Agent skill

QA Sweep

by ZaxbyHub in ZaxbyHub/opencode-swarm

Apply when implementing features, fixing bugs, debugging errors, investigating failures, tracing root causes, reviewing tech debt, tracing issues, planning fixes, or completing any task.

MITAuto-check passedDevelopment

Install QA Sweep

skills CLI
$ npx skills add ZaxbyHub/opencode-swarm --skill qa-sweep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ZaxbyHub/opencode-swarm qa-sweep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/qa-sweep .claude/skills/qa-sweep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
qa-sweep
GitHub stars
494
Token cost
~2.2k tokens
SKILL.md length
1,212 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Apply when implementing features, fixing bugs, debugging errors, investigating failures, tracing root causes, reviewing tech debt, tracing issues, planning fixes, or completing any task.

  • Works in 3 steps: Parallel Implementation → Independent Adversarial Review (Mandatory) → Completeness Verification
  • Tasks that involve Subagents
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Root cause analysis

What it does

QA Sweep is an agent skill from ZaxbyHub/opencode-swarm. Apply when implementing features, fixing bugs, debugging errors, investigating failures, tracing root causes, reviewing tech debt, tracing issues, planning fixes, or completing any task. Enforces parallel sub-agent implementation, independent adversarial review, and a 95% confidence gate before stopping.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Subagents, Root cause analysis and Technical debt. The repository describes itself as: Architect-centric agentic swarm plugin for OpenCode. Hub-and-spoke orchestration with SME consultation, code generation, and QA review. The licence is MIT.

When your agent uses it

  • Tasks that involve Subagents
  • Tasks that involve Root cause analysis
  • Tasks that involve Technical debt

Example prompts

  • “/qa-sweep”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Parallel Implementation
  2. Independent Adversarial Review (Mandatory)
  3. Completeness Verification

What it can do on your machine

Read from SKILL.md and the folder at commit b63a4bd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

QA Sweep loads about 2.2k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 1,212 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ZaxbyHub/opencode-swarm at commit b63a4bd, republished under its MIT licence (© ZaxbyHub). 1,212 words, ~2,213 tokens.

Download SKILL.mdSave it as .claude/skills/qa-sweep/SKILL.md (or your agent's skills folder).
name
qa-sweep
description
Apply when implementing features, fixing bugs, debugging errors, investigating failures, tracing root causes, reviewing tech debt, tracing issues, planning fixes, or completing any task. Enforces parallel sub-agent implementation, independent adversarial review, and a 95% confidence gate before stopping.
audience
swarm-plugin
effort
high

QA & Independent Review Protocol

Follow this protocol on every implementation, fix, debugging, or review task.

Proportionality

Scale the depth of each phase to risk — never skip a gate for changed work, but match its weight to the task:

  • Read-only or answer-only work (explaining code, reading logs, answering a question) with no worktree edit: Phases 2–3 are not required; verify claims against the actual source before answering.
  • Any worktree edit (code, tests, docs, package metadata, release notes, skill files): Phases 2 and 3 are mandatory. For a small, low-risk edit, one fresh review agent covering both the adversarial and completeness checklists is acceptable; for high-risk or cross-file work, keep them separate.
  • High-risk work (security, auth, isolation, IPC contracts, payments, migrations, concurrency): full protocol, no consolidation.

This proportionality applies only to qa-sweep's own Phase 2/3 passes. When swarm mode is enabled, the swarm-mode contract's separate independent implementation reviewer and final critic gates apply unreduced to any changed work — consolidation here never merges or replaces those gates.

For agent-type, model, and effort selection when spawning these sub-agents, load the orchestrating-subagents skill: economize on explorers, never on reviewers.

If no subagent tool is available

If this protocol executes in a context without a subagent tool (Agent or Task) — check your actual tool list rather than assuming — perform the Phase 2/3 checklists yourself as a clearly labeled fallback self-review and disclose in your report that independent review was unavailable, so the orchestrator can re-run the gate with a real fresh agent. Never present self-review as independent review.

Phase 1 — Parallel Implementation
  • Use parallel sub-agents to speed up independent units of work wherever possible.
  • Each sub-agent must read relevant source code end-to-end before making changes.
  • Reference official documentation to verify whether any behavior is intended before treating it as a bug.
  • Do not trust assumptions — prove every behavior against actual code.
Pre-implementation static-gate baseline

Before the first coder dispatch in any phase, capture a static-gate baseline so findings are scoped to the phase, not to pre-existing code:

  • Defining the pre-phase file set: the canonical source is the file list passed to declare_scope({ taskId, files }) (see the swarm-implement skill for the discipline). If declare_scope was called with the task's exact file list, that IS the pre-phase file set. If declare_scope was not called (e.g., the file list is not 100% obvious), use the containing directories declared in the previous call, OR fall back to the task's files_touched array in the plan (save_plan writes this). Never use the entire repository as the pre-phase file set — that defeats the point of phase scoping.
  • SAST: if sast_scan is available with capture_baseline:true, invoke it once at phase open against the pre-phase file set. Subsequent phase-scoped scans only fail on NEW findings. If swarm tools are unavailable, document the gap in the closure report and skip the baseline capture (do not silently fall back to a project-wide scan that fires on every historical finding).
  • placeholder_scan: no capture-baseline mode, but it is diff-aware — pass added_lines (file path → phase-added line numbers) so only newly added lines drive the verdict; a file omitted from the map is scanned unfiltered (fail-closed), so cross-check its findings against the changed lines. For intentionally retained TODO/FIXME/HACK comments, pre-configure allow_globs (technical debt tracked elsewhere). Do not delete real placeholders to silence the gate; add them to the allowlist.
  • Re-baseline if co-change detection expands the file list after the initial baseline — a missed re-baseline will mis-attribute pre-existing findings to the phase.
Acceptance tests first

Before running any broader test suite, run the smallest test set that covers the task's acceptance criteria. Full-suite passes can mask targeted failures when ordering or concurrency changes — exercise each FR's acceptance criterion explicitly first.

Phase 2 — Independent Adversarial Review (Mandatory)

After implementation, spawn a FRESH sub-agent that has not participated in any prior work. Give it this directive verbatim:

"Assume all work done by the implementing agent is incorrect until you can prove otherwise with absolute evidence from the actual code. The implementing agent makes frequent mistakes and tends to miss edge cases. Do not trust any claim without tracing it yourself. Review every change, test, and edge case end-to-end through the real source."

The review agent must:

  • Independently trace each change end-to-end through the codebase
  • Search for related issues and regressions the implementing agent may have introduced
  • Verify documented behavior vs. actual code behavior
  • Surface every edge case not explicitly covered

Timing requirement: Phase 2 must complete and all confirmed findings must be addressed before the commit you intend as the final substantive push. Do not defer this to "after CI passes" — CI passing on a buggy commit does not retroactively make the review optional. For high-risk work (security, isolation, IPC contracts, auth, payments), this is a hard gate with no exceptions.

Show full SKILL.md (425 more words)Show less
Phase 3 — Completeness Verification

Spawn a SECOND independent agent to verify original planned work vs. delivered work:

"Assume nothing was completed correctly or fully. Map every originally planned item to actual code changes and verify each one independently. Do not trust the implementing agent's report."

Stop Condition

Do NOT stop until ≥95% confident that:

  • All issues, related issues, and edge cases are covered
  • All review agent findings have been addressed
  • Delivered work matches the original plan completely

If below 95%, state what remains and continue working.

User-controlled gates

When the user has explicitly declined or deferred an action that is theirs to take — such as choosing "Leave it for you" on a merge offer, or explicitly saying they will merge manually — that action is outside the agent's scope. The 95% confidence gate applies to technical work the agent controls. Publication by merge is a user-controlled gate: once the user has deliberately declined it, the agent's work is complete and the stop condition is satisfied. Do not loop on pending user-controlled actions.

Reviewer rejection loops

When a single file has gone through 2+ reviewer rejection cycles without resolution, escalate to critic_sounding_board before the next re-dispatch. The sounding board can identify whether the reviewer's bar is unreasonable, the implementation is fundamentally wrong, or the rejection is structural (e.g., skill-load failure masquerading as a content rejection). Do not enter a third rejection cycle without sounding-board consultation.

Skill-load failures in reviewer delegation

If a reviewer returns a REJECT that explicitly cites SKILL_LOAD_FAILED, treat the verdict as INCONCLUSIVE — not a content rejection. Re-dispatch the reviewer with SKILLS: none (omitting the problematic file reference) so the reviewer evaluates the actual code, not the skill-loading infrastructure. This only applies when the rejection explicitly cites a skill-loading failure — never use SKILLS: none to suppress a legitimate content-based rejection.

Inline code fallback for restricted review contexts

When a reviewer cannot read files directly (read-restricted advisory lanes, sandbox limitations), include the most relevant code snippets inline in the delegation prompt with path:line anchors so citations are independently verifiable. This is a fallback only — prefer file-read access when available, and never inline entire files (large inline prompts can produce malformed tool-call JSON). Keep inline snippets to the specific functions or blocks under review.

One-shot docs review delegation

When a reviewer rejects a documentation file, do not send piecemeal fix-one-issue delegations. Read the entire file yourself, list ALL issues in a single comprehensive delegation, and have the coder fix everything in one pass. Apply this per-file — do not batch fixes across unrelated files (scope containment still applies).

© ZaxbyHub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/qa-sweep of ZaxbyHub/opencode-swarm.

Open the folder on GitHubat commit b63a4bd

Compare with similar skills

QA Sweep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

QA Sweep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
QA Sweep this skillZaxbyHub/opencode-swarm494—~2.2kAutomated safety check: PassMIT
Track Issuecdiggins/plato106—~1.7kAutomated safety check: PassMIT
Dead Code Removercode-yeongyu/oh-my-openagent70k—~1.8kAutomated safety check: PassCustom licence
Bug Hunt SwarmDimillian/Skills4k—~1.6kAutomated safety check: PassMIT
Researchwarpdotdev/common-skills6101 repos~1.3kAutomated safety check: PassMIT
Bug Hunt Swarmsickn33/agentic-awesome-skills47k1 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Track Issue

    cdiggins/plato

    Log a concrete issue (bug, technical debt, open design problem, or retire candidate) into tracker/ with elaboration — symptoms/impact, affected code links, root-cause notes, fix approaches, and…

    106 GitHub stars~1.7k tokensUpdated 14 days ago
    DevelopmentAuto-check passed
  • Dead Code Remover

    code-yeongyu/oh-my-openagent

    Finds unused code in a TypeScript project, confirms each candidate has no references through the language server, then hands removals to parallel agents.

    70k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Bug Hunt Swarm

    Dimillian/Skills

    Parallel read-only multi-agent root-cause investigation for bugs, regressions, crashes, flaky behavior, or unexplained failures.

    4k GitHub stars~1.6k tokensUpdated 6 mo ago
    Agent WorkflowsAuto-check passed
  • Research

    warpdotdev/common-skills

    Delegate noisy investigation to one or more subagents so the orchestrator's context stays clean, then work from the distilled answer.

    610 GitHub starsUsed in 1 repo~1.3k tokens
    Agent WorkflowsAuto-check passed
  • Bug Hunt Swarm

    sickn33/agentic-awesome-skills

    Parallel read-only multi-agent root-cause investigation for bugs, regressions, crashes, flaky behavior, or unexplained failures.

    47k GitHub starsUsed in 1 repo~1.9k tokens
    Agent WorkflowsAuto-check passed
  • Phx Investigate

    oliver-kriska/claude-elixir-phoenix

    Investigate Elixir/Phoenix bugs root-cause first. An agent skill from oliver-kriska/claude-elixir-phoenix.

    565 GitHub stars~1.1k tokensUpdated 5 days ago
    AI & LLM EngineeringAuto-check passed

More from ZaxbyHub/opencode-swarm

All 91 skills in this repo
  • Codebase Review Swarm

    ZaxbyHub/opencode-swarm

    Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

    496 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Issue Tracer

    ZaxbyHub/opencode-swarm

    Drives a bug report from validation and root-cause tracing through a critic-reviewed plan, an approved minimal fix and a PR-ready closure, never merging without recorded human approval.

    496 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Commit and PR Publishing for Codex

    ZaxbyHub/opencode-swarm

    Codex adapter for opencode-swarm that governs commits, pushes, draft PRs, PR body updates and CI closeout, deferring to the repo's canonical commit-pr protocol.

    496 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Durable Session State

    ZaxbyHub/opencode-swarm

    Keeps plans, decisions, evidence and reviewer verdicts in small files so long multi-phase tasks survive context compaction and session resumes.

    496 GitHub stars~896 tokensUpdated today
    Auto-check passed
  • Swarm PR Feedback Closer

    ZaxbyHub/opencode-swarm

    Ingests existing pull request feedback such as review comments and CI failures, verifies each claim, fixes confirmed issues and reports closure status for every item.

    496 GitHub stars~14k tokensUpdated today
    Auto-check passed
  • Swarm PR Subscribe

    ZaxbyHub/opencode-swarm

    Monitor a pull request after creation and act autonomously on pushed PR activity.

    496 GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Questions about QA Sweep

What does QA Sweep do?

Apply when implementing features, fixing bugs, debugging errors, investigating failures, tracing root causes, reviewing tech debt, tracing issues, planning fixes, or completing any task. QA Sweep is an agent skill from ZaxbyHub/opencode-swarm. Apply when implementing features, fixing bugs, debugging errors, investigating failures, tracing root causes, reviewing tech debt, tracing issues, planning fixes, or completing any task.

When should I use QA Sweep?

QA Sweep fits situations like: tasks that involve Subagents; tasks that involve Root cause analysis; tasks that involve Technical debt.

How do I install QA Sweep in Claude Code?

Run `npx skills add ZaxbyHub/opencode-swarm --skill qa-sweep -a claude-code`. Or copy the skill folder (.claude/skills/qa-sweep in ZaxbyHub/opencode-swarm) into .claude/skills/qa-sweep in your project. Claude Code loads it when a task matches its description.

How do I install QA Sweep in Codex?

Run `npx skills add ZaxbyHub/opencode-swarm --skill qa-sweep -a codex`. Or copy the skill folder (.claude/skills/qa-sweep in ZaxbyHub/opencode-swarm) into .agents/skills/qa-sweep in your project. Codex loads it when a task matches its description.

Can I use QA Sweep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZaxbyHub/opencode-swarm --skill qa-sweep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/qa-sweep, .gemini/skills/qa-sweep, .github/skills/qa-sweep and .opencode/skills/qa-sweep in your project.

What does QA Sweep need to run?

SKILL.md names no scripts, command-line tools or credentials: QA Sweep is instructions for the agent only.

Does QA Sweep access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is QA Sweep safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does QA Sweep use?

QA Sweep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does QA Sweep use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to QA Sweep?

Skills that share tags, products or a category with QA Sweep: Track Issue (cdiggins/plato, 106 stars), Dead Code Remover (code-yeongyu/oh-my-openagent, 70k stars), Bug Hunt Swarm (Dimillian/Skills, 4k stars) and Research (warpdotdev/common-skills, 610 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains QA Sweep?

ZaxbyHub (a GitHub organization) maintains it in ZaxbyHub/opencode-swarm, which has 494 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 10, 2026.

Source: ZaxbyHub/opencode-swarm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.