⏳ This skill is pending AI review.

Scores will appear once the review pipeline completes.

version unknown

openqodex

@openqodex⭐ 562 stars

Code review for the current change, before it is pushed. One command runs the security, secret, dependency and lint scanners that fit the changed files, a separate reviewer that checks every scanner finding and is given every changed line, and prints a short receipt with the path of the full report. Use before every git push, when asked for a code review, a security scan, or to review changes, a diff or a pull request, and when a push was blocked or warned by OpenQodex.

Choose how to use this skill

You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.

1. Native installer

This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.

Do not guess an installer command or replace an existing version without reviewing the diff.

2. Complete package recommended

Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.

No complete ProSkills package is published for this listing yet.

3. Prompt-only

Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.

Need only the instruction file?

Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.

No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.

—/10

// RATINGS

⭐GitHub Stars
⭐⭐⭐⭐ 562 on GitHubGitHub ↗

Popular

🟢ProSkills Score
—
📍

Not yet listed on ClawHub or SkillsMP

// README

OpenQodex

npm version licence CI

OpenQodex is open source AI code review for Claude Code and Codex. It runs before you push, from your coding agent or your terminal. One command, openqodex review, works out your change: the commits not yet pushed plus everything uncommitted. It runs the scanners that fit the changed files and keeps only findings on the lines you changed. Then it starts its own reviewer, a separate Claude Code or Codex process that reads a frozen copy of the change. The reviewer checks every scanner finding and is given every changed line. OpenQodex checks its answer with scripts, writes one report, and prints a short receipt: the verdict, one line per finding and the path of report.html, a local page that shows each finding under its line of code. You choose which findings your agent fixes. It needs Claude Code or Codex installed and logged in, and no other key, account or server.

Install

For humans, in your terminal:

npx openqodex init

init finds Claude Code, Cursor, Codex CLI and Cline on your machine. It prints every file it will write and asks once. Then it names the reviewer it found, or what to fix, and reviews your change, or asks what to review when there is none. After that, say to your agent "review my change with openqodex", or run ~/.openqodex/bin/openqodex review yourself: init prints that full path, since an npx install puts no openqodex on your PATH.

For agents, the same install, run by the agent for itself with no question:

npx -y [email protected] init --yes --agent <host>

<host> is claude-code, codex, cursor or cline. Or paste this prompt into your agent:

Install OpenQodex for yourself with `npx -y [email protected] init --yes --agent <host>`, where <host> is the agent you are: claude-code, codex, cursor or cline. Run it from this repository and allow it up to ten minutes: when a reviewer can start, it ends with a review of my current change.
Then tell me the verdict and the findings, or what its last lines say is missing.

Codex runs commands in a sandbox that by default cannot write outside the project or reach the network: from Codex, run the line in your own terminal instead.

The skill alone, with no push check, launcher or scanner download: npx skills add openqodex/openqodex -g. A later init replaces it with the skill it keeps up to date.

OpenQodex needs Node 22 or newer and git. It runs on macOS and Linux. On Windows, use WSL.

What it does today

Five commands: init, review, update, trust and graph. The commands hooks and agents call are listed in docs/plumbing.md.

  • openqodex review runs the whole review in one command: a frozen copy of the change, the scanners, the code graph, a reviewer process OpenQodex starts, script checks of its answer, and one report in report.html, report.md, report.json and report.sarif.
  • When it ends, the terminal shows a receipt: the verdict, the reviewer's summary, one line per finding (number, severity, category, title, file and line) and the absolute paths of report.html and report.md. --format markdown, json or sarif still prints the whole report.
  • report.html is one file on your disk: each changed file as a diff, each finding under its line, then the coverage, the scanners and the blast radius. It runs no script, loads nothing, escapes every string and redacts the secrets the scanners found.
  • The skill tells your agent to show you the receipt, ask "Fix all, or tell me which?", and fix only the findings you name. openqodex findings 1,3 prints the named findings in full for it.
  • openqodex review --all reviews the whole repository. openqodex review <branch> and openqodex review '#42' review a branch or a pull request that is not your current work. OpenQodex fetches it, checks it out in a temporary folder and reviews what it added since it left its base.
  • The reviewer is Claude Code (claude -p) or Codex (codex exec). auto picks the agent you run the command from, then Claude Code, then Codex; --reviewer or reviewer: in ~/.openqodex/config.yaml picks one.
  • Claude Code starts with read, search and list tools only, inside the copy of the change, with none of your settings, hooks, plugins, memory or instruction files. Its event stream shows every read, so the report lists the files it read.
  • Codex starts in a read-only sandbox that confines reads to the copy of the change and the system folders, with no network for its commands and none of your config, plugins, hooks or the repository's instruction files. It still loads your global ~/.codex/AGENTS.md, and its event stream does not show every command, so the report says its reads were not recorded. docs/internal-reviewer-drivers.md gives the tests.
  • A review is complete only when every stage ran, every scanner finding was raised or dropped with a reason, and every changed line was in front of the reviewer: in the brief, in a later message from OpenQodex, or, for Claude Code, in a file it read. Anything else prints "Review incomplete" with what is missing, and exits 2.
  • A change that only deletes code, such as a removed check, can still carry a finding: the lines next to a deletion count as changed.
  • Twenty-two built-in scanners. Every downloaded scanner is pinned to one version. Each runs only when the change holds a file it reads.
  • A suppression comment the change adds, such as # nosec, and a changed scanner settings file are shown, since the scanner then stays silent: the reviewer checks each one, and a scan counts it as a minor finding.
  • Any scanner by its GitHub link, after you approve it with openqodex trust.
  • A push gate for Claude Code and Codex, and an optional git pre-push hook. Both look for a review of exactly what is pushed; neither scans or reviews by itself. They warn by default and block only when .openqodex/config.yaml sets review.block_on_severity.
  • A GitHub Action that runs the full review on a pull request when the workflow gives it an Anthropic API key, and the scanners only (openqodex scan) without one. A pre-commit hook that runs the scanners only; it is not a review.
  • npx openqodex demo builds a small repo with planted bugs and scans it.
  • openqodex graph callers <symbol> and the other graph questions answer from the code graph, with the evidence for each item and a note when the list may be short. init registers the same questions as an MCP server (openqodex mcp, a tool server your agent starts) with each agent it installs into. docs/graph.md lists the questions.

What it does not do yet

  • The separate reviewer process needs Claude Code or Codex. Without either, review prints "Full review unavailable", says what is missing, saves the unchecked scanner findings to a file it names, and names the command with which the agent you are in reviews the change itself (review --agent). That report says which agent reviewed.
  • No Cursor reviewer. cursor-agent has no way to limit its tools to reading or to skip your rules and settings.
  • Codex cannot be the reviewer when openqodex review runs inside Codex's own sandbox: a second Codex does not start there. review then prints "Full review unavailable" and the review --agent command.

// HOW IT'S BUILT

KEY FILES

plugins/claude-code/skills/openqodex/SKILL.mdREADME.md

// REPO STATS

562 stars