Quality assurance specialist for security, performance, accessibility, comprehensive testing, and quality standard alignment. Use for test, review, security audit, OWASP, coverage, lint work, and ISO/IEC 25010 or ISO/IEC 29119-aligned QA recommendations.
64
76%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Fix and improve this skill with Tessl
tessl review fix ./.agents/skills/oma-qa/SKILL.mdReview and verify software quality with priority on security, performance, accessibility, correctness, test coverage, and standards-aligned quality evidence.
resources/execution-protocol.md, ISO guide, and checklistnpm audit, bandit, lighthouse, linters, tests, and coverage tools when applicableresources/iso-quality.md.| Action | SSL primitive | Evidence |
|---|---|---|
| Read review scope and code | READ | Diff, files, reports |
| Select quality checks | SELECT | Security/performance/accessibility/test dimensions |
| Run automated tools | CALL_TOOL | Audit, lint, tests, Lighthouse, coverage |
| Compare behavior to standards | COMPARE | OWASP, WCAG, ISO guides |
| Validate findings | VALIDATE | Reproducibility and evidence |
| Write review report | WRITE | Findings and remediation |
| Notify outcome | NOTIFY | Final review summary |
npm audit
bandit -r .
lighthouse <url>Run only the tools that match the detected stack and available target. Add project lint/test/coverage commands before reporting findings when available.
| Scope | Resource target |
|---|---|
CODEBASE | Reviewed source, tests, configs, and diff |
PROCESS | Automated QA/security/performance/accessibility commands |
LOCAL_FS | Reports, coverage output, review artifacts |
USER_DATA | User-provided acceptance and quality criteria |
npm audit, bandit, lighthouseFollow resources/execution-protocol.md step by step.
Use resources/iso-quality.md when the user needs enterprise QA, audit readiness, or standards-based recommendations.
Vendor-specific execution protocols are injected automatically by oma agent:spawn.
Source files live under ../_shared/runtime/execution-protocols/{vendor}.md.
resources/execution-protocol.mdresources/iso-quality.mdresources/checklist.mdresources/error-playbook.mdresources/verify-ship-protocol.md (used when this skill runs inside the ultrawork workflow)../_shared/core/context-loading.md../_shared/core/context-budget.md../_shared/core/lessons-learned.md../oma-observability/SKILL.md §Integrations — canary RUM (Core Web Vitals), backend perf spans3021301
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.