mo-qa
Run Controlled Web QA with Mo
Manual web QA can be slow to repeat and difficult to observe across browser states. This skill helps you create, monitor, and manage Momentic Mo sessions with explicit test scope.
لا تثبّت هذا Skill تلقائيًا.
تتطلب السياسة المعتمدة مراجعة المشغّل قبل أي إجراء تثبيت.
التثبيت باستخدام Agent لدي
انسخ هذا الطلب إلى Agent لديك. يتضمن صفحة Skill المعتمدة وملف manifest.
Review the Skillstore skill "mo-qa" from https://skillstore.io/skills/momentic-ai-mo-qa.md and its manifest at https://skillstore.io/api/skills/momentic-ai-mo-qa/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.يجب أن يواصل Agent عرض خطته وطلب أي تأكيد تفرضه سياسة الأمان.
موارد مهيّأة لـ Agents
استخدم هذه الروابط عندما يحتاج AI Agent أو crawler أو script إلى سياق نظيف بدلًا من قراءة الصفحة كاملة.
اختبرها
جارٍ استخدام "mo-qa". Test the checkout shipping change on staging. Do not submit payment or modify shared catalog data.
النتيجة المتوقعة:
A scoped QA brief covering the target URL, expected shipping behavior, staging sign-in, test-cart limits, prohibited actions, and pass criteria.
جارٍ استخدام "mo-qa". Mo is waiting for input after reporting a possible checkout bug.
النتيجة المتوقعة:
A follow-up message that answers the pending question, preserves the staging-only scope, and requests bounded waiting for the next attention boundary.
جارٍ استخدام "mo-qa". The local app needs one API address and one web address.
النتيجة المتوقعة:
- A tunnel plan exposing only the two required host and port addresses.
- A reminder to stop the tunnel after the final session.
التدقيق الأمني
حرجThe static catalog is mostly false positive matches from Markdown command examples, CLI names, paths, and documented credential handling. The remote installer uses a critical curl-to-shell pattern, and the skill also enables remote execution and file transfer that require strict scope and data controls.
مخاوف أمنية مؤكدة (3)
عوامل الخطر
📁 الوصول إلى نظام الملفات (4)
🔑 متغيرات البيئة (2)
🌐 الوصول إلى الشبكة (2)
⚙️ الأوامر الخارجية (50)
الأنماط المكتشفة
شارك واستشهد بهذا التقرير
شارك تقرير التقييم المرتبط بالإصدار والشارة المحايدة وبطاقة التضمين والاستشهادات. تعرض Skillstore الأدلة من دون أن تقرر ما إذا كانت هذه المهارة آمنة.
نسخ رابط التقرير
https://skillstore.io/skills/momentic-ai-mo-qa/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportشارة Markdown
[](https://skillstore.io/skills/momentic-ai-mo-qa?utm_source=security_passport_badge)شارة HTML
<a href="https://skillstore.io/skills/momentic-ai-mo-qa?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/momentic-ai-mo-qa/security.svg" alt="Skillstore security assessment" loading="lazy"></a>بطاقة قابلة للتضمين
<iframe src="https://skillstore.io/embed/skills/momentic-ai-mo-qa.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>الاستشهادات الأكاديمية (APA · BibTeX · CFF)
اقتباس APA
momentic-ai. (2026). mo-qa security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/momentic-ai-mo-qa/audits/1اقتباس BibTeX
@techreport{momentic-ai-momentic-ai-mo-qa-2026,
author = {momentic-ai},
title = {mo-qa security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/momentic-ai-mo-qa/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "mo-qa security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "momentic-ai"
date-released: "2026-08-28"
url: "https://skillstore.io/skills/momentic-ai-mo-qa/audits/1"
identifiers:
- type: other
value: "skillstore:momentic-ai-mo-qa:audit:1"
description: "Skillstore immutable audit report identifier"
تقييم Skillstore
سبب هذا التقييم موثوقية الأدلة: منخفضما الذي يمكنك بناؤه
Validate a Staging Release
Prepare a focused brief, run Mo against a staging URL, and review structured results before a release decision.
Test a Private Local Build
Expose only required local or private addresses through a tunnel, then connect the Mo session to that tunnel.
Manage Long-Running QA Work
Poll visible session state, answer pending questions, stop active work, or archive completed sessions.
جرّب هذه الموجّهات
Create a QA brief for this staging URL: [URL]. Test [change]. Use [account]. Create only [test data]. Do not perform [restricted actions]. Pass when [criteria].
Identify the exact local host and port needed for this flow: [flow]. Draft the narrow tunnel command and a QA brief. Use only the staging account and fixture data. Include cleanup steps.
For session [session ID], specify a bounded polling sequence. Compare status and read state, inspect test cases, bugs, controls, and verdicts, and identify when user input is required.
Given this session state: [state and pending input], draft the next Mo message with --wait. Preserve the original acceptance criteria, avoid destructive actions, and state what must be verified afterward.
أفضل الممارسات
- Define the target, expected behavior, test data, prohibited actions, and acceptance criteria before starting.
- Use staging accounts and fixture data, and review structured findings before reporting a defect.
- Expose only required tunnel addresses and stop tunnels after the final session.
تجنب
- Starting a session with invented credentials, permissions, test data, or acceptance criteria.
- Uploading credentials or sensitive production files to the hosted sandbox.
- Sending a new turn to change concurrency or inviting destructive actions without explicit authorization.
الأسئلة المتكررة
What is this skill for?
Does the skill run the CLI automatically?
What should a QA brief include?
Can Mo test a local application?
How should session output be reviewed?
How should files be handled?
تفاصيل المطور
المؤلف
momentic-aiالترخيص
MIT
مراجعة Skillstore
r1
تنبيه الإصدار
لم يعلن المؤلف عن إصدار.
المستودع
https://github.com/momentic-ai/skills/tree/1433d485384014d893a3d268000a0468e69517bb/skills/mo-qaمرجع
c97b34cbe3bb336d2e81cb28f9929f7488ecb3e2
حداثة الصيانة
٢٩/٨/٢٠٢٦
الاستخدام
1 تنزيلات · 0 مشاهدات
بنية الملفات