
After generating the QA report, persist it to the pull request as a sticky comment so the evidence survives beyond the conversation.
Write the full report markdown from Step 5 to .qa/latest-report.md with a filesystem editing tool.
Do not place report text in a shell command, variable assignment, heredoc, or command substitution.
Then run the fixed command below. It reads .qa/latest-report.md and passes it to gh as a literal
argument vector without shell evaluation, updating this user's own <!-- skyvern-qa-report --> comment
when one already exists:
skyvern skill post-qa-reportIf no PR exists for the current branch, the command leaves the report at .qa/latest-report.md.
Tell the user to run /qa again after creating a PR. Do not create a PR just to post a QA report.
Screenshots taken during QA (via skyvern_screenshot()) are saved locally for the agent's
verification. They are not uploaded to the PR comment because GitHub's API does not support
image uploads in issue comments. The text report describes what was observed.
If the user asks to preserve screenshots, save them to .qa/screenshots/ and tell the user
the local path. Do not include local file paths in the PR comment — they are meaningless to
other reviewers.
skyvern skill post-qa-report; do not reconstruct its gh calls in a shell.<!-- skyvern-qa-report --> marker, short commit hash, and UTC timestamp.gh is not available or not authenticated, fall back to saving the report locally and tell the user.| Problem | Action |
|---|---|
| No git diff found | Ask what behavior to validate, then fall back to explore mode |
| Frontend dev server not running | Start the most direct repo-documented local command for the changed surface; prefer a combined dev command only when the validation needs both frontend and backend; only ask the user if no documented command exists or startup fails |
| Backend server not running | Start the most direct repo-documented local command for the changed surface; prefer a combined dev environment command only when the validation needs both sides |
| Cannot identify changed endpoint | Read changed routes, schemas, and tests before proceeding |
| Auth required but no local creds available | Report the blocker clearly; do not fake coverage |
| Component does not render | Capture screenshot and specific UI error |
| API returns unexpected 5xx | Save request/response evidence and report the regression |
Before closing, fetch the session recording so you can include it in the QA report.
skyvern_browser_session_get(session_id="pbs_xxx")
→ Returns app_url (watch in browser) and recordings (download URLs)Or simply close — skyvern_browser_session_close() now returns recording data too:
skyvern_browser_session_close()
→ { session_id, closed, app_url, recordings: [{url, filename}], downloaded_files: [{url, filename}] }skyvern browser session get --session pbs_xxx --json
# → { "app_url": "https://...", "recordings": [...] }
skyvern browser session close --session pbs_xxx --json
# → { "session_id": "pbs_xxx", "closed": true, "app_url": "https://...", "recordings": [...] }Include in the QA report:
app_url valuerecordings[].urlAlways close browser sessions when done:
skyvern_browser_session_close()If you started local servers or background processes, leave the user a clear note about what is still running.
If there is no useful diff, fall back to explicit exploration:
The primary mode is still diff-driven. Always try to understand the code changes first.
© Skyvern-AI, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skyvern/cli/skills/qa of Skyvern-AI/skyvern.
Open the folder on GitHubat commit 94c7ee1
Diff-Driven QA next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Diff-Driven QA this skillSkyvern-AI/skyvern | 23k | — | ~4.7k | Automated safety check: Warn | AGPL-3.0 | |
| QA Test and Fixgarrytan/gstack | 136k | — | ~13k | Automated safety check: Notes | MIT | |
| QA Report Onlygarrytan/gstack | 136k | — | ~11k | Automated safety check: Notes | MIT | |
| Playwright Regression Testingfugazi/test-automation-skills-agents | 247 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Playwright Screen Recordingliaohch3/claude-tap | 3.3k | — | ~714 | Automated safety check: Pass | MIT | |
| Reprovaadin/web-components | 582 | — | ~1.3k | Automated safety check: Pass | None |
garrytan/gstack
Tests a site or service for bugs, fixes what it finds with one atomic commit per fix, and reports fix evidence and a ship-readiness summary at one of three depths.
garrytan/gstack
Tests a browser app, API, CLI, job, worker or webhook and writes a structured bug report with repro steps, without changing any code.
fugazi/test-automation-skills-agents
Govern Playwright TypeScript regression suites across many tests.
liaohch3/claude-tap
Records headless Playwright sessions as .webm videos to show a bug fix working or to give pull request reviewers visual evidence.
vaadin/web-components
Reproduce a Vaadin web component bug from a GitHub issue in vaadin/web-components.
reticlehq/reticle
Sweeps a running web app by clicking every reachable control, then reports dead buttons, console errors, failed requests and mismatches between API data and the screen.
Skyvern-AI/skyvern
Picks the right Skyvern CLI command for a web task, from quick yes/no checks to reusable multi-page workflows, instead of falling back to plain page fetching.
Skyvern-AI/skyvern
Walks through a Skyvern open-source release bump: update the version, rebuild the Python and TypeScript SDKs with Fern, commit, and open a pull request.
Skyvern-AI/skyvern
Automates websites with Skyvern's AI browser agent to fill forms, extract data, download files, log in and run multi-step workflows through SDKs, REST, MCP or a CLI.
Skyvern-AI/skyvern
Smoke-tests a Skyvern deployment by checking the backend API, frontend rendering, browser session provisioning and workflow execution in sequence.
Skyvern-AI/skyvern
Reads your git diff, writes a handful of happy-path browser smoke tests, runs them with Skyvern or Chrome DevTools MCP and posts screenshot evidence to the PR.
Works with
Categories
Reads your git diff, decides whether the change needs browser QA, API checks or repo tests, runs that validation and reports pass or fail with evidence. The /qa command starts from git diff, comparing against the last commit or the working tree, and reads every changed file that affects behavior: routes, components, visible text, forms, schemas, endpoints, validators and the tests that changed. It then classifies the diff as frontend or browser, backend API, backend-internal or mixed.
Diff-Driven QA fits situations like: validating code changes before opening a pull request; checking a UI change in the browser against the local dev server; running targeted API requests for changed route handlers; deciding which kind of validation a mixed frontend and backend diff needs.
Run `npx skills add Skyvern-AI/skyvern --skill qa -a claude-code`. Or copy the skill folder (skyvern/cli/skills/qa in Skyvern-AI/skyvern) into .claude/skills/qa in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Skyvern-AI/skyvern --skill qa -a codex`. Or copy the skill folder (skyvern/cli/skills/qa in Skyvern-AI/skyvern) into .agents/skills/qa in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Skyvern-AI/skyvern --skill qa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qa, .gemini/skills/qa, .github/skills/qa and .opencode/skills/qa in your project.
Going by SKILL.md and its folder, Diff-Driven QA needs the command-line tools its instructions call (git, curl, ngrok, npm and go). Our summary lists: A git repository with a diff to test; A locally runnable dev server or backend for the changed code.
SKILL.md contains no URLs. Its commands use git, curl and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a paste, webhook or tunnelling service often used to send data out. Read the flagged lines before installing; the check is not a guarantee either way.
Diff-Driven QA is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Diff-Driven QA: QA Test and Fix (garrytan/gstack, 136k stars), QA Report Only (garrytan/gstack, 136k stars), Playwright Regression Testing (fugazi/test-automation-skills-agents, 247 stars) and Playwright Screen Recording (liaohch3/claude-tap, 3.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Skyvern-AI (a GitHub organization) maintains it in Skyvern-AI/skyvern, which has 23,162 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.
Source: Skyvern-AI/skyvern on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.