Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

S Qa

ASecurity

Independently verify a frozen candidate through fast, vertical-slice, or final QA and return evidence, defects, boundaries, and useful feedback. Use for QA after product changes, final simulations, or a standalone quality check.

5 stars
0 votes
0 copies
1 views
Added 9/19/2026
ai-agentstesting

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add simonasrazm/skills --skill s-qa --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of S Qa?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for S Qa
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/simonasrazm-s-qa/badge)](https://www.skillsdirectory.com/skills/simonasrazm-s-qa)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: s-qa
description: Independently verify a frozen candidate through fast, vertical-slice, or final QA and return evidence, defects, boundaries, and useful feedback. Use for QA after product changes, final simulations, or a standalone quality check.
---

# S QA

Establish the deliverable under review from the supplied acceptance and candidate evidence before choosing or loading specialist checks.

Protect the product and improve the next decision. Inspect a frozen candidate without modifying maintained product or maintained tests. Temporary probes and evidence may live outside maintained output for the check. Bind every observation to the exact candidate; a product mutation invalidates affected evidence.

Independent acceptance starts in a fresh context with the accepted contract, candidate identity, and relevant project constraints, without inherited builder conversation or rationale. A review performed in the builder's context remains self-verification.

## Select the evidence depth

- **Fast:** focused feedback near a mutation unit. Check the changed behavior, core journey, applicable acceptance, boundaries, and silent wrong output. Exclude simulations and known long-running checks. Fast QA cannot claim final acceptance.
- **Slice:** exercise a meaningful vertical slice across its real layers and interfaces. Use rendered interaction or simulation when that is where the failure can exist.
- **Final:** exercise accumulated acceptance, cross-slice behavior, regressions, integration, and the destination as a whole. This mode owns justified end-to-end simulations and reuses current unaffected evidence.

The project's testing pyramid and defined checks remain authoritative. These modes describe feedback placement and cost, not code-versus-no-code techniques.

## Produce actionable evidence

For every applicable acceptance condition, record the action or command, observed result, evidence location, and pass/fail/blocked verdict. Add a verifier-chosen probe against the riskiest plausible false pass.

Before issuing a defect, locate the exact failing evidence and recheck that location with a focused observation or discriminating probe. Reconcile conflicting observations so the finding supports a repair rather than an inspection error.

A probe's exit status must match its stated expectation: required rejection is a passing outcome, not a failed test. For a new defect probe, demonstrate that the same assertion passes a contract-conforming control and fails the suspected behavior, using isolated fixtures when necessary. If a control cannot be established, report that limitation and keep the probe's verdict provisional.

Report supported observations as defects, observed boundaries or undecided policy, coverage gaps, user/operator friction, or actionable opportunities. When the reviewed deliverable has human-facing visual presentation or interaction, read and apply [S UI Check](../s-ui-check/SKILL.md) in its delivered medium. When it contains content intended for people, read and apply [Slop Sweep](../slop-sweep/SKILL.md). Select checks appropriate to the medium and intended use. Report applicable coverage outcomes distinctly; missing rendered evidence leaves visual acceptance open. Avoid quotas and tracker pollution; connect related symptoms to the smallest evidenced cause.

After repair, independently recheck the finding and relevant regressions against the new candidate. A checker that does not return identifiable, retrievable evidence is unavailable, not passed and not pending forever.

Return the report in-channel; create no report or run-state artifact unless requested.

For a small clean candidate, use one coverage table and normally about 200 words of prose, excluding hashes and executable evidence. Cover identity, checks, observed outcomes, coverage, gaps, and verdict without repeating the table in narrative sections. Preserve each verifier-chosen probe as a complete executable command or link its saved file with the invocation and result. Expand for material findings or limitations. If a report file is requested, create its parent directory and write the complete report in one invocation; after a successful write, return its exact path and verdict without routinely rereading it. Reinspect when the write failed or its contents are uncertain.

Attribution

simonasrazmsimonasrazm
View sourceSee grades on GitHubMore from simonasrazm →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →