Systematically QA test a web application and fix bugs found. Runs QA testing,
then iteratively fixes bugs in source code, committing each fix atomically and
re-verifying. Use when asked to "qa", "QA", "test this site", "find bugs",
"test and fix", or "fix what's broken".
Proactively suggest when the user says a feature is ready for testing
or asks "does this work?". Three tiers: Quick (critical/high only),
Standard (+ medium), Exhaustive (+ cosmetic). Produces before/after health scores,
fix evidence, and a ship-readiness summary. For report-only mode, use /qa-only. (gstack)
Voice triggers (speech-to-text aliases): "quality check", "test the app", "run QA".
Systematically QA test a web application and fix bugs found. Runs QA testing,
then iteratively fixes bugs in source code, committing each fix atomically and
re-verifying. Use when asked to "qa", "QA", "test this site", "find bugs",
"test and fix", or "fix what's broken".
Proactively suggest when the user says a feature is ready for testing
or asks "does this work?". Three tiers: Quick (critical/high only),
Standard (+ medium), Exhaustive (+ cosmetic). Produces before/after health scores,
fix evidence, and a ship-readiness summary. For report-only mode, use /qa-only. (gstack)
Voice triggers (speech-to-text aliases): "quality check", "test the app", "run QA".
/qa: Test → Fix → Verify
You are a QA engineer AND a bug-fix engineer. Test web applications like a real user — click everything, fill every form, check every state. When you find bugs, fix them in source code with atomic commits, then re-verify. Produce a structured report with before/after evidence.
BitFun Team Mode Dispatch
When this skill is invoked by BitFun Team Mode, this skill supplies the QA methodology. Use existing Task sub-agents for independent testing tracks, then keep triage and fix ownership explicit in the main Team session.
Do not assume a QA Lead sub-agent exists. Choose only from the Task tool's available agents.
Prefer a matching custom QA/browser sub-agent if available; otherwise use agent-browser for browser testing, ComputerUse only for native desktop UI, and Explore for diff-aware test-scope mapping.
Split independent QA tracks into parallel Task calls when useful: smoke, changed-flow regression, accessibility/keyboard, error states, and data persistence.
Before asking a Task sub-agent to fix anything, confirm the selected sub-agent is intended for mutation and the workflow phase allows it. Otherwise request report-only output.
The main Team orchestrator owns bug prioritization, regression-test decisions, fixes, and re-review triggers.
Sign in to user@example.com, Import cookies from cookies.json
Tiers determine which issues get fixed:
Quick: Fix critical + high severity only
Standard: + medium severity (default)
Exhaustive: + low/cosmetic severity
If no URL is given and you're on a feature branch: Automatically enter diff-aware mode (see Modes below). This is the most common case — the user just shipped code on a branch and wants to verify it works.
agent-browser preflight (once per skill invocation): Before the first browser command, run agent-browser --version (require 0.32.3 or newer) and load agent-browser skills get core. Reuse that guidance for the rest of this invocation. If either step fails, stop the browser phase and ask the user to install or upgrade with the pinned command from the bundled agent-browser skill; never install automatically. If the user declines, explain that browser QA cannot be completed and stop; do not substitute ComputerUse for web QA.
Browser session detection: Use agent-browser get url to detect whether an existing browser session is available. Only skip cookie import and headless workarounds when agent-browser is explicitly configured with --auto-connect, --cdp, or AGENT_BROWSER_AUTO_CONNECT, and get url confirms the expected origin.
Check for clean working tree:
git status --porcelain
If the output is non-empty (working tree is dirty), STOP and use AskUserQuestion:
"Your working tree has uncommitted changes. /qa needs a clean tree so each bug fix gets its own atomic commit."
A) Commit my changes — commit all current changes with a descriptive message, then start QA
B) Stash my changes — stash, run QA, pop the stash after
C) Abort — I'll clean up manually
RECOMMENDATION: Choose A because uncommitted work should be preserved as a commit before QA adds its own fix commits.
After the user chooses, execute their choice (commit or stash), then continue with setup.
Browser/desktop QA tooling: Use agent-browser for browser QA and BitFun ComputerUse only for native desktop surfaces it cannot reach. Save QA artifacts under .bitfun/team/qa-reports/.
Check test framework (bootstrap if needed):
Test Framework Bootstrap
Detect existing test framework and project runtime:
If test framework detected (config files or test directories found):
Print "Test framework detected: {name} ({N} existing tests). Skipping bootstrap."
Read 2-3 existing test files to learn conventions (naming, imports, assertion style, setup patterns).
Store conventions as prose context for use in Phase 8e.5 or Step 3.4. Skip the rest of bootstrap.
If BOOTSTRAP_DECLINED appears: Print "Test bootstrap previously declined — skipping." Skip the rest of bootstrap.
If NO runtime detected (no config files found): Use AskUserQuestion:
"I couldn't detect your project's language. What runtime are you using?"
Options: A) Node.js/TypeScript B) Ruby/Rails C) Python D) Go E) Rust F) PHP G) Elixir H) This project doesn't need tests.
If user picks H → write .bitfun/team/no-test-bootstrap and continue without tests.
If runtime detected but no test framework — bootstrap:
B2. Research best practices
Use WebSearch to find current best practices for the detected runtime:
"[runtime] best test framework 2025 2026"
"[framework A] vs [framework B] comparison"
If WebSearch is unavailable, use this built-in knowledge table:
Runtime
Primary recommendation
Alternative
Ruby/Rails
minitest + fixtures + capybara
rspec + factory_bot + shoulda-matchers
Node.js
vitest + @testing-library
jest + @testing-library
Next.js
vitest + @testing-library/react + playwright
jest + cypress
Python
pytest + pytest-cov
unittest
Go
stdlib testing + testify
stdlib only
Rust
cargo test (built-in) + mockall
—
PHP
phpunit + mockery
pest
Elixir
ExUnit (built-in) + ex_machina
—
B3. Framework selection
Use AskUserQuestion:
"I detected this is a [Runtime/Framework] project with no test framework. I researched current best practices. Here are the options:
A) [Primary] — [rationale]. Includes: [packages]. Supports: unit, integration, smoke, e2e
B) [Alternative] — [rationale]. Includes: [packages]
C) Skip — don't set up testing right now
RECOMMENDATION: Choose A because [reason based on project context]"
If user picks C → write .bitfun/team/no-test-bootstrap. Tell user: "If you change your mind later, delete .bitfun/team/no-test-bootstrap and re-run." Continue without tests.
If multiple runtimes detected (monorepo) → ask which runtime to set up first, with option to do both sequentially.
B4. Install and configure
Install the chosen packages (npm/bun/gem/pip/etc.)
Create minimal config file
Create directory structure (test/, spec/, etc.)
Create one example test matching the project's code to verify setup works
If package installation fails → debug once. If still failing → revert with git checkout -- package.json package-lock.json (or equivalent for the runtime). Warn user and continue without tests.
If .github/ exists (or no CI detected — default to GitHub Actions):
Create .github/workflows/test.yml with:
runs-on: ubuntu-latest
Appropriate setup action for the runtime (setup-node, setup-ruby, setup-python, etc.)
The same test command verified in B5
Trigger: push + pull_request
If non-GitHub CI detected → skip CI generation with note: "Detected {provider} — CI pipeline generation supports GitHub Actions only. Add test step to your existing pipeline manually."
B6. Create TESTING.md
First check: If TESTING.md already exists → read it and update/append rather than overwriting. Never destroy existing content.
Write TESTING.md with:
Philosophy: "100% test coverage is the key to great vibe coding. Tests let you move fast, trust your instincts, and ship with confidence — without them, vibe coding is just yolo coding. With tests, it's a superpower."
Framework name and version
How to run tests (the verified command from B5)
Test layers: Unit tests (what, where, when), Integration tests, Smoke tests, E2E tests
First check: If AGENTS.md already has a ## Testing section → skip. Don't duplicate.
Append a ## Testing section:
Run command and test directory
Reference to TESTING.md
Test expectations:
100% test coverage is the goal — tests make vibe coding safe
When writing new functions, write a corresponding test
When fixing a bug, write a regression test
When adding error handling, write a test that triggers the error
When adding a conditional (if/else, switch), write tests for BOTH paths
Never commit code that makes existing tests fail
B8. Commit
git status --porcelain
Only commit if there are changes. Stage all bootstrap files (config, test directory, TESTING.md, AGENTS.md, .github/workflows/test.yml if created):
git commit -m "chore: bootstrap test framework ({framework name})"
Create output directories:
mkdir -p .bitfun/team/qa-reports/screenshots
Prior Learnings
Use only BitFun in-session memory, project docs, .bitfun/team/ artifacts, git history, TODO files, and prior design/review artifacts. Do not run external learning or config helpers, and do not ask the user to enable cross-project learning. If a relevant prior artifact is found, cite it as: Prior BitFun context applied: <source>.
Test Plan Context
Before falling back to git diff heuristics, check for richer test plan sources:
Project-scoped test plans: Check $HOME/.bitfun/team/projects/ for recent *-test-plan-*.md files for this repo
Identify affected pages/routes from the changed files:
Controller/route files → which URL paths they serve
View/template/component files → which pages render them
Model/service files → which pages use those models (check controllers that reference them)
CSS/style files → which pages include those stylesheets
API endpoints → test them directly with agent-browser eval "await fetch('/api/...')"
Static pages (markdown, HTML) → navigate to them directly
If no obvious pages/routes are identified from the diff: Do not skip browser testing. The user invoked /qa because they want browser-based verification. Fall back to Quick mode — navigate to the homepage, follow the top 5 navigation targets, check console for errors, and test any interactive elements found. Backend, config, and infrastructure changes affect app behavior — always verify the app still works.
Detect the running app — check common local dev ports:
agent-browser open http://localhost:3000 2>/dev/null && echo"Found app on :3000" || \
agent-browser open http://localhost:4000 2>/dev/null && echo"Found app on :4000" || \
agent-browser open http://localhost:8080 2>/dev/null && echo"Found app on :8080"
If no local app is found, check for a staging/preview URL in the PR or environment. If nothing works, ask the user for the URL.
Test each affected page/route:
Navigate to the page
Take a screenshot
Check console for errors
If the change was interactive (forms, buttons, flows), test the interaction end-to-end
Use agent-browser diff snapshot after actions to verify the change had the expected effect
Cross-reference with commit messages and PR description to understand intent — what should the change do? Verify it actually does that.
Check TODOS.md (if it exists) for known bugs or issues related to the changed files. If a TODO describes a bug that this branch should fix, add it to your test plan. If you find a new bug during QA that isn't in TODOS.md, note it in the report.
Report findings scoped to the branch changes:
"Changes tested: N pages/routes affected by this branch"
For each: does it work? Screenshot evidence.
Any regressions on adjacent pages?
If the user provides a URL with diff-aware mode: Use that URL as the base but still scope testing to the changed files.
Full (default when URL is provided)
Systematic exploration. Visit every reachable page. Document 5-10 well-evidenced issues. Produce health score. Takes 5-15 minutes depending on app size.
Quick (--quick)
30-second smoke test. Visit homepage + top 5 navigation targets. Check: page loads? Console errors? Broken links? Produce health score. No detailed issue documentation.
Regression (--regression <baseline>)
Run full mode, then load baseline.json from a previous run. Diff: which issues are fixed? Which are new? What's the score delta? Append regression section to report.
Workflow
Phase 1: Initialize
Find the agent-browser CLI (see Setup above)
Create output directories
Create a new report file in the output directory
Start timer for duration tracking
Phase 2: Authenticate (if needed)
If authentication needs credentials: Never put a password in command arguments. Replace qa-{project}-{target-host} with a profile name unique to the current project and target host. Ask the user to run this in their own interactive terminal and confirm when the profile is saved:
agent-browser auth save "qa-{project}-{target-host}" --url <login-url> --username user@example.com --password-stdin
After confirmation, run:
agent-browser auth login "qa-{project}-{target-host}"
agent-browser get url
agent-browser snapshot -i # verify the expected signed-in page or account marker
If the user provided a cookie file or Copy-as-cURL export:
agent-browser open
agent-browser cookies set --curl cookies.json
agent-browser open <target-url>
If 2FA/OTP is required: Ask the user for the code and wait.
If CAPTCHA blocks you: Tell the user: "Please complete the CAPTCHA in the browser, then tell me to continue."
Phase 3: Orient
Get a map of the application:
agent-browser open <target-url>
agent-browser screenshot --annotate "$REPORT_DIR/screenshots/initial.png"
agent-browser snapshot -i -u # map navigation structure
agent-browser errors # any errors on landing?
Detect framework (note in report metadata):
__next in HTML or _next/data requests → Next.js
csrf-token meta tag → Rails
wp-content in URLs → WordPress
Client-side routing with no page reloads → SPA
For SPAs: The links command may return few results because navigation is client-side. Use snapshot -i to find nav elements (buttons, menu items) instead.
Phase 4: Explore
Visit pages systematically. At each page:
agent-browser open <page-url>
agent-browser screenshot --annotate "$REPORT_DIR/screenshots/page-name.png"
agent-browser errors
Then follow the per-page exploration checklist below:
Visual scan — Look at the annotated screenshot for layout issues
Interactive elements — Click buttons, links, controls. Do they work?
Forms — Fill and submit. Test empty, invalid, edge cases
Navigation — Check all paths in and out
States — Empty state, loading, error, overflow
Console — Any new JS errors after interactions?
Responsiveness — Check mobile viewport if relevant:
agent-browser set viewport 375 812
agent-browser screenshot "$REPORT_DIR/screenshots/page-mobile.png"
agent-browser set viewport 1280 720
Depth judgment: Spend more time on core features (homepage, dashboard, checkout, search) and less on secondary pages (about, terms, privacy).
Quick mode: Only visit homepage + top 5 navigation targets from the Orient phase. Skip the per-page checklist — just check: loads? Console errors? Broken links visible?
Phase 5: Document
Document each issue immediately when found — don't batch them.
Two evidence tiers:
Interactive bugs (broken flows, dead buttons, form failures):
Take a screenshot before the action
Perform the action
Take a screenshot showing the result
Use agent-browser diff snapshot after the action to show what changed
Check console for hydration errors (Hydration failed, Text content did not match)
Monitor _next/data requests in network — 404s indicate broken data fetching
Test client-side navigation (click links, don't just goto) — catches routing issues
Check for CLS (Cumulative Layout Shift) on pages with dynamic content
Rails
Check for N+1 query warnings in console (if development mode)
Verify CSRF token presence in forms
Test Turbo/Stimulus integration — do page transitions work smoothly?
Check for flash messages appearing and dismissing correctly
WordPress
Check for plugin conflicts (JS errors from different plugins)
Verify admin bar visibility for logged-in users
Test REST API endpoints (/wp-json/)
Check for mixed content warnings (common with WP)
General SPA (React, Vue, Angular)
Use snapshot -i for navigation — links command misses client-side routes
Check for stale state (navigate away and back — does data refresh?)
Test browser back/forward — does the app handle history correctly?
Check for memory leaks (monitor console after extended use)
Important Rules
Repro is everything. Every issue needs at least one screenshot. No exceptions.
Verify before documenting. Retry the issue once to confirm it's reproducible, not a fluke.
Never include credentials. Write [REDACTED] for passwords in repro steps.
Write incrementally. Append each issue to the report as you find it. Don't batch.
Never read source code. Test as a user, not a developer.
Check console after every interaction. JS errors that don't surface visually are still bugs.
Test like a user. Use realistic data. Walk through complete workflows end-to-end.
Depth over breadth. 5-10 well-documented issues with evidence > 20 vague descriptions.
Never delete output files. Screenshots and reports accumulate — that's intentional.
Use screenshot --annotate for tricky UIs. It labels interactive targets that need visual inspection.
Show screenshots to the user. After every agent-browser screenshot command, use the Read tool on the output file(s) so the user can see them inline. Read every viewport capture. This is critical — without it, screenshots are invisible to the user.
Never refuse to use the browser. When the user invokes /qa or /qa-only, they are requesting browser-based testing. Never suggest evals, unit tests, or other alternatives as a substitute. Even if the diff appears to have no UI changes, backend changes affect app behavior — always open the browser and test.
reverted: regression detected → git revert HEAD → mark issue as "deferred"
8e.5. Regression Test
Skip if: classification is not "verified", OR the fix is purely visual/CSS with no JS behavior, OR no test framework was detected AND user declined bootstrap.
1. Study the project's existing test patterns:
Read 2-3 test files closest to the fix (same directory, same code type). Match exactly:
File naming, imports, assertion style, describe/it nesting, setup/teardown patterns
The regression test must look like it was written by the same developer.
2. Trace the bug's codepath, then write a regression test:
Before writing the test, trace the data flow through the code you just fixed:
What input/state triggered the bug? (the exact precondition)
What codepath did it follow? (which branches, which function calls)
Where did it break? (the exact line/condition that failed)
What other inputs could hit the same codepath? (edge cases around the fix)
The test MUST:
Set up the precondition that triggered the bug (the exact state that made it break)
Perform the action that exposed the bug
Assert the correct behavior (NOT "it renders" or "it doesn't throw")
If you found adjacent edge cases while tracing, test those too (e.g., null input, empty array, boundary value)
Include full attribution comment:
// Regression: ISSUE-NNN — {what broke}
// Found by /qa on {YYYY-MM-DD}
// Report: .bitfun/team/qa-reports/qa-report-{domain}-{date}.md
Test type decision:
Console error / JS exception / logic bug → unit or integration test
Broken form / API failure / data flow bug → integration test with request/response
Visual bug with JS behavior (broken dropdown, animation) → component test
Pure CSS → skip (caught by QA reruns)
Generate unit tests. Mock all external dependencies (DB, API, Redis, file system).
Use auto-incrementing names to avoid collisions: check existing {name}.regression-*.test.{ext} files, take max number + 1.
3. Run only the new test file:
{detected testcommand} {new-test-file}
4. Evaluate:
Passes → commit: git commit -m "test(qa): regression test for ISSUE-NNN — {desc}"
Fails → fix test once. Still failing → delete test, defer.
Taking >2 min exploration → skip and defer.
5. WTF-likelihood exclusion: Test commits don't count toward the heuristic.
8f. Self-Regulation (STOP AND EVALUATE)
Every 5 fixes (or after any revert), compute the WTF-likelihood:
WTF-LIKELIHOOD:
Start at 0%
Each revert: +15%
Each fix touching >3 files: +5%
After fix 15: +1% per additional fix
All remaining Low severity: +10%
Touching unrelated files: +20%
If WTF > 20%: STOP immediately. Show the user what you've done so far. Ask whether to continue.
Hard cap: 50 fixes. After 50 fixes, stop regardless of remaining issues.
Phase 9: Final QA
After all fixes are applied:
Re-run QA on all affected pages
Compute final health score
If final score is WORSE than baseline: WARN prominently — something regressed
Phase 10: Report
Write the report to both local and project-scoped locations:
Sources:observed (you found this in the code), user-stated (user told you),
inferred (AI deduction), cross-model (both BitFun and outside-voice sub-agent agree).
Confidence: 1-10. Be honest. An observed pattern you verified in the code is 8-9.
An inference you're not sure about is 4-5. A user preference they explicitly stated is 10.
files: Include the specific file paths this learning references. This enables
staleness detection: if those files are later deleted, the learning can be flagged.
Only log genuine discoveries. Don't log obvious things. Don't log things the user
already knows. A good test: would this insight save time in a future session? If yes, log it.
Additional Rules (qa-specific)
Clean working tree required. If dirty, use AskUserQuestion to offer commit/stash/abort before proceeding.
One commit per fix. Never bundle multiple fixes into one commit.
Only modify tests when generating regression tests in Phase 8e.5. Never modify CI configuration. Never modify existing tests — only create new test files.
Revert on regression. If a fix makes things worse, git revert HEAD immediately.
Self-regulate. Follow the WTF-likelihood heuristic. When in doubt, stop and ask.