Agent skill

QA Session

by softspark in softspark/ai-toolkit

Interactive QA: user reports bugs conversationally, agent files GitHub issues.

Apache-2.0Auto-check: notesDevelopment

Install QA Session

skills CLI
$ npx skills add softspark/ai-toolkit --skill qa-session -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit qa-session --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/qa-session .claude/skills/qa-session && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
qa-session
GitHub stars
179
Token cost
~1.2k tokens
SKILL.md length
533 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

Interactive QA: user reports bugs conversationally, agent files GitHub issues.

  • Works in 5 steps: Listen and Lightly Clarify → Explore Codebase in Background → Assess Scope → …
  • Development work in your project
  • SKILL.md covers Usage, What This Command Does, For Each Issue and Rules, plus 2 more sections
  • Calls gh

What it does

QA Session is an agent skill from softspark/ai-toolkit. Interactive QA: user reports bugs conversationally, agent files GitHub issues. Triggers: QA session, report bug, file issue, conversational QA, bug intake.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with GitHub. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

When your agent uses it

  • Development work in your project

Example prompts

  • “/qa-session”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Agent

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Listen and Lightly Clarify
  2. Explore Codebase in Background
  3. Assess Scope
  4. File GitHub Issues
  5. Continue Session

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Agent

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

QA Session loads about 1.2k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 533 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, Agent

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 533 words, ~1,162 tokens.

Download SKILL.mdSave it as .claude/skills/qa-session/SKILL.md (or your agent's skills folder).
name
qa-session
description
Interactive QA: user reports bugs conversationally, agent files GitHub issues. Triggers: QA session, report bug, file issue, conversational QA, bug intake.
allowed-tools
Read, Grep, Glob, Bash, Agent
user-invocable
true
effort
high
argument-hint
[area to QA or first bug report]

QA Session

$ARGUMENTS

Interactive QA session. User describes problems, agent clarifies, explores codebase, and files GitHub issues.

Usage

/qa-session [area to QA or first bug report]

What This Command Does

  1. Listens to user's bug report
  2. Clarifies with 2-3 focused questions max
  3. Explores codebase in background for context and domain language
  4. Assesses scope — single issue or breakdown
  5. Files GitHub issues via gh issue create
  6. Continues until user says done

For Each Issue

1. Listen and Lightly Clarify

Let user describe the problem. Ask at most 2-3 short questions on:

  • Expected vs actual behavior
  • Steps to reproduce
  • Consistent or intermittent

Don't over-interview. If clear enough, move on.

2. Explore Codebase in Background

Kick off Agent (subagent_type=Explore) in background to:

  • Learn domain language (check UBIQUITOUS_LANGUAGE.md)
  • Understand what the feature should do
  • Identify behavior boundaries

This helps write better issues — but issues must NOT reference files/lines.

3. Assess Scope
DecisionWhen
Single issueOne behavior wrong in one place
BreakdownMultiple independent areas, separable concerns, distinct failure modes
4. File GitHub Issues

Use gh issue create. Do NOT ask to review — file and share URLs.

Single issue template:

## What happened
[Actual behavior in plain language]

## What I expected
[Expected behavior]

## Steps to reproduce
1. [Concrete numbered steps]
2. [Use domain terms, not module names]

## Additional context
[Extra observations using domain language]

Breakdown template (for each sub-issue):

## Parent issue
#{parent-issue-number} or "Reported during QA session"

## What's wrong
[This specific behavior problem]

## What I expected
[Expected behavior for this slice]

## Steps to reproduce
1. [Steps specific to THIS issue]

## Blocked by
- #{issue-number} or "None — can start immediately"
5. Continue Session

After filing, share URLs and ask: "Next issue, or are we done?"

Rules

  • MUST use the project's domain language from UBIQUITOUS_LANGUAGE.md — framework jargon in issues excludes non-engineering stakeholders
  • MUST describe behaviors, not code — "sync service fails to apply patch" not "applyPatch() throws"
  • MUST include reproduction steps — if they are not clear, ask the user rather than guess
  • NEVER include file paths, line numbers, or function names in issue bodies — they go stale before triage
  • NEVER over-interview. Cap clarifying questions at 2-3 per bug; more than that is signal the bug needs a QA session with a product owner, not more questions.
  • CRITICAL: the developer who picks up the issue should understand it in 30 seconds. Wall-of-text reports get reopened for clarification.
  • MANDATORY: when breaking one report into multiple issues, file them in dependency order so blockers have real issue numbers to reference
Show full SKILL.md (201 more words)Show less

Gotchas

  • Domain language in UBIQUITOUS_LANGUAGE.md may be out of date. If it was last updated months ago and new features have shipped, the glossary is an input hint, not a source of truth — confirm terms with the user when unsure.
  • "Intermittent" reports are often environmental (one user's browser, one region's data) rather than truly random. Always ask for "how often" and "when did it start" before labeling as race condition.
  • gh issue create opens $EDITOR without --body. In automation this hangs — always pass the body file or inline body.
  • Users often describe the workaround as if it were the bug ("I have to refresh the page"). Drill to the underlying behavior — "what fails before the refresh?" — otherwise the fix targets the symptom.
  • Independent sub-issues from one bug report can duplicate work if each gets a different developer. Mention the parent QA session in every sub-issue so reviewers notice the pattern.

When NOT to Use

  • For triaging a single known bug with a proposed fix — use /triage-issue
  • For creating issues from a PRD — use /prd-to-issues
  • For debugging a reproducible error — use /debug
  • For code review of a PR that addresses a bug — use /review
  • For architecture-level problems — use /architecture-audit, not bug reports

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/qa-session of softspark/ai-toolkit.

Open the folder on GitHubat commit d64db2b

Compare with similar skills

QA Session next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

QA Session compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
QA Session this skillsoftspark/ai-toolkit179—~1.2kAutomated safety check: NotesApache-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
Setup Matt Pocock Skillsbestofjs/bestofjs3.1k20 repos~1.7kAutomated safety check: PassMIT
Summarise Ecosystem Resultsastral-sh/ruff50k1 repos~2.2kAutomated safety check: PassMIT

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • Setup Matt Pocock Skills

    bestofjs/bestofjs

    Configure this repo for the engineering skills — set up its issue tracker, triage label vocabulary, and domain doc layout.

    3.1k GitHub starsUsed in 20 repos~1.7k tokens
    DevelopmentAuto-check passed
  • Official

    A skill your agent uses when a user says "summarise ecosystem results", "summarize this ty ecosystem report", "what changed in this ecosystem run?", or asks to summarise or summarize ty ecosystem…

    50k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated yesterday
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes

Works with

Categories

Questions about QA Session

What does QA Session do?

Interactive QA: user reports bugs conversationally, agent files GitHub issues. QA Session is an agent skill from softspark/ai-toolkit. Interactive QA: user reports bugs conversationally, agent files GitHub issues.

When should I use QA Session?

QA Session fits situations like: development work in your project.

How do I install QA Session in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill qa-session -a claude-code`. Or copy the skill folder (app/skills/qa-session in softspark/ai-toolkit) into .claude/skills/qa-session in your project. Claude Code loads it when a task matches its description.

How do I install QA Session in Codex?

Run `npx skills add softspark/ai-toolkit --skill qa-session -a codex`. Or copy the skill folder (app/skills/qa-session in softspark/ai-toolkit) into .agents/skills/qa-session in your project. Codex loads it when a task matches its description.

Can I use QA Session in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill qa-session -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qa-session, .gemini/skills/qa-session, .github/skills/qa-session and .opencode/skills/qa-session in your project.

What does QA Session need to run?

Going by SKILL.md and its folder, QA Session needs the command-line tools its instructions call (gh). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Agent.

Does QA Session access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is QA Session safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does QA Session use?

QA Session is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does QA Session use?

About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to QA Session?

Skills that share tags, products or a category with QA Session: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Greploop (onyx-dot-app/onyx, 32k stars), Check PR (onyx-dot-app/onyx, 32k stars) and Setup Matt Pocock Skills (bestofjs/bestofjs, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains QA Session?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.