Agent skill

Tracecat QA

by TracecatHQ in TracecatHQ/tracecat

QA Tracecat product features in a real local cluster. An agent skill from TracecatHQ/tracecat.

AGPL-3.0Auto-check: warningsTesting & QA

Install Tracecat QA

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add TracecatHQ/tracecat --skill tracecat-qa -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TracecatHQ/tracecat tracecat-qa --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TracecatHQ/tracecat.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/tracecat-qa .claude/skills/tracecat-qa && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tracecat-qa
GitHub stars
3.8k
Token cost
~1.1k tokens
SKILL.md length
588 words
Files
2
Skills in repo
4
Repo updated
First seen
Licence
AGPL-3.0

At a glance

QA Tracecat product features in a real local cluster. An agent skill from TracecatHQ/tracecat.

  • Works in 4 steps: Read… → Follow that skill's browser setup and… → If direct in-app browser tools are not… → …
  • Manual verification of Tracecat UI flows and PR changes with just cluster
  • SKILL.md covers Browser Tool Selection, Workflow, Cluster Safety and Blockers
  • Calls just, git and gh

What it does

Tracecat QA is an agent skill from TracecatHQ/tracecat. QA Tracecat product features in a real local cluster. Use for QA, browser tests, smoke tests, or manual verification of Tracecat UI flows and PR changes with just cluster. In Codex desktop app sessions, use browser:control-in-app-browser first; use Chrome DevTools only after the in-app browser path concretely fails or when the user asks for Chrome.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Testing & QA, covering Browser testing, Browser automation and QA and bug reports. It works with Chrome DevTools. The repository describes itself as: Open-source security automation platform for teams and AI agents. The licence is AGPL-3.0.

When your agent uses it

  • Manual verification of Tracecat UI flows and PR changes with just cluster
  • Asks for Chrome

Example prompts

  • “/tracecat-qa”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read browser:control-in-app-browser/SKILL.md.
  2. Follow that skill's browser setup and control instructions.
  3. If direct in-app browser tools are not visible, follow that skill's tool
  4. Use the in-app browser's documented APIs for navigation, DOM inspection,

What it can do on your machine

Read from SKILL.md and the folder at commit a01d80b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • just
    • git
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tracecat QA loads about 1.1k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 588 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:29
    The task depends on the user's existing Chrome profile, cookies, session, or

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TracecatHQ/tracecat at commit a01d80b, republished under its AGPL-3.0 licence (© TracecatHQ). 588 words, ~1,070 tokens.

Download SKILL.mdSave it as .claude/skills/tracecat-qa/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
tracecat-qa
description
QA Tracecat product features in a real local cluster. Use for QA, browser tests, smoke tests, or manual verification of Tracecat UI flows and PR changes with `just cluster`. In Codex desktop app sessions, use `browser:control-in-app-browser` first; use Chrome DevTools only after the in-app browser path concretely fails or when the user asks for Chrome.

Tracecat QA

Browser Tool Selection

For Codex desktop app sessions, always use the browser:control-in-app-browser skill for Tracecat UI QA.

Before opening a Tracecat URL in the Codex app:

  1. Read browser:control-in-app-browser/SKILL.md.
  2. Follow that skill's browser setup and control instructions.
  3. If direct in-app browser tools are not visible, follow that skill's tool discovery path, including searching for node_repl js, before declaring the in-app browser unavailable.
  4. Use the in-app browser's documented APIs for navigation, DOM inspection, screenshots, console, and network checks.

Do not call mcp__chrome_devtools just because Chrome DevTools tools are exposed directly by tool discovery.

Use Chrome DevTools only when one of these is true:

  • The user explicitly asks for Chrome.
  • The task depends on the user's existing Chrome profile, cookies, session, or extensions.
  • The in-app browser skill or tool path is unavailable or fails after a concrete attempt.

If falling back from the in-app browser to Chrome DevTools, state the reason in the QA report, including what in-app browser setup step failed.

Workflow

  1. Build a best-effort understanding of the branch, PR, or diff before testing. Inspect the user's request, current branch name, changed files, git diff, and, when available, the PR title/body/comments with gh pr view.
  2. Follow linked work items when they are discoverable. If the branch, PR body, commits, or changed files mention Linear issue keys, search or open those issues with available Linear tools; use them to understand intent, acceptance criteria, and target user roles. Treat unavailable GitHub or Linear access as a limitation, not a reason to stop.
  3. Infer the most relevant user flows from that intent plus the touched routes, components, services, permissions, and data shapes. Choose a focused QA path and proceed without asking the user to confirm the plan unless the next step is destructive, requires credentials the agent cannot obtain, or would affect external production systems.
  4. Start or reuse a local Tracecat cluster with just cluster up; prefer just cluster up -d when background services are enough. If command syntax is unclear, inspect the command reference in scripts/cluster.
  5. Run just cluster ports and use the UI URL it prints, especially the Caddy/public app URL. Do not manually build or browse to localhost:<port>; using a raw localhost port can hit CSRF/session-origin issues.
  6. Open the UI with browser tooling:
    • In the Codex app, use browser:control-in-app-browser first.
    • Outside the Codex app, use the Chrome DevTools MCP.
  7. Exercise the inferred feature flows through the real UI. Prefer real cluster behavior over mock-only checks unless the user explicitly asks for mocks.
  8. Inspect visible UI state, console errors, failed network requests, and relevant service logs. Use just cluster logs <service> or just cluster restart <service> when needed.
  9. Report the inferred intent, cluster URL used, steps performed, pass/fail status, screenshots or observations when useful, and any blockers.
Show full SKILL.md (119 more words)Show less

Cluster Safety

  • Before starting a new cluster, check whether an existing Tracecat cluster is already running if doing so could affect the user's environment.
  • Do not remove volumes or run destructive cleanup commands such as just cluster rm unless the user explicitly asks and confirms data loss is acceptable.
  • If QA created a cluster only for this task, either leave it running and say so, or stop it with just cluster down when that is clearly appropriate.

Blockers

If the app shell fails before reaching the feature, treat that as a QA blocker. Capture the exact browser error, relevant console/network details, and service logs instead of switching to a mock flow that no longer proves the requested user experience.

© TracecatHQ, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/tracecat-qa of TracecatHQ/tracecat.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit a01d80b

Compare with similar skills

Tracecat QA next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tracecat QA compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tracecat QA this skillTracecatHQ/tracecat3.8k—~1.1kAutomated safety check: WarnAGPL-3.0
Browsingobra/superpowers-chrome3561 repos~8kAutomated safety check: PassMIT
OpenWork Electron Browser Automationdifferent-ai/openwork24k—~780Automated safety check: PassCustom licence
Diff-Driven Smoke TestsSkyvern-AI/skyvern23k—~5.2kAutomated safety check: PassAGPL-3.0
Interactive TestingPorabuild/Poracode114—~4.5kAutomated safety check: NotesApache-2.0
Chrome Devtoolsaeroxy/chrome-devtools-cli253—~9kAutomated safety check: WarnNone

Similar skills

  • Browsing

    obra/superpowers-chrome

    A skill your agent uses when you need direct browser control - teaches Chrome DevTools Protocol for controlling existing browser sessions, multi-tab management, form automation, and content…

    356 GitHub starsUsed in 1 repo~8k tokens
    Testing & QAAuto-check passed
  • Attaches OpenCode browser tools to the OpenWork Electron dev app through CDP to explore its UI, send a composer task and debug, not to give test verdicts.

    24k GitHub stars~780 tokensUpdated today
    Testing & QAAuto-check passed
  • Diff-Driven Smoke Tests

    Skyvern-AI/skyvern

    Reads your git diff, writes a handful of happy-path browser smoke tests, runs them with Skyvern or Chrome DevTools MCP and posts screenshot evidence to the PR.

    23k GitHub stars~5.2k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Interactive Testing

    Porabuild/Poracode

    Run repeatable integration and smoke testing against the real Poracode Electron app through Chrome DevTools Protocol.

    114 GitHub stars~4.5k tokensUpdated today
    Testing & QAAuto-check: notes
  • Chrome Devtools

    aeroxy/chrome-devtools-cli

    A skill your agent uses when the user asks to "take a screenshot of a website", "navigate to a URL", "fill a form in the browser", "interact with Chrome", or when a chrome automation task is needed.

    253 GitHub stars~9k tokensUpdated yesterday
    Testing & QAAuto-check: warnings
  • Agentic Browser Testing

    petrkindlmann/qa-skills

    Goal-driven E2E testing where a browser agent (Playwright MCP / computer-use) reads a natural-language goal and explores the app via the accessibility tree to assert outcomes — no pre-written script.

    163 GitHub stars~4.5k tokensUpdated 3 mo ago
    Testing & QAAuto-check passed

More from TracecatHQ/tracecat

  • Docs Authoring

    TracecatHQ/tracecat

    A skill your agent uses when adding or updating documentation pages in an existing docs site.

    3.8k GitHub stars~3.1k tokensUpdated today
    Auto-check: notes
  • Gh Release

    TracecatHQ/tracecat

    Cut a stable GitHub release or prerelease directly from a Tracecat release branch, including the version bump, tag, image verification, and categorized release notes.

    3.8k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Make PR

    TracecatHQ/tracecat

    Create, retitle, or label a pull request for the current branch.

    3.8k GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Tracecat QA

What does Tracecat QA do?

QA Tracecat product features in a real local cluster. An agent skill from TracecatHQ/tracecat. Tracecat QA is an agent skill from TracecatHQ/tracecat. QA Tracecat product features in a real local cluster.

When should I use Tracecat QA?

Tracecat QA fits situations like: manual verification of Tracecat UI flows and PR changes with just cluster; asks for Chrome.

How do I install Tracecat QA in Claude Code?

Run `npx skills add TracecatHQ/tracecat --skill tracecat-qa -a claude-code`. Or copy the skill folder (.agents/skills/tracecat-qa in TracecatHQ/tracecat) into .claude/skills/tracecat-qa in your project. Claude Code loads it when a task matches its description.

How do I install Tracecat QA in Codex?

Run `npx skills add TracecatHQ/tracecat --skill tracecat-qa -a codex`. Or copy the skill folder (.agents/skills/tracecat-qa in TracecatHQ/tracecat) into .agents/skills/tracecat-qa in your project. Codex loads it when a task matches its description.

Can I use Tracecat QA in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TracecatHQ/tracecat --skill tracecat-qa -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tracecat-qa, .gemini/skills/tracecat-qa, .github/skills/tracecat-qa and .opencode/skills/tracecat-qa in your project.

What does Tracecat QA need to run?

Going by SKILL.md and its folder, Tracecat QA needs the command-line tools its instructions call (just, git and gh).

Does Tracecat QA access the network?

SKILL.md contains no URLs. Its commands use git and gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Tracecat QA safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Tracecat QA use?

Tracecat QA is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tracecat QA use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tracecat QA?

Skills that share tags, products or a category with Tracecat QA: Browsing (obra/superpowers-chrome, 356 stars), OpenWork Electron Browser Automation (different-ai/openwork, 24k stars), Diff-Driven Smoke Tests (Skyvern-AI/skyvern, 23k stars) and Interactive Testing (Porabuild/Poracode, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tracecat QA?

TracecatHQ (a GitHub organization) maintains it in TracecatHQ/tracecat, which has 3,824 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 7, 2026.

Source: TracecatHQ/tracecat on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.