Skip to content
Back to skills

Sdd Qa

ASecurity

Independent quality assurance for one SDD Composy task in qa_required: CA coverage, unit/integration/E2E, accessibility, responsiveness, environment, and evidence inventory, producing the QA report and requesting evidence_required. Use when a task finished execution — 'rodar o QA da task', 'testar a TASK-003', 'validar a implementação'. Do NOT use for code review (sdd-review), the final verdict (sdd-verify), or test runs outside an SDD task.

  • 3 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
testing

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 22, 2026

npx -y skills add pwdev-solucoes/pwdev-claude-marketplace --skill sdd-qa --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sdd Qa?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Sdd Qa
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/pwdev-solucoes-sdd-qa/badge)](https://www.skillsdirectory.com/skills/pwdev-solucoes-sdd-qa)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: sdd-qa
description: >
  Independent quality assurance for one SDD Composy task in qa_required: CA
  coverage, unit/integration/E2E, accessibility, responsiveness, environment, and
  evidence inventory, producing the QA report and requesting evidence_required. Use
  when a task finished execution — 'rodar o QA da task', 'testar a TASK-003',
  'validar a implementação'. Do NOT use for code review (sdd-review), the final
  verdict (sdd-verify), or test runs outside an SDD task.
metadata:
  version: 0.1.0
---

# SDD QA

This portable skill runs independent quality assurance for a task in `qa_required` and writes
`tasks/prd-<slug>/qa-<task-id>.md`. Read `templates/qa.md` and render it, keeping its frontmatter keys and headings exactly (translate prose only). The bundled `scripts/sdd_qa.py:assess` helper performs the deterministic
validation; the skill routes inputs and presents its result without reimplementing the gates.

Language: before writing human-facing prose, run `scripts/sdd_language.py <repo-root>` and use the persisted language; on `not_initialized`, return it with `next_action: run_init`. Localization rules: `references/language.md`.

## Contract

Consume the approved CA, SC, and test mappings; use browser capability when E2E applies. The
`assess` payload carries `state`, `acceptance` (`id`, `story`, `tests`), `results` (`unit`,
`integration`, `e2e`: `status`, `command`, `environment`, `exit_code`, `evidence`), `browser`,
`accessibility`, `responsiveness`, `environment` (`ready`, `runtime`, `versions`, `cleanup`),
`regression`, `evidence` (`path`, `type`, `result`, `summary`, `source`, `sha256`), and
`human_approved`. Integration, E2E, accessibility, and responsiveness may be
`{"status": "NOT_APPLICABLE", "justification": "..."}` when the TechSpec justifies it; unit tests
never are. Record
unit, integration, E2E, accessibility, responsiveness, environment, regression, and evidence
inventory results with confined paths and SHA-256 digests.

Fail closed: missing mappings, failed tests, unavailable browser capability, unclean environment,
missing evidence, or any blocker sets the report to `REJECTED`, records
`scripts/sdd_tasks.py evidence <state> <TASK-ID> qa --status rejected`, and moves the task with
`transition <state> <TASK-ID> rejected --reason <blocker>` instead of `evidence_required`; a
rejected report cannot advance. A passing, approved report records `qa --status passed` before the
`evidence_required` (or, without a dossier, `review_required`) transition is requested. Only explicit human approval can approve
the report. Generation and verification actors remain distinct. Do not change approved
requirements, stories, architecture, or source code, and do not stop user-owned services.

## Read when

- `references/quality.md` — writing the report (required coverage, evidence inventory, gate
  semantics); `templates/qa.md` when rendering it.

## Output

Return the report path, coverage matrix, commands and exit codes, environment, evidence inventory,
blockers, lifecycle status, and permitted next transition.

Safety: Do not commit, push, or publish. Do not read or expose `.env`, credentials, tokens, private keys, certificates, or fleet environment files. Full contract: `references/safety.md`.

Files in this skill

  • SKILL.md3.2 KB
  • agents/openai.yaml191 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…