{"_id":"@dujaunpaul/qass","_rev":"2-13360fc85169aa0b7825c70aa411ba5f","name":"@dujaunpaul/qass","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@dujaunpaul/qass","version":"0.1.0","keywords":["qa","security","scanner","testing","vibe-coding","ai","cursor","windsurf","copilot","playwright"],"license":"SEE LICENSE IN LICENSE","_id":"@dujaunpaul/qass@0.1.0","maintainers":[{"name":"dujaunpaul","email":"dujaunjpaul@gmail.com"}],"homepage":"https://github.com/Dujaun-Paul/QASS","bugs":{"url":"https://github.com/Dujaun-Paul/QASS/issues"},"bin":{"qass":"dist/cli.js"},"dist":{"shasum":"4f4b4d0159806608e4147cffafe24eb5f9ab3091","tarball":"https://registry.npmjs.org/@dujaunpaul/qass/-/qass-0.1.0.tgz","fileCount":103,"integrity":"sha512-WG0L9VjE66R5VRBdExiPCrlcavh2IfTozasKcCjvbU/bqZnQNMAFyQgnb3rYOMUcXd3bseod45S7reYyhlfpyQ==","signatures":[{"sig":"MEUCIDMSiuwd2cGkRiJaFaQxOGktHXzzZIFfLDAC1c30OgGQAiEA3c6FnYnZqUpEMAlSGEx0bdgygoj/vC+oUeJR18MjZE8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":243225},"type":"module","engines":{"node":">=20.11.0"},"gitHead":"8fc32b86165b69407a57832f5b2f7fd0188b7457","scripts":{"dev":"tsx src/cli.ts","test":"vitest run","build":"tsc","start":"node dist/cli.js"},"_npmUser":{"name":"dujaunpaul","email":"dujaunjpaul@gmail.com"},"repository":{"url":"git+https://github.com/Dujaun-Paul/QASS.git","type":"git"},"_npmVersion":"11.6.2","description":"QA + Security Scanner for vibe-coded applications. Your AI writes code. QASS catches what it got wrong.","directories":{},"_nodeVersion":"25.2.1","dependencies":{"yaml":"^2.7.0","chalk":"^5.4.1","commander":"^13.1.0","minimatch":"^10.0.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.3","vitest":"^4.0.18","typescript":"^5.7.3","@types/node":"^22.13.4"},"peerDependencies":{"vitest":">=1.0.0","playwright":">=1.40.0"},"peerDependenciesMeta":{"vitest":{"optional":true},"playwright":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/qass_0.1.0_1771881314854_0.9710334833664622","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@dujaunpaul/qass","version":"0.1.1","description":"QA + Security Scanner for vibe-coded applications. Your AI writes code. QASS catches what it got wrong.","type":"module","bin":{"qass":"dist/cli.js"},"scripts":{"dev":"tsx src/cli.ts","build":"tsc","start":"node dist/cli.js","test":"vitest run"},"keywords":["qa","security","scanner","testing","vibe-coding","ai","cursor","windsurf","copilot","playwright"],"license":"SEE LICENSE IN LICENSE","repository":{"type":"git","url":"git+https://github.com/Dujaun-Paul/QASS.git"},"homepage":"https://github.com/Dujaun-Paul/QASS","bugs":{"url":"https://github.com/Dujaun-Paul/QASS/issues"},"engines":{"node":">=20.11.0"},"dependencies":{"chalk":"^5.4.1","commander":"^13.1.0","minimatch":"^10.0.1","yaml":"^2.7.0"},"devDependencies":{"@types/node":"^22.13.4","tsx":"^4.19.3","typescript":"^5.7.3","vitest":"^4.0.18"},"peerDependencies":{"playwright":">=1.40.0","vitest":">=1.0.0"},"peerDependenciesMeta":{"playwright":{"optional":true},"vitest":{"optional":true}},"gitHead":"8fc32b86165b69407a57832f5b2f7fd0188b7457","_id":"@dujaunpaul/qass@0.1.1","_nodeVersion":"25.2.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-KTe1qma+PhFRSH7AIBg7U61ua4Ow5nC5c5RvQJDEvEAZcYcuH6BdOjb9tvXsfHyGhxNbrpGH1e6PRkSDFcy4yQ==","shasum":"d7eb952c7fa673adc0ae21d7c9d6c87d4a700b0a","tarball":"https://registry.npmjs.org/@dujaunpaul/qass/-/qass-0.1.1.tgz","fileCount":103,"unpackedSize":243225,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICzs5ezgClYv85Xvcb7HL1CsVlEgVYIbq8hdLbihrtP3AiB+62l96b4UM5VRhzmalxRMwDie1QvMg+JS/ZfIrO6kCQ=="}]},"_npmUser":{"name":"dujaunpaul","email":"dujaunjpaul@gmail.com"},"directories":{},"maintainers":[{"name":"dujaunpaul","email":"dujaunjpaul@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/qass_0.1.1_1771881669992_0.30235201869260075"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-23T21:15:14.722Z","modified":"2026-02-23T21:21:10.249Z","0.1.0":"2026-02-23T21:15:15.007Z","0.1.1":"2026-02-23T21:21:10.128Z"},"bugs":{"url":"https://github.com/Dujaun-Paul/QASS/issues"},"license":"SEE LICENSE IN LICENSE","homepage":"https://github.com/Dujaun-Paul/QASS","keywords":["qa","security","scanner","testing","vibe-coding","ai","cursor","windsurf","copilot","playwright"],"repository":{"type":"git","url":"git+https://github.com/Dujaun-Paul/QASS.git"},"description":"QA + Security Scanner for vibe-coded applications. Your AI writes code. QASS catches what it got wrong.","maintainers":[{"name":"dujaunpaul","email":"dujaunjpaul@gmail.com"}],"readme":"# QASS\r\n\r\n**QA + Security Scanner for vibe-coded apps.**\r\n\r\nYour AI writes code. QASS catches the security holes, broken flows, and silent failures it left behind — before your users do. Works with Cursor, Windsurf, Copilot, and any AI editor.\r\n\r\n## Install\r\n\r\n```bash\r\nnpm install -g qass\r\n```\r\n\r\nOr run without installing:\r\n\r\n```bash\r\nnpx qass scan --project .\r\n```\r\n\r\n## Quick Start\r\n\r\n```bash\r\n# Initialize config in your project\r\nqass init --project .\r\n\r\n# Run a full security scan\r\nqass scan --project . --full\r\n\r\n# Run tests based on your latest git changes\r\nqass test --project . --diff HEAD\r\n```\r\n\r\n## What It Catches\r\n\r\n### Free\r\n\r\n- **7 static security rules** — missing auth middleware, SQL/NoSQL injection, hardcoded secrets, XSS vectors, CORS misconfiguration, rate limiting gaps, dependency CVEs\r\n- **Basic smoke crawl** — page load verification, console error detection\r\n- **Endpoint discovery** — auto-detects Express routes\r\n- **Git diff analysis** — only scans what changed\r\n- **AI-readable reports** — structured for your AI editor to read and fix\r\n\r\n### Pro\r\n\r\n- **Full smoke crawl** — clicks every button, fills every form, catches silent failures\r\n- **Visual regression** — pixel-diff screenshots against baselines\r\n- **Flow testing** — multi-step user journeys defined in YAML\r\n- **API testing** — auth, plan gating, response validation with Supabase support\r\n- **Dynamic security probing** — tests live endpoints for error disclosure, missing headers\r\n\r\n## How It Works With AI Editors\r\n\r\nQASS generates a rule file that tells your AI editor to run tests after every code change:\r\n\r\n```bash\r\n# Generate a Cursor Rule\r\nqass cursor-rule --project .\r\n\r\n# Creates .cursor/rules/qass.mdc\r\n```\r\n\r\nThe rule instructs your AI to:\r\n\r\n1. Run `qass test` after making changes\r\n2. Read the report at `.qass/results/latest.md`\r\n3. Fix every finding (each has exact file, line, and fix instructions)\r\n4. Re-run until clean\r\n5. Only then tell you it's done\r\n\r\nThis works with any AI editor that can run terminal commands — Cursor, Windsurf, Copilot, Bolt, Lovable.\r\n\r\n## Configuration\r\n\r\nQASS uses a `.qass/config.yaml` file in your project root:\r\n\r\n```yaml\r\nproject:\r\n  name: my-app\r\n\r\nservices:\r\n  api:\r\n    framework: express\r\n    entry: src/server.ts\r\n    port: 3001\r\n  frontend:\r\n    framework: nextjs\r\n    port: 3000\r\n\r\nsecurity:\r\n  static_rules:\r\n    - auth-middleware\r\n    - input-sanitization\r\n    - secrets-scan\r\n    - xss-vectors\r\n    - config-audit\r\n    - rate-limit-audit\r\n    - dep-audit\r\n  severity_threshold: LOW\r\n\r\npaths:\r\n  api_routes: \"src/**/*.routes.ts\"\r\n  middleware: \"src/middleware/**\"\r\n  frontend_pages: \"app/**/page.tsx\"\r\n  components: \"components/**/*.tsx\"\r\n```\r\n\r\nRun `qass init` to generate a default config.\r\n\r\n## CLI Commands\r\n\r\n| Command | Description |\r\n|---------|-------------|\r\n| `qass init` | Initialize `.qass/config.yaml` in your project |\r\n| `qass scan` | Run security scan only |\r\n| `qass test` | Run full test suite (security + API + E2E + unit) |\r\n| `qass discover` | List discovered endpoints, pages, and accounts |\r\n| `qass cursor-rule` | Generate AI editor rule file |\r\n| `qass activate <key>` | Activate a Pro/Team license |\r\n| `qass status` | Show current license and plan info |\r\n\r\n## Reports\r\n\r\nQASS generates reports in two formats:\r\n\r\n- **`.qass/results/latest.json`** — machine-readable, for programmatic use\r\n- **`.qass/results/latest.md`** — human/AI-readable, with fix instructions\r\n\r\nEach finding includes:\r\n\r\n```markdown\r\n#### MEDIUM: input-sanitization — routes/contacts.ts:6\r\n**Issue**: Unsanitized user input passed to .filter()\r\n**Fix**: Use a sanitization function: const q = sanitize(req.query.q);\r\n```\r\n\r\n## Requirements\r\n\r\n- Node.js >= 20.11.0\r\n- Git (for diff analysis)\r\n- Playwright (optional, for E2E testing): `npm i -D playwright`\r\n- Vitest (optional, for unit test generation): `npm i -D vitest`\r\n\r\n## License\r\n\r\nProprietary. See [LICENSE](./LICENSE) for details.\r\n\r\nFree tier available. Pro and Team require a license key — see [qass.dev](https://qass.dev) for pricing.\r\n","readmeFilename":"README.md"}