run-qc
Execute QC_<date>.md and write FINDINGS_<date>.md.
A badly written item is a finding about the plan, not an edit of yours. How the run is organised — one pass or many, delegated or not, foreground or background — is the user's to compose.
Before starting
Prove the boundary. Assert the plan's out-of-bounds section holds — the credential is absent, not merely forbidden. Some items have you driving a part of the product that carries its own credentials and tools; a prompt on your side does not reach those, and a missing connection does. If the boundary cannot be asserted, do not start.
Prove the instruments. A blind instrument returns empty, and empty looks like approval. For every claim of absence in the plan, plant the signal first and confirm the reader sees it. A control that fails marks its whole class of item unreachable up front rather than stopping the QC.
Use what is here. Whatever this environment offers to drive a browser, query logs, run commands and drive the product itself. A missing capability makes its items NOT EXERCISED, declared up front rather than discovered mid-run.