Trailmark Graph Evolution
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk.
$ npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openqa-cn/codexqa codexqa-code-analyzer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codexqa-code-analyzer .claude/skills/codexqa-code-analyzer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codexqa-code-analyzer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-analyzer into .claude/skills/codexqa-code-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-analyzer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-analyzerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openqa-cn/codexqa codexqa-code-analyzer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/codexqa-code-analyzer .agents/skills/codexqa-code-analyzer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codexqa-code-analyzer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-analyzer into .agents/skills/codexqa-code-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-analyzer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openqa-cn/codexqa codexqa-code-analyzer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/codexqa-code-analyzer .cursor/skills/codexqa-code-analyzer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codexqa-code-analyzer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-analyzer into .cursor/skills/codexqa-code-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-analyzer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openqa-cn/codexqa.git --path skills/codexqa-code-analyzer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openqa-cn/codexqa codexqa-code-analyzer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/codexqa-code-analyzer .gemini/skills/codexqa-code-analyzer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codexqa-code-analyzer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-analyzer into .gemini/skills/codexqa-code-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-analyzer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openqa-cn/codexqa codexqa-code-analyzerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/codexqa-code-analyzer .github/skills/codexqa-code-analyzer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codexqa-code-analyzer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-analyzer into .github/skills/codexqa-code-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-analyzer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openqa-cn/codexqa codexqa-code-analyzer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/codexqa-code-analyzer .opencode/skills/codexqa-code-analyzer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codexqa-code-analyzer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-analyzer into .opencode/skills/codexqa-code-analyzer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-analyzer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codexqa-code-analyzerQueries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk.
Codexqa Code Analyzer is an agent skill from openqa-cn/codexqa. Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk. Use when the user mentions codexqa-code-analyzer, code-analyzer, codexqa, 符号图, 代码知识图谱, 建索引, 查调用, 影响面, --diff-base, 变更审查, 回归范围, 测试缺口, or asks to install / run the codexqa CLI (index, query). Former skill name: code-analyzer. Not CodexQA evidence-pack HTML review (that is codexqa-code-reviewer), not SAST + Agent LLM Detection code-risk scan reports (that is codexqa-defect-analyzer), and not…
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including reference files and assets (for example `KNOWN_LIMITATIONS.md`, `KNOWN_LIMITATIONS.zh-CN.md` and `README.md`). Compatibility notes: Requires Node.js = 18 and the codexqa CLI (npm i -g @openqa-cn/codexqa) on PATH. Index and query need no LLM. Data lives in ~/.codexqa/.
It sits in Security, covering Static analysis and SAST and Code review. The repository describes itself as: codexqa: 11 local-first Agent Skills for Cursor, Claude Code, Codex & OpenClaw — change impact analysis, AI code review, defect scan, testcase generation, browser replay & RCA. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 7839542. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires Node.js >= 18 and the `codexqa` CLI (`npm i -g @openqa-cn/codexqa`) on PATH. Index and query need no LLM. Data lives in ~/.codexqa/.
From compatibility in the SKILL.md frontmatter.
Codexqa Code Analyzer loads about 1.2k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 165 tokens; SKILL.md has 471 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openqa-cn/codexqa at commit 7839542, republished under its Apache-2.0 licence (© openqa-cn). 471 words, ~1,167 tokens.
.claude/skills/codexqa-code-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.Local symbol graph for quality work: index first, then answer what changed, who is hit, what is untested, and where an error comes from.
There is no codexqa diff or codexqa review. Review a change with:
index --diff-base <ref> → change-groups → symbol-diff → callers / tests / entriesPick the scenario before acting. Do not query or review a diff until an index exists. Do not run full-text search unless the user asked.
README.md / README.zh-CN.md are human-facing. Do not load them at runtime.
Read this file first. Read another file only when the row below applies. Do not preload the whole tree.
| File | Load when |
|---|---|
SKILL.md (this file) | always: routing, report contract, reject conditions |
| references/playbook.md | entering a scenario (index health / change / defect / implementation / architecture) |
| references/diagrams.md | before drawing; copy init and classDef verbatim |
| references/cli.md | CLI missing, PATH, LLM, or maintenance |
| references/mcp.json | graph-query tool schema is needed |
README.md, README.zh-CN.md | human-facing; not needed by the agent |
Open references/playbook.md and jump to the named section.
| User is asking… | Playbook section |
|---|---|
| Review a PR / what changed / vs main | Review one change (index health first) |
| Who is hit / what to regression-test | Regression scope under that change section |
| Any unit tests / coverage gaps | Test gaps under that change section |
| Which HTTP / RPC / MQ path reaches this | Entry risk under that change section |
| Auth, payments, password, token | Sensitive paths under that change section |
| Logs, stack, error text, comments | Locate a defect |
| How does this function work / who calls it | Understand an implementation |
| Module ownership / wrong layer | Architecture drift |
Results are empty / every change is default | Index health / Analysis blockers |
Deliver a Mermaid evidence report (graph conclusions + diagrams). Not a product review, and not Archify / interactive HTML. Read references/diagrams.md before drawing. A diagram that misses the quality bar fails the report.
Report body is only these blocks:
symbol-diff / file-source vs file-base)edges / reach / path / tagged)tests edge)Reject the whole report and rewrite if any of these hold:
summary / imports / source / edges / reach / change-groups / symbol-diffedges / reach to say who is hittested_count or reach --direction in --edge-kinds testsinit, the three classDef lines, or a core module that should be risk has no class ... risksubgraph titles are package names (Renderer / Compiler / Shared) instead of Entry → Application → Domain → Storage© openqa-cn, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (references, assets) in skills/codexqa-code-analyzer of openqa-cn/codexqa.
Open the folder on GitHubat commit 7839542
Codexqa Code Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codexqa Code Analyzer this skillopenqa-cn/codexqa | 152 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Trailmark Graph Evolutiontrailofbits/skills | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| LLM Sast ScannerSunWeb3Sec/llm-sast-scanner | 287 | — | ~6.2k | Automated safety check: Pass | None | |
| Scan Codemicrosoft/power-platform-skills | 979 | — | ~3.4k | Automated safety check: Notes | MIT | |
| ReviewdogAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3k | Automated safety check: Pass | Custom licence | |
| Code Review AI AI Reviewaiskillstore/marketplace | 430 | 7 repos | ~3.9k | Automated safety check: Pass | None |
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
SunWeb3Sec/llm-sast-scanner
General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.
microsoft/power-platform-skills
Scans a Power Pages site project for security issues in source code and dependencies.
AgentSecOps/SecOpsAgentKit
Automated code review and security linting integration for CI/CD pipelines using reviewdog.
aiskillstore/marketplace
You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices.
github/awesome-copilot
Enforce output quality, evidence verification, and quality gates across security audits.
openqa-cn/codexqa
Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page.
openqa-cn/codexqa
Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.
openqa-cn/codexqa
Constructs test data against real backends and writes it back into test cases as executable preconditions.
openqa-cn/codexqa
Auto-routes a user request to the matching codexqa skill, then ensures that skill is on disk and follows its SKILL.md.
openqa-cn/codexqa
Generates test plans and test cases from local requirements for APP, Web, and server.
openqa-cn/codexqa
Constructs catalog products (standard or limited), catalog orders, and account-credit enrollment, including product-then-credit scenes.
Categories
Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk. Codexqa Code Analyzer is an agent skill from openqa-cn/codexqa. Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk.
Codexqa Code Analyzer fits situations like: the user mentions codexqa-code-analyzer; asks to install / run the codexqa CLI (index.
Run `npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a claude-code`. Or copy the skill folder (skills/codexqa-code-analyzer in openqa-cn/codexqa) into .claude/skills/codexqa-code-analyzer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a codex`. Or copy the skill folder (skills/codexqa-code-analyzer in openqa-cn/codexqa) into .agents/skills/codexqa-code-analyzer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codexqa-code-analyzer, .gemini/skills/codexqa-code-analyzer, .github/skills/codexqa-code-analyzer and .opencode/skills/codexqa-code-analyzer in your project.
SKILL.md names no scripts, command-line tools or credentials: Codexqa Code Analyzer is instructions for the agent only. Our summary lists: Node.js. Compatibility (from SKILL.md): Requires Node.js >= 18 and the `codexqa` CLI (`npm i -g @openqa-cn/codexqa`) on PATH. Index and query need no LLM. Data lives in ~/.codexqa/. .
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Codexqa Code Analyzer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Codexqa Code Analyzer: Trailmark Graph Evolution (trailofbits/skills, 7.4k stars), LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 287 stars), Scan Code (microsoft/power-platform-skills, 979 stars) and Reviewdog (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openqa-cn (a GitHub organization) maintains it in openqa-cn/codexqa, which has 152 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 3, 2026.
Source: openqa-cn/codexqa on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.