Skip to content
Back to skills

Qa Fix Routing

ASecurity

Repo/tracker routing library for the vc-fix plugin — decides which external product repo owns a bug (client vs platform), whether the fix delivers as a direct PR, a fork-PR, or an upstream issue, and which VCS/tracker host to talk to. Used by /qa-fix and /project-init. Self-contained — no dependency on the ci/ directory.

  • 2 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 20, 2026
developmenttypescriptnodeazuregitapifrontendbackendfullstackdevops

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 28, 2026

npx -y skills add VirtoCommerce/vc-mcp-testing-module --skill qa-fix-routing --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Qa Fix Routing?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Qa Fix Routing
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/virtocommerce-qa-fix-routing/badge)](https://www.skillsdirectory.com/skills/virtocommerce-qa-fix-routing)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: qa-fix-routing
description: Repo/tracker routing library for the vc-fix plugin — decides which external product repo owns a bug (client vs platform), whether the fix delivers as a direct PR, a fork-PR, or an upstream issue, and which VCS/tracker host to talk to. Used by /qa-fix and /project-init. Self-contained — no dependency on the ci/ directory.
---

# qa-fix-routing — repo + tracker routing library

Self-contained TypeScript library, so the `vc-fix` plugin does not depend on the
`ci/` directory persisting or being installed. `/qa-fix` and `/project-init` invoke
these modules directly (via a `tsx`/`node` one-off script) rather than authoring
routing logic inline.

## Files

| File | Role |
|------|------|
| `skill-dir.ts` | `SKILL_DIR` — this directory's own path via `fileURLToPath(import.meta.url)`, CWD-independent. Shared by `repo-router.ts` and `module-registry.ts` so the pattern isn't duplicated. |
| `repo-router.ts` | Core routing: `repoKind`, `repoOwnership`, `isAllowedRepo`, `repoProfile` (build/test cmd per kind), `contributionPlan` (direct / fork / issue), `suggestRepo`, `checkoutForFix`. Reads `fix-repos.json` (allowlist + routing hints) and the deployment profile (`project-profile.json` via `loadProjectProfile`). |
| `module-registry.ts` | Live VC module dependency graph via the Platform API (`BACK_URL`) — `repoFromProjectUrl`, `moduleIdToRepoGuess`. Caches to `.module-registry.cache.json` (gitignored) next to this file. |
| `provenance.ts` | Pure logic, no I/O — `classifyFrontendProvenance` / `frontendDeliveryPlan` for Gate 1b (telling a client's storefront-fork customization from an unmodified-platform bug). Depends only on `repo-router.ts`'s `RepoOwnership` type. |
| `ado-rest.ts` | Azure DevOps REST auth helpers (PAT or `az login`) shared by the Azure tracker/VCS. |
| `vcs/` | `Vcs` interface + `github-vcs.ts` (gh CLI) + `azure-repos-vcs.ts` (ADO REST) implementations + `index.ts` factory (`getVcs`/`getUpstreamVcs`). |
| `trackers/` | `Tracker` interface + `jira-tracker.ts` + `azure-tracker.ts` implementations + `index.ts` factory. |
| `fix-repos.json` | Data: allowed-repo patterns/denylist/explicit kinds + routing keyword table. Override path via `FIX_REPOS_CONFIG`; org override via `FIX_REPO_ORG`. |

## Why self-contained

The `fix-repos.json` / `.module-registry.cache.json`
default paths resolve off this directory's own path (`SKILL_DIR`, from `skill-dir.ts`)
rather than `process.cwd()` — still overridable via `FIX_REPOS_CONFIG` /
`MODULE_REGISTRY_CACHE`. If `ci/` is ever removed from this repo, or this plugin
is installed on its own with no `ci/` present at all, `vc-fix` keeps working
unaffected.

## Fully self-contained (not repo-coupled)

`vc-fix` does not assume it lives inside a full checkout of this repo. Claude
Code plugin installs don't reliably give a plugin's own commands/skills a
resolvable "project root" to reference shared files from (no documented
`${CLAUDE_PLUGIN_ROOT}`-equivalent, and bare relative paths resolve against
whatever the *user's* current working directory happens to be — see the
plugin's own `knowledge/`, `.claude/rules/`, `scripts/lib/` etc., which are
**duplicated into `plugins/vc-fix/`** rather than referenced at the parent
repo's root, precisely to avoid that dependency). `scripts/lib/project-profile.mjs`
and `scripts/lib/resolve-test-env.js` are copied to `plugins/vc-fix/scripts/lib/`
(not shared with the root copy) — see the `../../scripts/lib/project-profile.mjs`
imports in `repo-router.ts` and the one-deeper `../../../scripts/lib/...` in the
`vcs/`/`trackers/` files.

> The rest of `vc-fix` (its command/agent/skill markdown) still resolves file
> references as bare relative paths, which inherits the same undocumented-CWD
> risk described above for any tool call the model issues at runtime — that's a
> broader `/project-init`-level concern tracked separately, not something this
> one skill's file layout can fix on its own.

## Consumers

- `commands/qa-fix.md` (Gate 1 routing, Gate 1b provenance, Phase 5 PR delivery, Phase 6 CI-check-contract-by-ownership)
- `commands/project-init.md` / `skills/project-init/*.mjs` (writes `project-profile.json` that `repoOwnership`/`contributionPlan` read)
- `agents/fullstack-backend.md`, `agents/fullstack-frontend.md` (checkout + repo profile for the fix)

Files in this skill

  • SKILL.md4.6 KB
  • ado-html.d.mts2 KB
  • ado-html.mjs15.2 KB
  • ado-rest.ts2.3 KB
  • ado.mjs65.6 KB
  • bug-contract.mjs42.8 KB
  • fix-repos.json4.2 KB
  • iteration-dates.mjs4.9 KB
  • module-registry.ts8.7 KB
  • provenance.ts6.1 KB
  • repo-router.ts26.9 KB
  • skill-dir.ts566 B
  • trackers/azure-tracker.ts9.1 KB
  • trackers/index.ts1.1 KB
  • trackers/jira-tracker.ts7.8 KB
  • trackers/tracker.ts3.8 KB
  • vcs/azure-repos-vcs.ts3.8 KB
  • vcs/github-vcs.ts4.5 KB
  • vcs/index.ts2 KB
  • vcs/vcs.ts2.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…