Agent skill

Codexqa Code Analyzer

by openqa-cn in openqa-cn/codexqa

Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk.

Apache-2.0Auto-check passedSecurity

Install Codexqa Code Analyzer

skills CLI
$ npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openqa-cn/codexqa codexqa-code-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codexqa-code-analyzer .claude/skills/codexqa-code-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codexqa-code-analyzer
GitHub stars
152
Token cost
~1.2k tokens
SKILL.md length
471 words
Files
10 (incl. references, assets)
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk.

  • The user mentions codexqa-code-analyzer
  • SKILL.md covers Documents (load on demand), Scenario routing and Report contract
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Asks to install / run the codexqa CLI (index

What it does

Codexqa Code Analyzer is an agent skill from openqa-cn/codexqa. Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk. Use when the user mentions codexqa-code-analyzer, code-analyzer, codexqa, 符号图, 代码知识图谱, 建索引, 查调用, 影响面, --diff-base, 变更审查, 回归范围, 测试缺口, or asks to install / run the codexqa CLI (index, query). Former skill name: code-analyzer. Not CodexQA evidence-pack HTML review (that is codexqa-code-reviewer), not SAST + Agent LLM Detection code-risk scan reports (that is codexqa-defect-analyzer), and not…

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including reference files and assets (for example `KNOWN_LIMITATIONS.md`, `KNOWN_LIMITATIONS.zh-CN.md` and `README.md`). Compatibility notes: Requires Node.js = 18 and the codexqa CLI (npm i -g @openqa-cn/codexqa) on PATH. Index and query need no LLM. Data lives in ~/.codexqa/.

It sits in Security, covering Static analysis and SAST and Code review. The repository describes itself as: codexqa: 11 local-first Agent Skills for Cursor, Claude Code, Codex & OpenClaw — change impact analysis, AI code review, defect scan, testcase generation, browser replay & RCA. The licence is Apache-2.0.

When your agent uses it

  • The user mentions codexqa-code-analyzer
  • Asks to install / run the codexqa CLI (index

Example prompts

  • “Use the codexqa-code-analyzer skill to query a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry…”
  • “/codexqa-code-analyzer”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Requires Node.js >= 18 and the `codexqa` CLI (`npm i -g @openqa-cn/codexqa`) on PATH. Index and query need no LLM. Data lives in ~/.codexqa/.

What it can do on your machine

Read from SKILL.md and the folder at commit 7839542. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Node.js >= 18 and the `codexqa` CLI (`npm i -g @openqa-cn/codexqa`) on PATH. Index and query need no LLM. Data lives in ~/.codexqa/.

    From compatibility in the SKILL.md frontmatter.

Context cost

Codexqa Code Analyzer loads about 1.2k tokens when it runs, and up to ~11k if it reads all its reference files. Until then it costs about 165 tokens; SKILL.md has 471 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~165
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~11k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openqa-cn/codexqa at commit 7839542, republished under its Apache-2.0 licence (© openqa-cn). 471 words, ~1,167 tokens.

Download SKILL.mdSave it as .claude/skills/codexqa-code-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
codexqa-code-analyzer
description
Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk. Use when the user mentions codexqa-code-analyzer, code-analyzer, codexqa, 符号图, 代码知识图谱, 建索引, 查调用, 影响面, --diff-base, 变更审查, 回归范围, 测试缺口, or asks to install / run the codexqa CLI (index, query). Former skill name: code-analyzer. Not CodexQA evidence-pack HTML review (that is codexqa-code-reviewer), not SAST + Agent LLM Detection code-risk scan reports (that is codexqa-defect-analyzer), and not architecture wiki reports (that is codexqa-code-wiki), and not full exception RCA reports (that is codexqa-rootcause-analyzer).
compatibility
Requires Node.js >= 18 and the `codexqa` CLI (`npm i -g @openqa-cn/codexqa`) on PATH. Index and query need no LLM. Data lives in ~/.codexqa/.
license
Apache-2.0
metadata.author
open-source
metadata.version
1.0.0
metadata.open-standard
agentskills

Code Analyzer

Local symbol graph for quality work: index first, then answer what changed, who is hit, what is untested, and where an error comes from.

There is no codexqa diff or codexqa review. Review a change with:

text
index --diff-base <ref>  →  change-groups  →  symbol-diff  →  callers / tests / entries

Pick the scenario before acting. Do not query or review a diff until an index exists. Do not run full-text search unless the user asked. README.md / README.zh-CN.md are human-facing. Do not load them at runtime.

Documents (load on demand)

Read this file first. Read another file only when the row below applies. Do not preload the whole tree.

FileLoad when
SKILL.md (this file)always: routing, report contract, reject conditions
references/playbook.mdentering a scenario (index health / change / defect / implementation / architecture)
references/diagrams.mdbefore drawing; copy init and classDef verbatim
references/cli.mdCLI missing, PATH, LLM, or maintenance
references/mcp.jsongraph-query tool schema is needed
README.md, README.zh-CN.mdhuman-facing; not needed by the agent

Scenario routing

Open references/playbook.md and jump to the named section.

User is asking…Playbook section
Review a PR / what changed / vs mainReview one change (index health first)
Who is hit / what to regression-testRegression scope under that change section
Any unit tests / coverage gapsTest gaps under that change section
Which HTTP / RPC / MQ path reaches thisEntry risk under that change section
Auth, payments, password, tokenSensitive paths under that change section
Logs, stack, error text, commentsLocate a defect
How does this function work / who calls itUnderstand an implementation
Module ownership / wrong layerArchitecture drift
Results are empty / every change is defaultIndex health / Analysis blockers
Show full SKILL.md (214 more words)Show less

Report contract

Deliver a Mermaid evidence report (graph conclusions + diagrams). Not a product review, and not Archify / interactive HTML. Read references/diagrams.md before drawing. A diagram that misses the quality bar fails the report.

Report body is only these blocks:

  • Must-read groups (by risk)
  • What changed (trust only symbol-diff / file-source vs file-base)
  • Must-test callers / entries (must come from edges / reach / path / tagged)
  • Test gaps (a tests directory is not a tests edge)
  • Sensitive paths (write "none" if there are none)
  • Diagrams: at least one, and it must pass the quality bar

Reject the whole report and rewrite if any of these hold:

  • Written as a generic project review (product intro, use cases, scored pros/cons)
  • Evidence comes from README / a website / guesswork, not this run of summary / imports / source / edges / reach / change-groups / symbol-diff
  • Only names large files or high fan-in; never uses edges / reach to say who is hit
  • Infers "covered" from a tests directory name; never checked tested_count or reach --direction in --edge-kinds tests
  • Mermaid is missing the Claude paper init, the three classDef lines, or a core module that should be risk has no class ... risk
  • Architecture subgraph titles are package names (Renderer / Compiler / Shared) instead of Entry → Application → Domain → Storage
  • Interactive HTML / Archify canvas was generated (this skill does not ask for that)

© openqa-cn, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (references, assets) in skills/codexqa-code-analyzer of openqa-cn/codexqa.

  • SKILL.md
  • KNOWN_LIMITATIONS.md
  • KNOWN_LIMITATIONS.zh-CN.md
  • README.md
  • README.zh-CN.md
  • assets/checkout-change-impact.svg
  • references/cli.md
  • references/diagrams.md
  • references/mcp.json
  • references/playbook.md

Open the folder on GitHubat commit 7839542

Compare with similar skills

Codexqa Code Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codexqa Code Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codexqa Code Analyzer this skillopenqa-cn/codexqa152—~1.2kAutomated safety check: PassApache-2.0
Trailmark Graph Evolutiontrailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.0
LLM Sast ScannerSunWeb3Sec/llm-sast-scanner287—~6.2kAutomated safety check: PassNone
Scan Codemicrosoft/power-platform-skills979—~3.4kAutomated safety check: NotesMIT
ReviewdogAgentSecOps/SecOpsAgentKit2201 repos~3kAutomated safety check: PassCustom licence
Code Review AI AI Reviewaiskillstore/marketplace4307 repos~3.9kAutomated safety check: PassNone

Similar skills

  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • LLM Sast Scanner

    SunWeb3Sec/llm-sast-scanner

    General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

    287 GitHub stars~6.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Scan Code

    microsoft/power-platform-skills

    Official

    Scans a Power Pages site project for security issues in source code and dependencies.

    979 GitHub stars~3.4k tokensUpdated today
    DevelopmentAuto-check: notes
  • Reviewdog

    AgentSecOps/SecOpsAgentKit

    Automated code review and security linting integration for CI/CD pipelines using reviewdog.

    220 GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check passed
  • Code Review AI AI Review

    aiskillstore/marketplace

    You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices.

    430 GitHub starsUsed in 7 repos~3.9k tokens
    DevelopmentAuto-check passed
  • Audit Integrity

    github/awesome-copilot

    Official

    Enforce output quality, evidence verification, and quality gates across security audits.

    40k GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed

More from openqa-cn/codexqa

All 14 skills in this repo
  • Codexqa Code Wiki

    openqa-cn/codexqa

    Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page.

    152 GitHub stars~1.3k tokensUpdated 6 days ago
    Auto-check passed
  • Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.

    152 GitHub stars~2.6k tokensUpdated 6 days ago
    Auto-check passed
  • Constructs test data against real backends and writes it back into test cases as executable preconditions.

    152 GitHub stars~4.8k tokensUpdated 6 days ago
    Auto-check passed
  • Codexqa Skill Router

    openqa-cn/codexqa

    Auto-routes a user request to the matching codexqa skill, then ensures that skill is on disk and follows its SKILL.md.

    152 GitHub stars~2k tokensUpdated 6 days ago
    Auto-check passed
  • Generates test plans and test cases from local requirements for APP, Web, and server.

    152 GitHub stars~3.6k tokensUpdated 6 days ago
    Auto-check passed
  • Catalog

    openqa-cn/codexqa

    Constructs catalog products (standard or limited), catalog orders, and account-credit enrollment, including product-then-credit scenes.

    152 GitHub stars~514 tokensUpdated 6 days ago
    Auto-check passed

Questions about Codexqa Code Analyzer

What does Codexqa Code Analyzer do?

Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk. Codexqa Code Analyzer is an agent skill from openqa-cn/codexqa. Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk.

When should I use Codexqa Code Analyzer?

Codexqa Code Analyzer fits situations like: the user mentions codexqa-code-analyzer; asks to install / run the codexqa CLI (index.

How do I install Codexqa Code Analyzer in Claude Code?

Run `npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a claude-code`. Or copy the skill folder (skills/codexqa-code-analyzer in openqa-cn/codexqa) into .claude/skills/codexqa-code-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Codexqa Code Analyzer in Codex?

Run `npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a codex`. Or copy the skill folder (skills/codexqa-code-analyzer in openqa-cn/codexqa) into .agents/skills/codexqa-code-analyzer in your project. Codex loads it when a task matches its description.

Can I use Codexqa Code Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openqa-cn/codexqa --skill codexqa-code-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codexqa-code-analyzer, .gemini/skills/codexqa-code-analyzer, .github/skills/codexqa-code-analyzer and .opencode/skills/codexqa-code-analyzer in your project.

What does Codexqa Code Analyzer need to run?

SKILL.md names no scripts, command-line tools or credentials: Codexqa Code Analyzer is instructions for the agent only. Our summary lists: Node.js. Compatibility (from SKILL.md): Requires Node.js >= 18 and the `codexqa` CLI (`npm i -g @openqa-cn/codexqa`) on PATH. Index and query need no LLM. Data lives in ~/.codexqa/. .

Does Codexqa Code Analyzer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Codexqa Code Analyzer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codexqa Code Analyzer use?

Codexqa Code Analyzer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codexqa Code Analyzer use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.

What are the alternatives to Codexqa Code Analyzer?

Skills that share tags, products or a category with Codexqa Code Analyzer: Trailmark Graph Evolution (trailofbits/skills, 7.4k stars), LLM Sast Scanner (SunWeb3Sec/llm-sast-scanner, 287 stars), Scan Code (microsoft/power-platform-skills, 979 stars) and Reviewdog (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codexqa Code Analyzer?

openqa-cn (a GitHub organization) maintains it in openqa-cn/codexqa, which has 152 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 3, 2026.

Source: openqa-cn/codexqa on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.