{"id":"2be422aa-cee7-44ed-a527-e6539fe1b916","entityType":"agent","slug":"clawhub-skills-1kalin-afrexai-qa-engine","name":"afrexai-qa-engine","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-1kalin-afrexai-qa-engine","canonicalPath":"/agent/clawhub-skills-1kalin-afrexai-qa-engine","generatedAt":"2026-10-09T18:15:08.239Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"QA & Test Engineering Command Center QA & Test Engineering Command Center Complete quality assurance system — from test strategy to automation frameworks, coverage analysis, and release readiness. Works for any stack, any team size. When to Use - Planning test strategy for a new feature or project - Writing unit, integration, or E2E tests - Reviewing test quality and coverage gaps - Setting up test automation and CI/CD quality gates - Performance testin","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:1kalin:afrexai-qa-engine","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/1kalin/afrexai-qa-engine","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/1kalin/afrexai-qa-engine","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"QA & Test Engineering Command Center QA & Test Engineering Command Center Complete quality assurance system — from test strategy to automation frameworks, cover"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"this","status":"self-declared"},{"label":"for","status":"self-declared"},{"label":"you","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":4,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"this","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"for","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"you","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:this|supported|profile capability:for|supported|profile capability:you|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T06:17:57.819Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T06:17:57.819Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T06:17:57.819Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:1kalin:afrexai-qa-engine","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-engine/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-engine/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-engine/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-engine/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-engine/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-engine/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T18:15:08.238Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-engine/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-engine/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-engine/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-engine/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"# QA & Test Engineering Command Center\n\nComplete quality assurance system — from test strategy to automation frameworks, coverage analysis, and release readiness. Works for any stack, any team size.\n\n## When to Use\n\n- Planning test strategy for a new feature or project\n- Writing unit, integration, or E2E tests\n- Reviewing test quality and coverage gaps\n- Setting up test automation and CI/CD quality gates\n- Performance testing and load analysis\n- Security testing checklist\n- Bug triage and defect management\n- Release readiness assessment\n\n---\n\n## Phase 1: Test Strategy\n\n### Strategy Brief\n\nBefore writing any tests, define the strategy:\n\n```yaml\n# test-strategy.yaml\nproject: \"[name]\"\nscope: \"[feature/module/full product]\"\nrisk_level: high | medium | low\nstack:\n  language: \"[TypeScript/Python/Java/Go]\"\n  framework: \"[React/Express/Django/Spring]\"\n  test_runner: \"[Jest/Vitest/pytest/JUnit/Go test]\"\n  e2e_tool: \"[Playwright/Cypress/Selenium]\"\n\n# What are we testing?\ntest_scope:\n  - area: \"[e.g., Auth module]\"\n    risk: high\n    test_types: [unit, integration, e2e]\n    priority: 1\n  - area: \"[e.g., Settings page]\"\n    risk: low\n    test_types: [unit]\n    priority: 3\n\n# What's NOT in scope (and why)\nexclusions:\n  - \"[e.g., Third-party widget — covered by vendor]\"\n\n# Quality targets\ntargets:\n  line_coverage: 80\n  branch_coverage: 70\n  critical_path_coverage: 100\n  max_flaky_rate: 2%\n  max_test_duration_unit: 10ms\n  max_test_duration_integration: 500ms\n  max_test_duration_e2e: 30s\n```\n\n### Risk-Based Test Allocation\n\nNot everything needs the same testing depth. Use the risk matrix:\n\n| Risk Level | Unit Tests | Integration | E2E | Manual/Exploratory |\n|-----------|-----------|-------------|-----|-------------------|\n| **Critical** (payments, auth, data loss) | 95%+ coverage | Full API coverage | Happy + error paths | Exploratory session |\n| **High** (core features, user-facing) | 85%+ coverage | Key integrations | Happy path | Spot check |\n| **Medium** (secondary features) | 70%+ coverage | Critical paths only | Smoke only | On release |\n| **Low** (admin, internal tools) | 50%+ coverage | None | None | None |\n\n### Test Pyramid\n\nFollow the pyramid — not the ice cream cone:\n\n```\n         /  E2E  \\          ← Few (5-10%) — slow, expensive, brittle\n        / Integr. \\         ← Some (15-25%) — API contracts, DB queries\n       /   Unit    \\        ← Many (65-80%) — fast, isolated, cheap\n```\n\n**Anti-pattern: Ice cream cone** (mostly E2E, few unit tests) = slow CI, flaky builds, expensive maintenance.\n\n**Decision rule:** Can this be tested at a lower level? → Test it there.\n\n---\n\n## Phase 2: Unit Testing\n\n### Anatomy of a Good Unit Test\n\nEvery unit test follows AAA (Arrange-Act-Assert):\n\n```\n1. ARRANGE — Set up test data, mocks, state\n2. ACT     — Call the function/method under test\n3. ASSERT  — Verify the output matches expectations\n```\n\n### Unit Test Checklist (per function)\n\nFor each function/method, verify:\n\n- [ ] **Happy path** — expected input → expected output\n- [ ] **Edge cases** — empty input, null/undefined, zero, max values\n- [ ] **Boundary values** — off-by-one, min-1, max+1\n- [ ] **Error handling** — invalid input → correct error thrown\n- [ ] **Return types** — correct type, shape, structure\n- [ ] **Side effects** — does it modify state it shouldn't?\n- [ ] **Idempotency** — calling twice gives same result?\n\n### What to Mock (and What NOT to Mock)\n\n**Mock these:**\n- External APIs (HTTP calls, third-party services)\n- Database queries (in unit tests only)\n- File system operations\n- Date/time (use fake timers)\n- Random number generators\n- Environment variables\n\n**DO NOT mock these:**\n- The function under test itself\n- Pure utility functions (test them directly)\n- Data transformations\n- Simple value objects\n\n**Mock rule of thumb:** If removing the mock would make the test hit the network, file system, or database → mock it. Otherwise → don't.\n\n### Test Naming Convention\n\nUse the pattern: `[unit] [scenario] [expected result]`\n\nExamples:\n- `calculateTotal returns 0 for empty cart`\n- `validateEmail throws for missing @ symbol`\n- `parseDate handles ISO 8601 with timezone offset`\n\n### Coverage Analysis\n\n**Metrics that matter:**\n| Metric | Target | Why |\n|--------|--------|-----|\n| Line coverage | 80%+ | Basic completeness |\n| Branch coverage | 70%+ | Catches missed if/else paths |\n| Function coverage | 90%+ | Ensures all functions are tested |\n| Critical path coverage | 100% | Business-critical code fully verified |\n\n**Coverage traps to avoid:**\n- 100% line coverage ≠ good tests (assertions matter more than lines hit)\n- Coverage on generated code inflates numbers\n- Trivial getters/setters pad coverage without value\n- Coverage should INCREASE over time, never decrease\n\n---\n\n## Phase 3: Integration Testing\n\n### What Integration Tests Cover\n\nIntegration tests verify that components work TOGETHER:\n\n- API endpoint → middleware → handler → database → response\n- Service A calls Service B and handles the response\n- Message queue producer → consumer → side effect\n- Auth flow: login → token → authenticated request\n\n### Integration Test Patterns\n\n**Pattern 1: API Contract Testing**\n```\n1. Start test server (or use supertest/httptest)\n2. Send HTTP request with specific payload\n3. Assert: status code, response body shape, headers\n4. Assert: database state changed correctly\n5. Assert: side effects triggered (emails, events)\n```\n\n**Pattern 2: Database Integration**\n```\n1. Start test database (SQLite in-memory or test container)\n2. Run migrations\n3. Seed test data\n4. Execute query/operation\n5. Assert: data matches expectations\n6. Teardown (truncate or rollback transaction)\n```\n\n**Pattern 3: External Service**\n```\n1. Record real API response (VCR/nock/wiremock)\n2. Replay recorded response in tests\n3. Assert: your code handles the response correctly\n4. Also test: timeout, 500 error, malformed response\n```\n\n### Integration Test Checklist\n\n- [ ] **Happy path** — full flow works end-to-end\n- [ ] **Auth** — unauthenticated returns 401, wrong role returns 403\n- [ ] **Validation** — bad payload returns 400 with error details\n- [ ] **Not found** — missing resource returns 404\n- [ ] **Conflict** — duplicate create returns 409\n- [ ] **Rate limiting** — excessive requests return 429\n- [ ] **Database constraints** — unique violations, foreign keys\n- [ ] **Concurrency** — two simultaneous writes don't corrupt data\n- [ ] **Timeout handling** — external service timeout → graceful fallback\n\n---\n\n## Phase 4: End-to-End (E2E) Testing\n\n### E2E Strategy\n\nE2E tests verify complete user journeys. They're expensive — be strategic:\n\n**Test these E2E:**\n- User registration → email verification → first login\n- Purchase flow → payment → confirmation\n- Critical business workflows (the ones that make money)\n- Cross-browser/device smoke tests\n\n**DON'T test these E2E:**\n- Individual form validations (unit test)\n- API error handling (integration test)\n- Edge cases (lower-level tests)\n- Visual styling (visual regression tools)\n\n### E2E Test Template\n\n```yaml\ntest_name: \"[User journey name]\"\npreconditions:\n  - \"[User is logged in]\"\n  - \"[Product exists in catalog]\"\nsteps:\n  - action: \"Navigate to /products\"\n    verify: \"Product list is visible\"\n  - action: \"Click 'Add to Cart' on Product A\"\n    verify: \"Cart badge shows 1\"\n  - action: \"Click 'Checkout'\"\n    verify: \"Checkout form displayed\"\n  - action: \"Fill payment details and submit\"\n    verify: \"Order confirmation page with order ID\"\npostconditions:\n  - \"Order exists in database with status 'paid'\"\n  - \"Confirmation email sent\"\nmax_duration: 30s\n```\n\n### Flaky Test Management\n\nFlaky tests are the #1 CI killer. Handle them:\n\n**Flaky Test Triage:**\n1. **Identify** — Track test pass rates over 10+ runs\n2. **Classify** — Why is it flaky?\n   - Timing/race condition → Add explicit waits, not sleep()\n   - Test data dependency → Isolate test data per run\n   - External service → Mock it or use test container\n   - Browser rendering → Use visibility checks, not delays\n3. **Quarantine** — Move to @flaky suite, run separately\n4. **Fix or delete** — Flaky test unfixed for 2 weeks → delete it\n\n**Flaky rate target:** < 2% of total test runs\n\n---\n\n## Phase 5: Performance Testing\n\n### Performance Test Types\n\n| Type | Purpose | When |\n|------|---------|------|\n| **Load test** | Normal traffic handling | Before every release |\n| **Stress test** | Find breaking point | Quarterly or before scaling |\n| **Spike test** | Sudden traffic burst | Before marketing campaigns |\n| **Soak test** | Memory leaks over time | Monthly or after major changes |\n| **Capacity test** | Max users/throughput | Planning infrastructure |\n\n### Performance Test Plan\n\n```yaml\ntest_name: \"[API/Page] Load Test\"\ntarget: \"[URL or endpoint]\"\nbaseline:\n  p50_response: \"[current p50 ms]\"\n  p95_response: \"[current p95 ms]\"\n  p99_response: \"[current p99 ms]\"\n  error_rate: \"[current %]\"\n\nscenarios:\n  - name: \"Normal load\"\n    vus: 50          # virtual users\n    duration: 5m\n    ramp_up: 30s\n    thresholds:\n      p95_response: \"< 500ms\"\n      error_rate: \"< 1%\"\n\n  - name: \"Peak load\"\n    vus: 200\n    duration: 10m\n    ramp_up: 1m\n    thresholds:\n      p95_response: \"< 2000ms\"\n      error_rate: \"< 5%\"\n\n  - name: \"Stress test\"\n    vus: 500\n    duration: 5m\n    ramp_up: 2m\n    # Find the breaking point — no thresholds, observe\n```\n\n### Performance Metrics Dashboard\n\nTrack these per endpoint:\n\n| Metric | Green | Yellow | Red |\n|--------|-------|--------|-----|\n| p50 response | < 200ms | 200-500ms | > 500ms |\n| p95 response | < 500ms | 500ms-2s | > 2s |\n| p99 response | < 1s | 1-5s | > 5s |\n| Error rate | < 0.1% | 0.1-1% | > 1% |\n| Throughput | > baseline | 80-100% baseline | < 80% |\n| CPU usage | < 60% | 60-80% | > 80% |\n| Memory usage | < 70% | 70-85% | > 85% |\n| DB query time | < 50ms avg | 50-200ms | > 200ms |\n\n### Common Performance Fixes\n\n| Symptom | Likely Cause | Fix |\n|---------|-------------|-----|\n| Slow API response | N+1 queries | Batch/join queries |\n| Memory climbing | Object retention | Profile heap, fix leaks |\n| Timeout spikes | Connection pool exhaustion | Increase pool, add queuing |\n| Slow page load | Large bundle | Code split, lazy load |\n| DB bottleneck | Missing index | Add index on WHERE/JOIN columns |\n| High CPU | Synchronous compute | Move to worker/queue |\n\n---\n\n## Phase 6: Security Testing\n\n### Security Test Checklist\n\nRun through these for every feature/release:\n\n**Authentication & Authorization:**\n- [ ] Passwords hashed with bcrypt/argon2 (not MD5/SHA1)\n- [ ] Session tokens are random, sufficient length (128+ bits)\n- [ ] JWT tokens have short expiry (15 min access, 7 day refresh)\n- [ ] Failed login rate limiting (5 attempts → lockout)\n- [ ] Password reset tokens expire (1 hour max)\n- [ ] Role-based access enforced server-side (not just UI)\n- [ ] Can't access other users' data by changing IDs in URL\n\n**Input Validation:**\n- [ ] SQL injection — parameterized queries everywhere\n- [ ] XSS — output encoding, CSP headers\n- [ ] CSRF — tokens on state-changing requests\n- [ ] Path traversal — validate file paths, no `../`\n- [ ] Command injection — never pass user input to shell\n- [ ] File upload — validate type, size, scan for malware\n- [ ] JSON/XML parsing — depth limits, entity expansion disabled\n\n**Data Protection:**\n- [ ] HTTPS everywhere (HSTS header)\n- [ ] Sensitive data encrypted at rest\n- [ ] PII not logged (mask in log output)\n- [ ] API keys not in client-side code\n- [ ] CORS configured correctly (not `*`)\n- [ ] Security headers set (X-Frame-Options, X-Content-Type-Options)\n\n**Infrastructure:**\n- [ ] Dependencies scanned for CVEs (npm audit / pip audit)\n- [ ] Docker images scanned (Trivy/Snyk)\n- [ ] Secrets not in code/env files (use vault)\n- [ ] Error messages don't leak internals\n- [ ] Admin endpoints behind VPN/IP allowlist\n\n### OWASP Top 10 Quick Reference\n\n| # | Vulnerability | Test For |\n|---|--------------|----------|\n| A01 | Broken Access Control | Access other users' resources, bypass role checks |\n| A02 | Cryptographic Failures | Weak hashing, plaintext secrets, expired certs |\n| A03 | Injection | SQL, XSS, command, LDAP injection |\n| A04 | Insecure Design | Business logic flaws, missing rate limits |\n| A05 | Security Misconfiguration | Default creds, verbose errors, open ports |\n| A06 | Vulnerable Components | Outdated deps with known CVEs |\n| A07 | Authentication Failures | Brute force, weak passwords, session fixation |\n| A08 | Data Integrity Failures | Unsigned updates, CI/CD pipeline injection |\n| A09 | Logging Failures | Missing audit logs, no alerting on breaches |\n| A10 | SSRF | Internal network access via user-controlled URLs |\n\n---\n\n## Phase 7: Bug Triage & Defect Management\n\n### Bug Report Template\n\n```yaml\nbug_id: \"[auto or manual]\"\ntitle: \"[Short description of the bug]\"\nseverity: P0-critical | P1-high | P2-medium | P3-low\nreporter: \"[name]\"\ndate: \"[YYYY-MM-DD]\"\n\nenvironment:\n  os: \"[OS + version]\"\n  browser: \"[Browser + version]\"\n  app_version: \"[version/commit]\"\n  \nsteps_to_reproduce:\n  1. \"[Step 1]\"\n  2. \"[Step 2]\"\n  3. \"[Step 3]\"\n\nexpected_result: \"[What should happen]\"\nactual_result: \"[What actually happens]\"\nfrequency: \"always | intermittent | once\"\nscreenshots: \"[links]\"\nlogs: \"[relevant log output]\"\n```\n\n### Severity Classification\n\n| Level | Definition | SLA | Example |\n|-------|-----------|-----|---------|\n| **P0 Critical** | System down, data loss, security breach | Fix in 4 hours | Payment processing broken |\n| **P1 High** | Major feature broken, no workaround | Fix in 24 hours | Users can't login |\n| **P2 Medium** | Feature broken with workaround | Fix this sprint | Search returns wrong results sometimes |\n| **P3 Low** | Minor issue, cosmetic | Fix when convenient | Button alignment off by 2px |\n\n### Bug Triage Process (Weekly)\n\n```\n1. Review all new bugs (unassigned)\n2. For each bug:\n   a. Reproduce — can you trigger it?\n   b. Classify severity (P0-P3)\n   c. Estimate fix effort (S/M/L)\n   d. Assign to owner + sprint\n   e. Link to related bugs/stories\n3. Review P0/P1 bugs from last week — are they fixed?\n4. Close bugs that can't be reproduced (after 2 attempts)\n5. Update metrics dashboard\n```\n\n### Bug Metrics Dashboard\n\nTrack weekly:\n\n| Metric | Formula | Target |\n|--------|---------|--------|\n| Bug escape rate | Bugs found in prod / total bugs | < 10% |\n| Mean time to fix (P0) | Avg hours from report to deploy | < 8 hours |\n| Mean time to fix (P1) | Avg hours from report to deploy | < 48 hours |\n| Bug reopen rate | Reopened bugs / closed bugs | < 5% |\n| Test escape analysis | Bugs that SHOULD have been caught | Track & reduce |\n| Open bug count | Total open by severity | Trending down |\n\n---\n\n## Phase 8: Release Readiness\n\n### Release Checklist\n\nBefore shipping to production:\n\n**Code Quality:**\n- [ ] All unit tests passing\n- [ ] All integration tests passing\n- [ ] E2E smoke suite passing\n- [ ] No new lint warnings/errors\n- [ ] Code reviewed and approved\n- [ ] No known P0/P1 bugs open for this release\n\n**Coverage & Quality Gates:**\n- [ ] Line coverage ≥ target (80%)\n- [ ] Branch coverage ≥ target (70%)\n- [ ] No coverage decrease from last release\n- [ ] Mutation testing score ≥ 60% (if applicable)\n\n**Performance:**\n- [ ] Load test passed (within thresholds)\n- [ ] No performance regressions vs baseline\n- [ ] Bundle size within budget\n\n**Security:**\n- [ ] Dependency audit clean (no critical/high CVEs)\n- [ ] Security checklist completed\n- [ ] Secrets rotated if needed\n\n**Operational Readiness:**\n- [ ] Monitoring/alerts configured for new features\n- [ ] Rollback plan documented\n- [ ] Feature flags in place for risky changes\n- [ ] Database migration tested and reversible\n- [ ] Runbook updated\n\n### Release Readiness Score\n\nScore 0-100 across 5 dimensions:\n\n| Dimension | Weight | Scoring |\n|-----------|--------|---------|\n| **Test coverage** | 25% | 100 if targets met, -10 per gap area |\n| **Bug status** | 25% | 100 if 0 P0/P1, -20 per open P0, -10 per P1 |\n| **Performance** | 20% | 100 if all green, -15 per yellow, -30 per red |\n| **Security** | 20% | 100 if clean, -25 per critical, -15 per high |\n| **Operational** | 10% | 100 if checklist complete, -20 per missing item |\n\n**Ship threshold: ≥ 80 overall, no dimension below 60**\n\n---\n\n## Phase 9: CI/CD Quality Gates\n\n### Pipeline Quality Gates\n\nConfigure these gates in your CI pipeline:\n\n```yaml\n# Quality gate configuration\ngates:\n  - name: \"Lint\"\n    stage: pre-commit\n    command: \"npm run lint\"\n    blocking: true\n    \n  - name: \"Unit Tests\"\n    stage: commit\n    command: \"npm test -- --coverage\"\n    blocking: true\n    thresholds:\n      pass_rate: 100%\n      coverage_line: 80%\n      coverage_branch: 70%\n      \n  - name: \"Integration Tests\"\n    stage: merge\n    command: \"npm run test:integration\"\n    blocking: true\n    thresholds:\n      pass_rate: 100%\n      \n  - name: \"Security Scan\"\n    stage: merge\n    command: \"npm audit --audit-level=high\"\n    blocking: true\n    \n  - name: \"E2E Smoke\"\n    stage: staging\n    command: \"npm run test:e2e:smoke\"\n    blocking: true\n    thresholds:\n      pass_rate: 100%\n      \n  - name: \"Performance\"\n    stage: staging\n    command: \"npm run test:perf\"\n    blocking: false  # Alert only\n    thresholds:\n      p95_regression: 20%\n```\n\n### Test Automation Maturity Model\n\nRate your team 1-5:\n\n| Level | Description | Characteristics |\n|-------|------------|-----------------|\n| **1 — Manual** | All testing is manual | No automation, long release cycles |\n| **2 — Reactive** | Some unit tests, no CI | Tests written after bugs, not before |\n| **3 — Structured** | Test pyramid, CI pipeline | Unit + integration, automated on push |\n| **4 — Proactive** | Full automation, quality gates | E2E + perf + security in pipeline, TDD |\n| **5 — Optimized** | Self-healing, predictive | Flaky auto-quarantine, AI-assisted testing, continuous deployment |\n\n---\n\n## Phase 10: Test Maintenance\n\n### Weekly Test Health Review\n\n```yaml\nreview_date: \"[YYYY-MM-DD]\"\n\nmetrics:\n  total_tests: 0\n  pass_rate_7d: \"0%\"\n  flaky_tests: 0\n  flaky_rate: \"0%\"\n  avg_suite_duration: \"0s\"\n  coverage_line: \"0%\"\n  coverage_branch: \"0%\"\n  \nactions:\n  quarantined: []     # Tests moved to flaky suite\n  deleted: []         # Tests removed (obsolete/unfixable)\n  fixed: []           # Flaky tests fixed this week\n  added: []           # New tests added\n  \ntrends:\n  coverage_delta: \"+0%\"     # vs last week\n  flaky_delta: \"+0\"         # vs last week\n  duration_delta: \"+0s\"     # vs last week\n  \nnotes: \"\"\n```\n\n### Test Maintenance Rules\n\n1. **No commented-out tests** — delete or fix, never comment\n2. **No skipped tests > 2 weeks** — fix or remove\n3. **No test duplication** — each behavior tested once at the right level\n4. **Test names must be readable** — someone new should understand what broke\n5. **Shared test utilities** — common setup in fixtures/factories, not copy-pasted\n6. **Test data isolation** — each test creates its own data, cleans up after\n7. **No magic numbers** — use named constants in assertions\n8. **Assertion messages** — custom messages on complex assertions\n\n### Common Test Anti-Patterns\n\n| Anti-Pattern | Problem | Fix |\n|-------------|---------|-----|\n| **Sleeping tests** | `sleep(2000)` instead of waiting | Use explicit waits/polling |\n| **Test interdependence** | Test B relies on Test A's state | Isolate — each test sets up its own state |\n| **Assertionless tests** | Test runs code but doesn't assert | Add meaningful assertions |\n| **Brittle selectors** | CSS selectors that break on redesign | Use data-testid or aria roles |\n| **God test** | One test verifying 20 things | Split into focused tests |\n| **Mock overload** | Everything mocked, nothing real tested | Only mock external boundaries |\n| **Hardcoded data** | Tests break when seed data changes | Use factories/builders |\n| **Ignoring test output** | \"It passed, ship it\" | Review WHY it passed — is the assertion meaningful? |\n\n---\n\n## Quick Reference: Natural Language Commands\n\nTell the agent:\n- **\"Create test strategy for [feature]\"** → Generates strategy brief\n- **\"Write unit tests for [function/file]\"** → AAA-structured tests with edge cases\n- **\"Review test coverage for [module]\"** → Gap analysis + recommendations\n- **\"Write integration tests for [API endpoint]\"** → Full HTTP test suite\n- **\"Plan E2E tests for [user journey]\"** → E2E test template\n- **\"Run security checklist for [feature]\"** → OWASP-based security review\n- **\"Triage these bugs: [list]\"** → Severity classification + assignment\n- **\"Release readiness check\"** → Full readiness score + blockers\n- **\"Performance test plan for [endpoint]\"** → Load/stress test configuration\n- **\"Fix flaky test [name]\"** → Root cause analysis + fix strategy\n","readmeExcerpt":"QA & Test Engineering Command Center Complete quality assurance system — from test strategy to automation frameworks, coverage analysis, and release readiness. Works for any stack, any team size. When to Use - Planning test strategy for a new feature or project - Writing unit, integration, or E2E tests - Reviewing test quality and coverage gaps - Setting up test automation and CI/CD quality gates - Performance testin","codeSnippets":[],"executableExamples":[{"language":"yaml","snippet":"# test-strategy.yaml\nproject: \"[name]\"\nscope: \"[feature/module/full product]\"\nrisk_level: high | medium | low\nstack:\n  language: \"[TypeScript/Python/Java/Go]\"\n  framework: \"[React/Express/Django/Spring]\"\n  test_runner: \"[Jest/Vitest/pytest/JUnit/Go test]\"\n  e2e_tool: \"[Playwright/Cypress/Selenium]\"\n\n# What are we testing?\ntest_scope:\n  - area: \"[e.g., Auth module]\"\n    risk: high\n    test_types: [unit, integration, e2e]\n    priority: 1\n  - area: \"[e.g., Settings page]\"\n    risk: low\n    test_types: [unit]\n    priority: 3\n\n# What's NOT in scope (and why)\nexclusions:\n  - \"[e.g., Third-party widget — covered by vendor]\"\n\n# Quality targets\ntargets:\n  line_coverage: 80\n  branch_coverage: 70\n  critical_path_coverage: 100\n  max_flaky_rate: 2%\n  max_test_duration_unit: 10ms\n  max_test_duration_integration: 500ms\n  max_test_duration_e2e: 30s"},{"language":"text","snippet":"/  E2E  \\          ← Few (5-10%) — slow, expensive, brittle\n        / Integr. \\         ← Some (15-25%) — API contracts, DB queries\n       /   Unit    \\        ← Many (65-80%) — fast, isolated, cheap"},{"language":"text","snippet":"1. ARRANGE — Set up test data, mocks, state\n2. ACT     — Call the function/method under test\n3. ASSERT  — Verify the output matches expectations"},{"language":"text","snippet":"1. Start test server (or use supertest/httptest)\n2. Send HTTP request with specific payload\n3. Assert: status code, response body shape, headers\n4. Assert: database state changed correctly\n5. Assert: side effects triggered (emails, events)"},{"language":"text","snippet":"1. Start test database (SQLite in-memory or test container)\n2. Run migrations\n3. Seed test data\n4. Execute query/operation\n5. Assert: data matches expectations\n6. Teardown (truncate or rollback transaction)"},{"language":"text","snippet":"1. Record real API response (VCR/nock/wiremock)\n2. Replay recorded response in tests\n3. Assert: your code handles the response correctly\n4. Also test: timeout, 500 error, malformed response"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"QA & Test Engineering Command Center QA & Test Engineering Command Center Complete quality assurance system — from test strategy to automation frameworks, coverage analysis, and release readiness. Works for any stack, any team size. When to Use - Planning test strategy for a new feature or project - Writing unit, integration, or E2E tests - Reviewing test quality and coverage gaps - Setting up test automation and CI/CD quality gates - Performance testin","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":380,"uniquenessScore":66,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T18:15:08.239Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}