mo-qa
Run Controlled Web QA with Mo
Manual web QA can be slow to repeat and difficult to observe across browser states. This skill helps you create, monitor, and manage Momentic Mo sessions with explicit test scope.
Не устанавливайте этот Skill автоматически.
Каноническая политика требует проверки оператором перед любым действием по установке.
Установить с помощью моего Агента
Скопируйте этот запрос в своего Агента. Он содержит каноническую страницу Skill и манифест.
Review the Skillstore skill "mo-qa" from https://skillstore.io/skills/momentic-ai-mo-qa.md and its manifest at https://skillstore.io/api/skills/momentic-ai-mo-qa/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Ваш Агент по-прежнему должен показать план и запросить все подтверждения, требуемые политикой безопасности.
Ресурсы для AI-агентов
Используйте эти ссылки, когда AI-агенту, crawler или script нужен чистый контекст вместо полной страницы.
Протестировать
Использование «mo-qa». Test the checkout shipping change on staging. Do not submit payment or modify shared catalog data.
Ожидаемый результат:
A scoped QA brief covering the target URL, expected shipping behavior, staging sign-in, test-cart limits, prohibited actions, and pass criteria.
Использование «mo-qa». Mo is waiting for input after reporting a possible checkout bug.
Ожидаемый результат:
A follow-up message that answers the pending question, preserves the staging-only scope, and requests bounded waiting for the next attention boundary.
Использование «mo-qa». The local app needs one API address and one web address.
Ожидаемый результат:
- A tunnel plan exposing only the two required host and port addresses.
- A reminder to stop the tunnel after the final session.
Аудит безопасности
КритичноThe static catalog is mostly false positive matches from Markdown command examples, CLI names, paths, and documented credential handling. The remote installer uses a critical curl-to-shell pattern, and the skill also enables remote execution and file transfer that require strict scope and data controls.
Подтверждённые проблемы безопасности (3)
Факторы риска
📁 Доступ к файловой системе (4)
🔑 Переменные окружения (2)
🌐 Доступ к сети (2)
⚙️ Внешние команды (50)
Обнаруженные паттерны
Поделиться и цитировать этот отчет
Делитесь версионным отчетом об оценке, нейтральным значком, встраиваемой карточкой и цитатами. Skillstore публикует доказательства, не решая, безопасен ли этот Skill.
Копировать ссылку на отчёт
https://skillstore.io/skills/momentic-ai-mo-qa/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportЗначок Markdown
[](https://skillstore.io/skills/momentic-ai-mo-qa?utm_source=security_passport_badge)Значок HTML
<a href="https://skillstore.io/skills/momentic-ai-mo-qa?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/momentic-ai-mo-qa/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Встраиваемая карточка
<iframe src="https://skillstore.io/embed/skills/momentic-ai-mo-qa.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Академические ссылки (APA · BibTeX · CFF)
Цитата APA
momentic-ai. (2026). mo-qa security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/momentic-ai-mo-qa/audits/1Цитата BibTeX
@techreport{momentic-ai-momentic-ai-mo-qa-2026,
author = {momentic-ai},
title = {mo-qa security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/momentic-ai-mo-qa/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "mo-qa security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "momentic-ai"
date-released: "2026-08-28"
url: "https://skillstore.io/skills/momentic-ai-mo-qa/audits/1"
identifiers:
- type: other
value: "skillstore:momentic-ai-mo-qa:audit:1"
description: "Skillstore immutable audit report identifier"
Оценка Skillstore
Почему такая оценка Достоверность доказательств: НизкийЧто вы можете построить
Validate a Staging Release
Prepare a focused brief, run Mo against a staging URL, and review structured results before a release decision.
Test a Private Local Build
Expose only required local or private addresses through a tunnel, then connect the Mo session to that tunnel.
Manage Long-Running QA Work
Poll visible session state, answer pending questions, stop active work, or archive completed sessions.
Попробуйте эти промпты
Create a QA brief for this staging URL: [URL]. Test [change]. Use [account]. Create only [test data]. Do not perform [restricted actions]. Pass when [criteria].
Identify the exact local host and port needed for this flow: [flow]. Draft the narrow tunnel command and a QA brief. Use only the staging account and fixture data. Include cleanup steps.
For session [session ID], specify a bounded polling sequence. Compare status and read state, inspect test cases, bugs, controls, and verdicts, and identify when user input is required.
Given this session state: [state and pending input], draft the next Mo message with --wait. Preserve the original acceptance criteria, avoid destructive actions, and state what must be verified afterward.
Лучшие практики
- Define the target, expected behavior, test data, prohibited actions, and acceptance criteria before starting.
- Use staging accounts and fixture data, and review structured findings before reporting a defect.
- Expose only required tunnel addresses and stop tunnels after the final session.
Избегать
- Starting a session with invented credentials, permissions, test data, or acceptance criteria.
- Uploading credentials or sensitive production files to the hosted sandbox.
- Sending a new turn to change concurrency or inviting destructive actions without explicit authorization.
Часто задаваемые вопросы
What is this skill for?
Does the skill run the CLI automatically?
What should a QA brief include?
Can Mo test a local application?
How should session output be reviewed?
How should files be handled?
Сведения для разработчиков
Автор
momentic-aiЛицензия
MIT
Ревизия Skillstore
r1
Примечание о версии
Автор не указал версию.
Репозиторий
https://github.com/momentic-ai/skills/tree/1433d485384014d893a3d268000a0468e69517bb/skills/mo-qaСсылка
c97b34cbe3bb336d2e81cb28f9929f7488ecb3e2
Актуальность поддержки
29.08.2026
Использование
1 загрузок · 0 просмотров
Структура файлов