mo-qa
Run Controlled Web QA with Mo
Manual web QA can be slow to repeat and difficult to observe across browser states. This skill helps you create, monitor, and manage Momentic Mo sessions with explicit test scope.
この Skill を自動インストールしないでください。
基準ポリシーにより、インストール操作の前にオペレーターのレビューが必要です。
自分のエージェントでインストール
このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。
Review the Skillstore skill "mo-qa" from https://skillstore.io/skills/momentic-ai-mo-qa.md and its manifest at https://skillstore.io/api/skills/momentic-ai-mo-qa/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。
エージェントが読めるリソース
AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。
テストする
「mo-qa」を使用しています。 Test the checkout shipping change on staging. Do not submit payment or modify shared catalog data.
期待される結果:
A scoped QA brief covering the target URL, expected shipping behavior, staging sign-in, test-cart limits, prohibited actions, and pass criteria.
「mo-qa」を使用しています。 Mo is waiting for input after reporting a possible checkout bug.
期待される結果:
A follow-up message that answers the pending question, preserves the staging-only scope, and requests bounded waiting for the next attention boundary.
「mo-qa」を使用しています。 The local app needs one API address and one web address.
期待される結果:
- A tunnel plan exposing only the two required host and port addresses.
- A reminder to stop the tunnel after the final session.
セキュリティ監査
重大The static catalog is mostly false positive matches from Markdown command examples, CLI names, paths, and documented credential handling. The remote installer uses a critical curl-to-shell pattern, and the skill also enables remote execution and file transfer that require strict scope and data controls.
確認済みのセキュリティ上の懸念 (3)
リスク要因
📁 ファイルシステムへのアクセス (4)
🌐 ネットワークアクセス (2)
⚙️ 外部コマンド (50)
検出されたパターン
このレポートを共有・引用
バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。
レポートリンクをコピー
https://skillstore.io/skills/momentic-ai-mo-qa/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdownバッジ
[](https://skillstore.io/skills/momentic-ai-mo-qa?utm_source=security_passport_badge)HTMLバッジ
<a href="https://skillstore.io/skills/momentic-ai-mo-qa?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/momentic-ai-mo-qa/security.svg" alt="Skillstore security assessment" loading="lazy"></a>埋め込みカード
<iframe src="https://skillstore.io/embed/skills/momentic-ai-mo-qa.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>学術引用 (APA · BibTeX · CFF)
APA形式の引用
momentic-ai. (2026). mo-qa security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/momentic-ai-mo-qa/audits/1BibTeX形式の引用
@techreport{momentic-ai-momentic-ai-mo-qa-2026,
author = {momentic-ai},
title = {mo-qa security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/momentic-ai-mo-qa/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "mo-qa security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "momentic-ai"
date-released: "2026-08-28"
url: "https://skillstore.io/skills/momentic-ai-mo-qa/audits/1"
identifiers:
- type: other
value: "skillstore:momentic-ai-mo-qa:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore スコア
このスコアの理由 証拠の信頼度: 低作成できるもの
Validate a Staging Release
Prepare a focused brief, run Mo against a staging URL, and review structured results before a release decision.
Test a Private Local Build
Expose only required local or private addresses through a tunnel, then connect the Mo session to that tunnel.
Manage Long-Running QA Work
Poll visible session state, answer pending questions, stop active work, or archive completed sessions.
これらのプロンプトを試す
Create a QA brief for this staging URL: [URL]. Test [change]. Use [account]. Create only [test data]. Do not perform [restricted actions]. Pass when [criteria].
Identify the exact local host and port needed for this flow: [flow]. Draft the narrow tunnel command and a QA brief. Use only the staging account and fixture data. Include cleanup steps.
For session [session ID], specify a bounded polling sequence. Compare status and read state, inspect test cases, bugs, controls, and verdicts, and identify when user input is required.
Given this session state: [state and pending input], draft the next Mo message with --wait. Preserve the original acceptance criteria, avoid destructive actions, and state what must be verified afterward.
ベストプラクティス
- Define the target, expected behavior, test data, prohibited actions, and acceptance criteria before starting.
- Use staging accounts and fixture data, and review structured findings before reporting a defect.
- Expose only required tunnel addresses and stop tunnels after the final session.
回避
- Starting a session with invented credentials, permissions, test data, or acceptance criteria.
- Uploading credentials or sensitive production files to the hosted sandbox.
- Sending a new turn to change concurrency or inviting destructive actions without explicit authorization.
よくある質問
What is this skill for?
Does the skill run the CLI automatically?
What should a QA brief include?
Can Mo test a local application?
How should session output be reviewed?
How should files be handled?
開発者情報
作成者
momentic-aiライセンス
MIT
Skillstore リビジョン
r1
バージョンに関する注意
作者はバージョンを宣言していません。
リポジトリ
https://github.com/momentic-ai/skills/tree/1433d485384014d893a3d268000a0468e69517bb/skills/mo-qa参照
c97b34cbe3bb336d2e81cb28f9929f7488ecb3e2
メンテナンスの新しさ
2026/8/29
利用状況
1 ダウンロード · 0 閲覧
ファイル構成