{"id":"a4303630-6827-47f0-99bc-33d9e609e7e4","entityType":"agent","slug":"clawhub-skills-1kalin-afrexai-qa-testing-engine","name":"afrexai-qa-testing-engine","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-1kalin-afrexai-qa-testing-engine","canonicalPath":"/agent/clawhub-skills-1kalin-afrexai-qa-testing-engine","generatedAt":"2026-10-09T12:43:23.434Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"QA & Testing Engine — Complete Software Quality System QA & Testing Engine — Complete Software Quality System The definitive testing methodology for AI agents. From test strategy to execution, coverage to reporting — everything you need to ship quality software. Phase 1: Test Strategy Design Before writing a single test, design the strategy. Strategy Brief Template Test Type Decision Matrix | Risk Profile | Unit | Integration | E2E | Performance | Security | Accessibilit","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:1kalin:afrexai-qa-testing-engine","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/1kalin/afrexai-qa-testing-engine","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/1kalin/afrexai-qa-testing-engine","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"QA & Testing Engine — Complete Software Quality System QA & Testing Engine — Complete Software Quality System The definitive testing methodology for AI agents. "},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"stage_4_post_deploy","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":2,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"stage_4_post_deploy","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:stage_4_post_deploy|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T06:17:58.614Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T06:17:58.614Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T06:17:58.614Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:1kalin:afrexai-qa-testing-engine","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-testing-engine/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-testing-engine/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-testing-engine/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-testing-engine/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-testing-engine/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-testing-engine/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T12:43:23.434Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-testing-engine/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-testing-engine/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-testing-engine/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-1kalin-afrexai-qa-testing-engine/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"# QA & Testing Engine — Complete Software Quality System\n\n> The definitive testing methodology for AI agents. From test strategy to execution, coverage to reporting — everything you need to ship quality software.\n\n## Phase 1: Test Strategy Design\n\nBefore writing a single test, design the strategy.\n\n### Strategy Brief Template\n\n```yaml\nproject:\n  name: \"\"\n  type: web-app | api | mobile | library | cli | data-pipeline\n  languages: [typescript, python, go, java]\n  frameworks: [react, express, django, spring]\n  \nrisk_profile:\n  data_sensitivity: low | medium | high | critical  # PII, financial, health\n  user_impact: internal | b2b | b2c | life-safety\n  deployment_frequency: daily | weekly | monthly\n  regulatory: [none, SOC2, HIPAA, PCI-DSS, GDPR]\n\ntest_scope:\n  in_scope: []    # Features, services, components\n  out_of_scope: [] # Explicitly excluded (with reason)\n  \nenvironments:\n  dev: { url: \"\", db: \"local\" }\n  staging: { url: \"\", db: \"seeded\" }\n  prod: { url: \"\", smoke_only: true }\n```\n\n### Test Type Decision Matrix\n\n| Risk Profile | Unit | Integration | E2E | Performance | Security | Accessibility |\n|---|---|---|---|---|---|---|\n| Internal tool | ✅ Core | ✅ API | ⚠️ Happy path | ❌ | ⚠️ Basic | ❌ |\n| B2B SaaS | ✅ Full | ✅ Full | ✅ Critical flows | ✅ Load | ✅ OWASP Top 10 | ✅ WCAG AA |\n| B2C high-traffic | ✅ Full | ✅ Full | ✅ Full | ✅ Stress + soak | ✅ Full | ✅ WCAG AA |\n| Financial/Health | ✅ Full + mutation | ✅ Full + contract | ✅ Full + chaos | ✅ Full suite | ✅ Pen test | ✅ WCAG AAA |\n\n### Test Pyramid Architecture\n\n```\n         /  E2E  \\          5-10% — Critical user journeys only\n        / Integration \\     20-30% — API contracts, service boundaries\n       /    Unit Tests   \\  60-70% — Business logic, pure functions\n```\n\n**Anti-pattern: Ice cream cone** — More E2E than unit tests. Slow, flaky, expensive. Fix by pushing test coverage DOWN the pyramid.\n\n**Anti-pattern: Hourglass** — Lots of unit + E2E, no integration. Misses contract bugs between services.\n\n---\n\n## Phase 2: Unit Testing Mastery\n\n### The AAA Pattern (Arrange-Act-Assert)\n\nEvery unit test follows this structure:\n\n```typescript\ndescribe('PricingCalculator', () => {\n  // Group by behavior, not by method\n  describe('when customer has volume discount', () => {\n    it('applies tiered pricing above threshold', () => {\n      // ARRANGE — Set up the scenario\n      const calculator = new PricingCalculator();\n      const customer = createCustomer({ tier: 'enterprise', units: 150 });\n      \n      // ACT — Execute the behavior under test\n      const price = calculator.calculate(customer);\n      \n      // ASSERT — Verify the outcome (ONE logical assertion)\n      expect(price).toEqual({\n        subtotal: 12000,\n        discount: 1800,  // 15% volume discount\n        total: 10200,\n      });\n    });\n  });\n});\n```\n\n### Test Naming Convention\n\n**Format:** `[unit] [scenario] [expected behavior]`\n\n✅ Good:\n- `PricingCalculator applies 15% discount when units exceed 100`\n- `UserService throws NotFoundError when user ID is invalid`\n- `parseDate returns null for malformed ISO strings`\n\n❌ Bad:\n- `test1`, `should work`, `calculates price`\n\n### What to Unit Test (Priority Order)\n\n1. **Business logic** — Pricing, rules, calculations, state machines\n2. **Data transformations** — Parsers, formatters, serializers, mappers\n3. **Edge cases** — Boundaries, null/undefined, empty collections, overflow\n4. **Error handling** — Every `catch` block, every validation path\n5. **Pure functions** — Easiest to test, highest ROI\n\n### What NOT to Unit Test\n\n- Framework internals (React rendering, Express routing)\n- Simple getters/setters with no logic\n- Third-party library behavior\n- Implementation details (private methods, internal state)\n\n### Mocking Rules\n\n| Dependency Type | Strategy | Example |\n|---|---|---|\n| Database | Mock the repository/DAO | `jest.mock('./userRepo')` |\n| HTTP API | Mock the client or use MSW | `msw.http.get('/api/users', ...)` |\n| File system | Mock fs or use temp dirs | `jest.mock('fs/promises')` |\n| Time/Date | Fake timers | `jest.useFakeTimers()` |\n| Randomness | Seed or mock | `jest.spyOn(Math, 'random')` |\n| Environment | Override env vars | `process.env.NODE_ENV = 'test'` |\n\n**Rule: Mock at boundaries, not internals.** If you're mocking a class you own, your design might need refactoring.\n\n### Coverage Targets\n\n| Metric | Minimum | Good | Excellent |\n|---|---|---|---|\n| Line coverage | 70% | 85% | 95%+ |\n| Branch coverage | 60% | 80% | 90%+ |\n| Function coverage | 75% | 90% | 95%+ |\n| Critical path coverage | 100% | 100% | 100% |\n\n**Warning:** 100% coverage ≠ quality. Coverage measures what code ran, not what was verified. A test with no assertions has coverage but no value.\n\n---\n\n## Phase 3: Integration Testing\n\n### API Testing Checklist\n\nFor every API endpoint, test:\n\n```yaml\nendpoint: POST /api/orders\ntests:\n  happy_path:\n    - Valid request returns 201 with order ID\n    - Response matches schema\n    - Database record created correctly\n    - Events/webhooks fired\n    \n  validation:\n    - Missing required fields → 400 with field errors\n    - Invalid data types → 400 with type errors\n    - Business rule violations → 422 with explanation\n    \n  authentication:\n    - No token → 401\n    - Expired token → 401\n    - Wrong role → 403\n    - Valid token → proceeds\n    \n  edge_cases:\n    - Duplicate request (idempotency) → same response\n    - Concurrent requests → no race condition\n    - Maximum payload size → 413 or graceful handling\n    - Special characters in input → no injection\n    \n  error_handling:\n    - Database down → 503 with retry hint\n    - External service timeout → 504 or fallback\n    - Rate limit exceeded → 429 with retry-after\n```\n\n### Contract Testing\n\nWhen services communicate, test the contract:\n\n```yaml\ncontract:\n  consumer: order-service\n  provider: payment-service\n  \n  interactions:\n    - description: \"Process payment\"\n      request:\n        method: POST\n        path: /payments\n        body:\n          amount: 99.99\n          currency: USD\n          order_id: \"ord_123\"\n      response:\n        status: 200\n        body:\n          payment_id: \"pay_xxx\"  # string, not null\n          status: \"completed\"    # enum: completed|pending|failed\n          \n  breaking_changes:  # NEVER do these without versioning\n    - Remove a field from response\n    - Change a field's type\n    - Add a required field to request\n    - Change the URL path\n    - Change error response format\n```\n\n### Database Testing Rules\n\n1. **Each test gets a clean state** — Use transactions that rollback, or truncate between tests\n2. **Use factories, not fixtures** — `createUser({ role: 'admin' })` > hardcoded SQL dumps\n3. **Test migrations** — Run migrate-up, migrate-down, migrate-up (roundtrip)\n4. **Test constraints** — Unique violations, FK cascades, NOT NULL\n5. **Test queries** — Especially complex JOINs, aggregations, window functions\n\n---\n\n## Phase 4: End-to-End Testing\n\n### Critical User Journey Mapping\n\nIdentify and test the flows that generate revenue or block users:\n\n```yaml\ncritical_journeys:\n  - name: \"Sign up → First value\"\n    steps:\n      - Visit landing page\n      - Click sign up\n      - Fill registration form\n      - Verify email\n      - Complete onboarding\n      - Perform first key action\n    max_duration: 3 minutes\n    \n  - name: \"Purchase flow\"\n    steps:\n      - Browse products\n      - Add to cart\n      - Enter shipping\n      - Enter payment\n      - Confirm order\n      - Receive confirmation email\n    max_duration: 2 minutes\n    \n  - name: \"Login → Core task → Logout\"\n    steps:\n      - Login (password + SSO + MFA variants)\n      - Navigate to core feature\n      - Complete primary workflow\n      - Verify result\n      - Logout\n    max_duration: 1 minute\n```\n\n### E2E Best Practices\n\n1. **Test user behavior, not implementation** — Click buttons by text/role, not by CSS class\n2. **Use data-testid sparingly** — Only when no accessible selector exists\n3. **Wait for state, not time** — `waitFor(element)` not `sleep(3000)`\n4. **Isolate test data** — Each test creates its own users/data\n5. **Run in CI with retries** — 1 retry for flaky network, investigate if >5% flake rate\n\n### Selector Priority (Best → Worst)\n\n1. `getByRole('button', { name: 'Submit' })` — Accessible, resilient\n2. `getByLabelText('Email')` — Form-specific, accessible\n3. `getByText('Welcome back')` — Content-based\n4. `getByTestId('submit-btn')` — Explicit test hook\n5. `querySelector('.btn-primary')` — ❌ Fragile, breaks on CSS changes\n\n### Flaky Test Triage\n\n| Symptom | Likely Cause | Fix |\n|---|---|---|\n| Passes locally, fails in CI | Timing/race condition | Add explicit waits, check CI resource limits |\n| Fails intermittently | Shared state between tests | Isolate test data, reset state |\n| Fails after deploy | Environment difference | Check env vars, API versions, feature flags |\n| Fails at specific time | Time-dependent logic | Mock dates/times, avoid time-sensitive assertions |\n| Fails in parallel | Resource contention | Use unique ports/DBs per worker |\n\n**Rule: Quarantine flaky tests within 24 hours.** A flaky test suite that everyone ignores is worse than no tests.\n\n---\n\n## Phase 5: Performance Testing\n\n### Load Test Design\n\n```yaml\nperformance_tests:\n  smoke:\n    vus: 5\n    duration: 1m\n    purpose: \"Verify test works\"\n    \n  load:\n    vus: 100  # Expected concurrent users\n    duration: 10m\n    ramp_up: 2m\n    purpose: \"Normal traffic behavior\"\n    thresholds:\n      p95_response: <500ms\n      error_rate: <1%\n      \n  stress:\n    vus: 300  # 3x expected load\n    duration: 15m\n    ramp_up: 5m\n    purpose: \"Find breaking point\"\n    \n  soak:\n    vus: 80\n    duration: 2h\n    purpose: \"Memory leaks, connection exhaustion\"\n    \n  spike:\n    stages:\n      - { vus: 50, duration: 2m }\n      - { vus: 500, duration: 30s }  # Sudden spike\n      - { vus: 50, duration: 2m }\n    purpose: \"Recovery behavior\"\n```\n\n### Performance Budgets\n\n| Metric | Web App | API | Background Job |\n|---|---|---|---|\n| Response time (p50) | <200ms | <100ms | N/A |\n| Response time (p95) | <1s | <500ms | N/A |\n| Response time (p99) | <3s | <1s | N/A |\n| Throughput | >100 rps | >500 rps | >1000/min |\n| Error rate | <0.1% | <0.1% | <0.5% |\n| CPU usage | <70% | <70% | <90% |\n| Memory growth | <5%/hr | <2%/hr | <10%/hr |\n\n### Database Performance Testing\n\n```yaml\ndb_performance:\n  query_tests:\n    - name: \"Dashboard aggregate query\"\n      baseline: 50ms\n      max_acceptable: 200ms\n      with_1M_rows: measure\n      with_10M_rows: measure\n      \n  index_verification:\n    - Run EXPLAIN ANALYZE on all critical queries\n    - Verify no sequential scans on tables >10K rows\n    - Check index usage statistics weekly\n    \n  connection_pool:\n    - Test at max connections\n    - Verify graceful handling when pool exhausted\n    - Monitor connection wait time\n```\n\n---\n\n## Phase 6: Security Testing\n\n### OWASP Top 10 Test Checklist\n\n```yaml\nsecurity_tests:\n  A01_broken_access_control:\n    - [ ] Horizontal privilege escalation (access other user's data)\n    - [ ] Vertical privilege escalation (access admin functions)\n    - [ ] IDOR (Insecure Direct Object References)\n    - [ ] Missing function-level access control\n    - [ ] CORS misconfiguration\n    \n  A02_cryptographic_failures:\n    - [ ] Sensitive data in transit (TLS 1.2+)\n    - [ ] Sensitive data at rest (encryption)\n    - [ ] Password hashing (bcrypt/argon2, not MD5/SHA)\n    - [ ] No secrets in code/logs/URLs\n    \n  A03_injection:\n    - [ ] SQL injection (parameterized queries)\n    - [ ] NoSQL injection\n    - [ ] Command injection (OS commands)\n    - [ ] XSS (stored, reflected, DOM-based)\n    - [ ] Template injection (SSTI)\n    \n  A04_insecure_design:\n    - [ ] Rate limiting on auth endpoints\n    - [ ] Account lockout after N failures\n    - [ ] CAPTCHA on public forms\n    - [ ] Business logic abuse scenarios\n    \n  A05_security_misconfiguration:\n    - [ ] Default credentials removed\n    - [ ] Error messages don't leak stack traces\n    - [ ] Security headers set (CSP, HSTS, X-Frame-Options)\n    - [ ] Directory listing disabled\n    - [ ] Unnecessary HTTP methods disabled\n    \n  A07_auth_failures:\n    - [ ] Brute force protection\n    - [ ] Session fixation\n    - [ ] Session timeout\n    - [ ] JWT validation (signature, expiry, issuer)\n    - [ ] MFA bypass attempts\n```\n\n### Input Validation Test Payloads\n\nTest every user input with:\n\n```yaml\ninjection_payloads:\n  sql: [\"' OR 1=1--\", \"'; DROP TABLE users;--\", \"1 UNION SELECT * FROM users\"]\n  xss: [\"<script>alert(1)</script>\", \"<img onerror=alert(1) src=x>\", \"javascript:alert(1)\"]\n  path_traversal: [\"../../etc/passwd\", \"..\\\\..\\\\windows\\\\system32\", \"%2e%2e%2f\"]\n  command: [\"; ls -la\", \"| cat /etc/passwd\", \"$(whoami)\", \"`id`\"]\n  \nboundary_values:\n  strings: [\"\", \" \", \"a\"*10000, null, undefined, \"emoji: 🎯\", \"unicode: é à ü\", \"rtl: مرحبا\"]\n  numbers: [0, -1, 2147483647, -2147483648, NaN, Infinity, 0.1+0.2]\n  arrays: [[], [null], Array(10000)]\n  dates: [\"1970-01-01\", \"2099-12-31\", \"invalid-date\", \"2024-02-29\", \"2023-02-29\"]\n```\n\n---\n\n## Phase 7: Test Automation Architecture\n\n### Framework Selection Guide\n\n| Need | JavaScript/TS | Python | Go | Java |\n|---|---|---|---|---|\n| Unit | Vitest / Jest | pytest | testing + testify | JUnit 5 |\n| API | Supertest | httpx + pytest | net/http/httptest | RestAssured |\n| E2E (browser) | Playwright | Playwright | chromedp | Selenium |\n| Performance | k6 | Locust | vegeta | Gatling |\n| Contract | Pact | Pact | Pact | Pact |\n| Security | ZAP + custom | Bandit + custom | gosec | SpotBugs |\n\n### CI Pipeline Test Stages\n\n```yaml\npipeline:\n  stage_1_fast:  # <2 min, blocks PR\n    - Lint + type check\n    - Unit tests\n    - Security: dependency scan (npm audit / safety)\n    \n  stage_2_thorough:  # <10 min, blocks merge\n    - Integration tests\n    - Contract tests\n    - Security: SAST scan\n    - Coverage report + threshold check\n    \n  stage_3_confidence:  # <30 min, blocks deploy\n    - E2E critical journeys\n    - Visual regression (if applicable)\n    - Security: container scan\n    \n  stage_4_post_deploy:  # After deploy to staging\n    - Smoke tests against staging\n    - Performance baseline check\n    - Security: DAST scan (ZAP)\n    \n  stage_5_production:  # After prod deploy\n    - Smoke tests (critical paths only)\n    - Synthetic monitoring enabled\n    - Canary metrics watching\n```\n\n### Test Data Management\n\n```yaml\ntest_data_strategy:\n  unit_tests:\n    approach: factories  # Builder pattern, create exactly what you need\n    example: \"createUser({ role: 'admin', plan: 'enterprise' })\"\n    \n  integration_tests:\n    approach: seeded_database\n    reset: per_test_suite  # Transaction rollback or truncate\n    sensitive_data: anonymized  # Never use real PII\n    \n  e2e_tests:\n    approach: api_setup  # Create data via API before test\n    cleanup: after_each  # Delete created data\n    isolation: unique_identifiers  # Timestamp or UUID in test data\n    \n  performance_tests:\n    approach: representative_dataset\n    volume: 10x_production  # Test with more data than prod\n    generation: faker_libraries  # Realistic but synthetic\n```\n\n---\n\n## Phase 8: Quality Metrics & Reporting\n\n### Test Health Dashboard\n\n```yaml\nmetrics:\n  test_suite_health:\n    total_tests: 0\n    passing: 0\n    failing: 0\n    skipped: 0  # >5% skipped = tech debt alarm\n    flaky: 0    # >2% flaky = quarantine immediately\n    \n  coverage:\n    line: \"0%\"\n    branch: \"0%\"\n    critical_paths: \"0%\"  # Must be 100%\n    \n  execution:\n    unit_duration: \"0s\"    # Target: <30s\n    integration_duration: \"0s\"  # Target: <5m\n    e2e_duration: \"0s\"     # Target: <15m\n    total_ci_time: \"0s\"    # Target: <20m\n    \n  defect_metrics:\n    bugs_found_in_test: 0\n    bugs_escaped_to_prod: 0\n    escape_rate: \"0%\"      # Target: <5%\n    mttr: \"0h\"             # Mean time to resolve\n    \n  trends:  # Track weekly\n    new_tests_added: 0\n    tests_deleted: 0  # Healthy deletion = removing redundant tests\n    coverage_delta: \"+0%\"\n    flake_rate_delta: \"+0%\"\n```\n\n### Test Report Template\n\n```markdown\n# Test Report — [Feature/Sprint/Release]\n\n## Summary\n- **Status:** ✅ PASS / ⚠️ PASS WITH RISKS / ❌ FAIL\n- **Tests Run:** X | **Passed:** X | **Failed:** X | **Skipped:** X\n- **Coverage:** Line X% | Branch X% | Critical 100%\n- **Duration:** Xm Xs\n\n## Key Findings\n\n### 🔴 Critical (Block Release)\n1. [Finding] — [Impact] — [Fix recommendation]\n\n### 🟡 High (Fix Before Next Release)\n1. [Finding] — [Impact] — [Fix recommendation]\n\n### 🟢 Medium/Low (Backlog)\n1. [Finding] — [Impact]\n\n## Risk Assessment\n- **Untested areas:** [list]\n- **Known flaky tests:** [list with ticket IDs]\n- **Performance concerns:** [if any]\n\n## Recommendation\n[Ship / Ship with monitoring / Hold for fixes]\n```\n\n### Quality Score (0-100)\n\n| Dimension | Weight | Scoring |\n|---|---|---|\n| Test coverage | 20% | <60%=0, 60-70%=5, 70-80%=10, 80-90%=15, 90%+=20 |\n| Critical path coverage | 20% | <100%=0, 100%=20 |\n| Defect escape rate | 15% | >10%=0, 5-10%=5, 2-5%=10, <2%=15 |\n| Test suite speed | 10% | >30m=0, 20-30m=3, 10-20m=7, <10m=10 |\n| Flake rate | 10% | >5%=0, 2-5%=3, 1-2%=7, <1%=10 |\n| Security test coverage | 10% | None=0, Basic=3, OWASP Top 10=7, Full=10 |\n| Documentation | 5% | None=0, Basic=2, Complete=5 |\n| Automation ratio | 10% | <50%=0, 50-70%=3, 70-90%=7, 90%+=10 |\n\n**Scoring:** 0-40 = 🔴 Critical | 41-60 = 🟡 Needs Work | 61-80 = 🟢 Good | 81-100 = 💎 Excellent\n\n---\n\n## Phase 9: Specialized Testing\n\n### Accessibility Testing (WCAG 2.1)\n\n```yaml\naccessibility_checklist:\n  level_a:  # Minimum compliance\n    - [ ] All images have alt text\n    - [ ] All form inputs have labels\n    - [ ] Color is not the only visual indicator\n    - [ ] Page has proper heading hierarchy (h1→h2→h3)\n    - [ ] All functionality available via keyboard\n    - [ ] Focus is visible and logical\n    - [ ] No content flashes >3 times/second\n    \n  level_aa:  # Standard compliance (recommended)\n    - [ ] Color contrast ratio ≥4.5:1 (normal text)\n    - [ ] Color contrast ratio ≥3:1 (large text)\n    - [ ] Text resizable to 200% without loss\n    - [ ] Skip navigation links\n    - [ ] Consistent navigation across pages\n    - [ ] Error suggestions provided\n    - [ ] ARIA landmarks for page regions\n    \n  tools:\n    - axe-core (automated, catches ~30% of issues)\n    - Lighthouse accessibility audit\n    - Manual keyboard navigation test\n    - Screen reader testing (VoiceOver/NVDA)\n```\n\n### API Backward Compatibility Testing\n\n```yaml\ncompatibility_tests:\n  when_updating_api:\n    - [ ] All existing fields still present in response\n    - [ ] No field type changes (string→number)\n    - [ ] New required request fields have defaults\n    - [ ] Deprecated fields still work (with warning header)\n    - [ ] Error format unchanged\n    - [ ] Pagination behavior unchanged\n    - [ ] Rate limits not reduced\n    \n  versioning_strategy:\n    - URL versioning: /v1/users, /v2/users\n    - Header versioning: Accept: application/vnd.api+json;version=2\n    - Sunset header for deprecated versions\n    - Minimum 6-month deprecation notice\n```\n\n### Chaos Engineering Principles\n\n```yaml\nchaos_tests:\n  network:\n    - Service dependency goes down → graceful degradation?\n    - Network latency increases 10x → timeout handling?\n    - DNS resolution fails → fallback behavior?\n    \n  infrastructure:\n    - Database primary fails → replica promotion?\n    - Cache (Redis) goes down → DB fallback works?\n    - Disk fills up → alerting + graceful failure?\n    \n  application:\n    - Memory pressure → OOM handling?\n    - CPU saturation → request queuing?\n    - Certificate expiry → monitoring alert?\n    \n  data:\n    - Corrupt message in queue → dead letter + alert?\n    - Schema migration fails mid-way → rollback works?\n    - Clock skew between services → idempotency holds?\n```\n\n---\n\n## Phase 10: Daily QA Workflow\n\n### For New Features\n\n1. **Review requirements** — Identify test scenarios before code is written (shift-left)\n2. **Write test cases** — Cover happy path, edge cases, error cases, security\n3. **Review PR tests** — Are tests meaningful? Do they test behavior, not implementation?\n4. **Run full suite** — Unit + integration + E2E for affected areas\n5. **Report findings** — Use the test report template above\n\n### For Bug Fixes\n\n1. **Write failing test first** — Reproduce the bug as a test\n2. **Verify fix makes test pass** — The test IS the proof\n3. **Check for regression** — Run related test suites\n4. **Add to regression suite** — Bug tests prevent re-introduction\n\n### Weekly QA Review\n\n```yaml\nweekly_review:\n  monday:\n    - Review flaky test quarantine — fix or delete\n    - Check coverage trends — declining = tech debt\n    - Review escaped defects — update test strategy\n    \n  friday:\n    - Update test health dashboard\n    - Clean up obsolete tests\n    - Document new testing patterns discovered\n    - Plan next week's testing focus\n```\n\n### Natural Language Commands\n\n- `\"Create test strategy for [project/feature]\"` → Full strategy brief\n- `\"Write unit tests for [function/class]\"` → AAA pattern tests with edge cases\n- `\"Test this API endpoint: [method] [path]\"` → Full API test checklist\n- `\"Review these tests for quality\"` → Test code review with scoring\n- `\"Generate performance test plan\"` → k6/Locust test design\n- `\"Security test [feature/endpoint]\"` → OWASP-based test checklist\n- `\"Create test report for [release]\"` → Formatted test report\n- `\"What's our test health?\"` → Dashboard with metrics and recommendations\n- `\"Find gaps in our test coverage\"` → Analysis with prioritized recommendations\n- `\"Help debug this flaky test\"` → Root cause analysis with fix suggestions\n- `\"Set up CI test pipeline\"` → Stage-by-stage pipeline config\n- `\"Accessibility audit [page/component]\"` → WCAG checklist with findings\n","readmeExcerpt":"QA & Testing Engine — Complete Software Quality System The definitive testing methodology for AI agents. From test strategy to execution, coverage to reporting — everything you need to ship quality software. Phase 1: Test Strategy Design Before writing a single test, design the strategy. Strategy Brief Template Test Type Decision Matrix | Risk Profile | Unit | Integration | E2E | Performance | Security | Accessibilit","codeSnippets":[],"executableExamples":[{"language":"yaml","snippet":"project:\n  name: \"\"\n  type: web-app | api | mobile | library | cli | data-pipeline\n  languages: [typescript, python, go, java]\n  frameworks: [react, express, django, spring]\n  \nrisk_profile:\n  data_sensitivity: low | medium | high | critical  # PII, financial, health\n  user_impact: internal | b2b | b2c | life-safety\n  deployment_frequency: daily | weekly | monthly\n  regulatory: [none, SOC2, HIPAA, PCI-DSS, GDPR]\n\ntest_scope:\n  in_scope: []    # Features, services, components\n  out_of_scope: [] # Explicitly excluded (with reason)\n  \nenvironments:\n  dev: { url: \"\", db: \"local\" }\n  staging: { url: \"\", db: \"seeded\" }\n  prod: { url: \"\", smoke_only: true }"},{"language":"text","snippet":"/  E2E  \\          5-10% — Critical user journeys only\n        / Integration \\     20-30% — API contracts, service boundaries\n       /    Unit Tests   \\  60-70% — Business logic, pure functions"},{"language":"typescript","snippet":"describe('PricingCalculator', () => {\n  // Group by behavior, not by method\n  describe('when customer has volume discount', () => {\n    it('applies tiered pricing above threshold', () => {\n      // ARRANGE — Set up the scenario\n      const calculator = new PricingCalculator();\n      const customer = createCustomer({ tier: 'enterprise', units: 150 });\n      \n      // ACT — Execute the behavior under test\n      const price = calculator.calculate(customer);\n      \n      // ASSERT — Verify the outcome (ONE logical assertion)\n      expect(price).toEqual({\n        subtotal: 12000,\n        discount: 1800,  // 15% volume discount\n        total: 10200,\n      });\n    });\n  });\n});"},{"language":"yaml","snippet":"endpoint: POST /api/orders\ntests:\n  happy_path:\n    - Valid request returns 201 with order ID\n    - Response matches schema\n    - Database record created correctly\n    - Events/webhooks fired\n    \n  validation:\n    - Missing required fields → 400 with field errors\n    - Invalid data types → 400 with type errors\n    - Business rule violations → 422 with explanation\n    \n  authentication:\n    - No token → 401\n    - Expired token → 401\n    - Wrong role → 403\n    - Valid token → proceeds\n    \n  edge_cases:\n    - Duplicate request (idempotency) → same response\n    - Concurrent requests → no race condition\n    - Maximum payload size → 413 or graceful handling\n    - Special characters in input → no injection\n    \n  error_handling:\n    - Database down → 503 with retry hint\n    - External service timeout → 504 or fallback\n    - Rate limit exceeded → 429 with retry-after"},{"language":"yaml","snippet":"contract:\n  consumer: order-service\n  provider: payment-service\n  \n  interactions:\n    - description: \"Process payment\"\n      request:\n        method: POST\n        path: /payments\n        body:\n          amount: 99.99\n          currency: USD\n          order_id: \"ord_123\"\n      response:\n        status: 200\n        body:\n          payment_id: \"pay_xxx\"  # string, not null\n          status: \"completed\"    # enum: completed|pending|failed\n          \n  breaking_changes:  # NEVER do these without versioning\n    - Remove a field from response\n    - Change a field's type\n    - Add a required field to request\n    - Change the URL path\n    - Change error response format"},{"language":"yaml","snippet":"critical_journeys:\n  - name: \"Sign up → First value\"\n    steps:\n      - Visit landing page\n      - Click sign up\n      - Fill registration form\n      - Verify email\n      - Complete onboarding\n      - Perform first key action\n    max_duration: 3 minutes\n    \n  - name: \"Purchase flow\"\n    steps:\n      - Browse products\n      - Add to cart\n      - Enter shipping\n      - Enter payment\n      - Confirm order\n      - Receive confirmation email\n    max_duration: 2 minutes\n    \n  - name: \"Login → Core task → Logout\"\n    steps:\n      - Login (password + SSO + MFA variants)\n      - Navigate to core feature\n      - Complete primary workflow\n      - Verify result\n      - Logout\n    max_duration: 1 minute"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"QA & Testing Engine — Complete Software Quality System QA & Testing Engine — Complete Software Quality System The definitive testing methodology for AI agents. From test strategy to execution, coverage to reporting — everything you need to ship quality software. Phase 1: Test Strategy Design Before writing a single test, design the strategy. Strategy Brief Template Test Type Decision Matrix | Risk Profile | Unit | Integration | E2E | Performance | Security | Accessibilit","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":389,"uniquenessScore":63,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T12:43:23.434Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}