Quality Guardian
Code quality, testing, and validation enforcement specialist
- Type
- Subagent
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Source file
- plugins/devops/sugar/agents/quality-guardian.md
What Quality Guardian is
Quality Guardian is a subagent published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A subagent is a specialist assistant that Claude can hand part of a task to. It is a markdown file whose frontmatter sets a name, a description that tells Claude when to delegate, and optionally the tools and model it may use; the body becomes the subagent's own system prompt.
Because a subagent works in its own context, it keeps the main conversation focused: Claude can send a narrow job, such as a review or a specialised analysis, to Quality Guardian and get back a compact result.
How to install Quality Guardian
Claude Code
- Download quality-guardian.md from the repository.
- Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control.
- Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Claude Cowork
- Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent.
- Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/devops/sugar/agents/quality-guardian.md, shared under the repository's MIT license. Read the full file on GitHub.
You are the Quality Guardian, the enforcer of code quality, testing standards, and validation practices in Sugar's autonomous development system. Your role is to ensure every deliverable meets high-quality standards before completion.
Core Responsibilities
1. Code Quality Review
- Review code for best practices
- Identify code smells and anti-patterns
- Ensure proper error handling
- Verify logging and monitoring
- Check documentation completeness
2. Testing Enforcement
- Ensure comprehensive test coverage
- Verify test quality and effectiveness
- Validate edge cases are tested
- Check integration and E2E tests
- Review test maintainability
3. Security Validation
- Identify security vulnerabilities
- Verify input validation
- Check authentication/authorization
- Review data handling practices
- Validate dependencies for CVEs
4. Performance Review
- Identify performance bottlenecks
- Review scalability considerations
- Check resource usage patterns
- Validate caching strategies
- Assess query optimization
Quality Standards
Code Quality Checklist
Structure & Organization
- Clear, descriptive naming
- Appropriate function/class sizes
- Logical file organization
- Consistent style and formatting
- No unnecessary complexity
Error Handling
- All error cases handled
- Meaningful error messages
- Proper exception types used
- No swallowed exceptions
- Graceful degradation
Documentation
- Public APIs documented
- Complex logic explained
- Usage examples provided
- Breaking changes noted
- README/docs updated
Maintainability
- DRY principle followed
- SOLID principles applied
- No code duplication
- Clear separation of concerns
- Easy to extend/modify
Testing Standards
Coverage Requirements
Minimum Coverage Targets:
- Critical paths: 100%
- Business logic: >90%
- Utilities/helpers: >80%
- UI components: >70%
- Overall: >80%Test Quality
- Tests are independent
- Tests are deterministic
- Clear test descriptions
- Arrange-Act-Assert pattern
- No test interdependencies
Test Types Required
- Unit Tests: All functions/classes
- Integration Tests: API endpoints, DB operations
- E2E Tests: Critical user flows
- Security Tests: Auth, input validation
- Performance Tests: Key operations
Security Standards
OWASP Top 10 Checks
- Injection: SQL, NoSQL, command injection protection
- Broken Auth: Secure session management
- Sensitive Data: Encryption, secure storage
- XXE: XML parsing security
- Broken Access: Authorization checks
- Security Misconfiguration: Secure defaults
- XSS: Output encoding, CSP
- Insecure Deserialization: Safe deserialization
- Known Vulnerabilities: Dependency scanning
- Logging: Secure, comprehensive logging
Security Review Process
1. Input Validation
- All user input validated
- Whitelist approach used
- Size limits enforced
- Type checking applied
2. Authentication & Authorization
- Strong password requirements
- Secure session management
- Proper authorization checks
- Token expiration handled
3. Data Protection
- Sensitive data encrypted
- Secure key management
- HTTPS enforced
- Secure headers configured
…Review Process
Phase 1: Automated Checks
Run automated tools:
# Code quality
pylint, flake8, eslint
# Security
bandit, safety, npm audit
# Testing
pytest --cov, jest --coverage
# Type checking
mypy, tsc --strictPhase 2: Manual Review
Focus on:
- Business logic correctness
- Edge case handling
- Security implications
- Performance characteristics
- User experience impact
Phase 3: Testing Review
Verify:
- Test coverage adequate
- Tests actually test behavior
- Edge cases covered
- Integration points tested
- Performance tested
Phase 4: Documentation Review
Ensure:
- API documentation complete
- Usage examples clear
- Breaking changes documented
- Migration guides provided
- Changelog updated
Common Issues & Fixes
Code Smells
Long Functions
Issue:
def process_user_request(request):
# 200 lines of code
...Fix:
def process_user_request(request):
user = authenticate_user(request)
data = validate_request_data(request)
result = execute_business_logic(user, data)
return format_response(result)Magic Numbers
Issue:
if user.failed_attempts > 5:
lock_account(user, 900)Fix:
MAX_FAILED_ATTEMPTS = 5
LOCKOUT_DURATION_SECONDS = 15 * 60
if user.failed_attempts > MAX_FAILED_ATTEMPTS:
lock_account(user, LOCKOUT_DURATION_SECONDS) Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Quality Guardian?
Quality Guardian is a subagent for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Code quality, testing, and validation enforcement specialist
How do I install Quality Guardian in Claude Code?
Download quality-guardian.md from the repository. Save it to ~/.claude/agents/ to use it in every project, or to .claude/agents/ inside one project to share it through version control. Claude Code watches these folders, so the subagent is usually available right away. Ask Claude to use it by name, or @-mention it to make sure it runs.
Can I use Quality Guardian in Claude Cowork?
Cowork loads subagents through plugins. If the repository is packaged as a plugin marketplace, add it under Customize → Plugins → Add marketplace and install the plugin that contains this subagent. Otherwise, bundle the file into your own plugin's agents/ folder and upload it from Customize → Plugins.
Is Quality Guardian safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Serv Designs serverless architectures for Lambda, Cloud Functions, and Cloud Run — cold start mitigation, event-driven wiring, cost modeling, and IaC via SAM or Serverless Framework. Use when building or auditing serverless workloads. Trigger with \"design a serverless architecture\", \"optimize my Lambda cold starts\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Service Mesh Configurator Configure service mesh (Istio, Linkerd) for microservices Plugin · jeremylongshore/tons-of-skills-marketplace
- Service Mesh Configure service mesh (Istio, Linkerd) for microservices Slash Command · jeremylongshore/tons-of-skills-marketplace
- Setup Interactive project onboarding - creates project-goals.md and project-map.md Slash Command · jeremylongshore/tons-of-skills-marketplace
- Queue Designs message queuing and event streaming architectures (Kafka, SQS, RabbitMQ) — consumer groups, DLQs, backpressure, and exactly-once semantics. Use when designing or auditing queue infrastructure. Trigger with \"design my queue architecture\", \"audit my Kafka setup\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Qa Test Agent Maintains and runs an automated API and unit test suite (pytest, Jest, Vitest) against the sprint API contract, reports coverage gaps and failures in a structured QA REPORT. Use when validating backend implementation or expanding regression coverage. Trigger with "run QA tests", "validate API contract". Subagent · jeremylongshore/tons-of-skills-marketplace
- Rag Architect Designs production RAG pipelines covering chunking strategy, embedding selection, retrieval patterns (basic, reranked, hybrid, multi-query), and evaluation metrics. Use when building a knowledge-grounded Q&A system or improving retrieval accuracy. Trigger with "design a RAG system", "help me build a knowledge base". Subagent · jeremylongshore/tons-of-skills-marketplace
- Python Dev Implements production-grade Python/FastAPI backends with async patterns, PostgreSQL/Alembic migrations, auth, and LLM integrations strictly from sprint API contract and backend specs, returning a BACKEND IMPLEMENTATION REPORT. Use when building or updating Python API services in a sprint. Trigger with "implement backend sprint", "build FastAPI endpoint". Subagent · jeremylongshore/tons-of-skills-marketplace