Openqodex
openqodex/openqodex
Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.
Graph-evidence AI code review (codexqa-code-reviewer) for ANY language repo using ONLY the CodexQA CLI symbol graph (call chains, classes, methods, configs, blast radius, test edges), then an…
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add openqa-cn/codexqa --skill codexqa-code-reviewer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openqa-cn/codexqa codexqa-code-reviewer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codexqa-code-reviewer .claude/skills/codexqa-code-reviewer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codexqa-code-reviewer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-reviewer into .claude/skills/codexqa-code-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-reviewer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-reviewerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openqa-cn/codexqa --skill codexqa-code-reviewer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openqa-cn/codexqa codexqa-code-reviewer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/codexqa-code-reviewer .agents/skills/codexqa-code-reviewer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codexqa-code-reviewer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-reviewer into .agents/skills/codexqa-code-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-reviewer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openqa-cn/codexqa --skill codexqa-code-reviewer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openqa-cn/codexqa codexqa-code-reviewer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/codexqa-code-reviewer .cursor/skills/codexqa-code-reviewer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codexqa-code-reviewer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-reviewer into .cursor/skills/codexqa-code-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-reviewer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openqa-cn/codexqa.git --path skills/codexqa-code-reviewer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openqa-cn/codexqa --skill codexqa-code-reviewer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openqa-cn/codexqa codexqa-code-reviewer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/codexqa-code-reviewer .gemini/skills/codexqa-code-reviewer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codexqa-code-reviewer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-reviewer into .gemini/skills/codexqa-code-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-reviewer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openqa-cn/codexqa codexqa-code-reviewerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openqa-cn/codexqa --skill codexqa-code-reviewer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/codexqa-code-reviewer .github/skills/codexqa-code-reviewer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codexqa-code-reviewer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-reviewer into .github/skills/codexqa-code-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-reviewer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openqa-cn/codexqa --skill codexqa-code-reviewer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openqa-cn/codexqa codexqa-code-reviewer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqa-cn/codexqa.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/codexqa-code-reviewer .opencode/skills/codexqa-code-reviewer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codexqa-code-reviewer" agent skill from https://github.com/openqa-cn/codexqa/tree/main/skills/codexqa-code-reviewer into .opencode/skills/codexqa-code-reviewer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codexqa-code-reviewer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codexqa-code-reviewerGraph-evidence AI code review (codexqa-code-reviewer) for ANY language repo using ONLY the CodexQA CLI symbol graph (call chains, classes, methods, configs, blast radius, test edges), then an…
Codexqa Code Reviewer is an agent skill from openqa-cn/codexqa. Graph-evidence AI code review (codexqa-code-reviewer) for ANY language repo using ONLY the CodexQA CLI symbol graph (call chains, classes, methods, configs, blast radius, test edges), then an order-16 Agent LLM judgment pass by the host agent's embedded model with deterministic dedupe/merge against heuristic findings. Use when the user asks for codexqa-code-reviewer (former name ai-code-reviewer), code review, PR review, 代码评审, impact analysis, 影响面, regression scope, test gaps, full-repo health review, 全仓评审…
Its SKILL.md is about 7.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 181 other files, including scripts, reference files and assets (for example `.meta.json`, `HOW_IT_WORKS.md` and `HOW_IT_WORKS.zh-CN.md`). Compatibility notes: Requires Node.js = 18, bash 3.2+, jq, Python 3.10+ (via scripts/acr-python), and the codexqa CLI for every language. Resolve it with the Preflight gate…
It sits in Development, covering Code review and Static analysis and SAST. It works with Git. The repository describes itself as: codexqa: 11 local-first Agent Skills for Cursor, Claude Code, Codex & OpenClaw — change impact analysis, AI code review, defect scan, testcase generation, browser replay & RCA. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 7839542. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
npmgopython3npxbrewasdfFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires Node.js >= 18, bash 3.2+, jq, Python 3.10+ (via `scripts/acr-python`), and the `codexqa` CLI for every language. Resolve it with the Preflight gate (`codexqa_cli_path` after sourcing `scripts/lib/codexqa-preflight.sh`), not with `command -v` on the default PATH. Install only when that probe prints nothing. Collect / validate / render / merge-llm-findings need no external LLM API; review prose and the order-16 semantic pass use the host agent's embedded model. Data lands under `<repo>/.codexqa-review/<run-id>/`.
From compatibility in the SKILL.md frontmatter.
Codexqa Code Reviewer loads about 7.2k tokens when it runs, and up to ~53k if it reads all its reference files. Until then it costs about 229 tokens; SKILL.md has 2,738 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
bin directory comes from `prefix` in `~/.npmrc`, `$npm_config_prefix`, and `npm prefix -g`, and that directory is often`, eslint) come from the `prefix` in `~/.npmrc`, `$npm_config_prefix`, and `npm prefix -g` (`<prefix>/bin` on Unix; theAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from openqa-cn/codexqa at commit 7839542, republished under its Apache-2.0 licence (© openqa-cn). 2,738 words, ~7,220 tokens.
.claude/skills/codexqa-code-reviewer/SKILL.md (or your agent's skills folder). This skill also uses 178 other files; get the full folder from GitHub.Graph-first code review via CodexQA CLI only. Collect a JSON evidence pack, then reason from those artifacts. Applies to every language / polyglot monorepo.
CLI: {baseDir}/scripts/collect-pr-evidence.sh (and full-repo / adhoc variants).
Runtime pack: <repo>/.codexqa-review/<run-id>/ → review-conclusion.json +
REVIEW-REPORT.html.
Install: Prefer npx skills add openqa-cn/codexqa --skill codexqa-code-reviewer.
Do not copy into a skills library manually until the user names the install target.
README.md / README.zh-CN.md / HOW_IT_WORKS.md / KNOWN_LIMITATIONS.md
(and their .zh-CN twins) are human-facing. Do not load them at runtime.
| Need | Skill |
|---|---|
Graph-evidence pack → bilingual HTML CR (REVIEW-REPORT.html) | this skill (codexqa-code-reviewer) |
SAST + Agent LLM Detection → report_scan.* | codexqa-defect-analyzer |
| Symbol-graph change impact, callers, test gaps | codexqa-code-analyzer |
| Exception RCA from stacks/logs on top of CLI analysis | codexqa-rootcause-analyzer |
| Dependency | Why |
|---|---|
codexqa (Node ≥ 18) | Sole primary analysis backend. Resolve it with the Preflight gate below, not with command -v on the default PATH. npm i -g @openqa-cn/codexqa only when that probe prints nothing. |
jq | Evidence JSON / HTML render |
bash 3.2+ | Collect / validate / render scripts (macOS OK) |
Python 3.10+ (scripts/acr-python) | Local derive-* helpers / validate-skill gate |
| Semgrep, Bandit, gosec, gitleaks, osv-scanner, ruff, eslint | Deterministic SAST. If any binary is missing, install it before collect (scripts/lib/install-sast-tools.sh) |
Local skill gate (Eval substitute when skill-up is missing):
./scripts/validate-skill.shRun this once in the current shell before any later step. Collect, SAST install, index, validate, review, merge, and render stay blocked until codexqa_cli_path has actually executed here and its stdout is known. Intending to preflight later does not open those steps. A second probe is needed only after an install that can change PATH.
A bare command -v codexqa or which codexqa is not this gate. The CLI is an npm global. Its bin directory comes from prefix in ~/.npmrc, $npm_config_prefix, and npm prefix -g, and that directory is often missing from the default PATH. A failed lookup means this shell has not been probed, not that the CLI is absent. Installing from that failure reinstalls a CLI that is already there.
source scripts/lib/codexqa-preflight.sh
codexqa_cli_path
command -v jq >/dev/null
codexqa --versionKeep source and codexqa_cli_path in this shell. $(codexqa_cli_path) drops the PATH update. Do not hardcode the prefix.
npm i -g. Record the path and the version. If the user asked for the latest release, compare that version with npm view @openqa-cn/codexqa version only after this probe, and upgrade only when they differ. Source the preflight again after an upgrade.npm i -g @openqa-cn/codexqa (Node ≥ 18). Source the preflight again. If codexqa_cli_path is still empty, stop with missing_gate: missing_codexqa_engine.jq missing stops the same way. Do not switch the engine to grep or a language-native SAST.Task progress:
- [ ] 1. Preflight gate in this shell (source + codexqa_cli_path). Steps 1b–6 stay blocked until this has run once.
- [ ] 1a+1b. After the path is printed, run resolve-pr-checkout.sh and install-sast-tools.sh in parallel. Do not git fetch or git clone before resolve returns. SAST install stays mandatory.
- [ ] 2. Collect. Stdout is the primary language, the pack path, and validate-evidence. Traces stay in commands.log. status=ok ends the incremental-index question; do not open the collector or commands.log.
- [ ] 3. From 31-model-brief.json, jq only still_open, open_suspects, test_oracle_open, chain_dimensions, and output. Do not print methods. still_open is one row per shape. chain_dimensions.chains is every CodexQA call chain; judge each chain once against its rules. Do not restate look_for, do_not_report, or closed_lines. Do not open rule-construction or review-conclusion.json.
- [ ] 4. If those three lists are empty, render immediately. Do not read methods, judgment-work, 29, or the repository. If any list is non-empty, judge each shape once and read only its hosts. A different shape is a separate finding. Do not compare it with a closed line to decide they are one defect.
- [ ] 5. Render writes the sealed review-conclusion.json. Summarize from that file. Do not reclassify a sealed card by opening the repository.# Step 1 — required before every command below. See Preflight gate.
source scripts/lib/codexqa-preflight.sh
codexqa_cli_path
# Steps 1a and 1b run in parallel after codexqa_cli_path has printed a path.
# 1a fetches at most one URL. An empty HTTP reply gets one HTTP/1.1 downgrade, then stop.
./scripts/resolve-pr-checkout.sh --pr <url-or-owner/repo#N> --search-root <workspace>
# status=local means do not fetch. Use the printed repo and diff_base.
./scripts/lib/install-sast-tools.sh
# PR / diff (default). derive-sast.sh runs the installer again before the scan.
./scripts/collect-pr-evidence.sh --repo /path/to/repo --diff-base origin/main
# Full-repo (optional)
./scripts/collect-fullrepo-evidence.sh --repo /path/to/repo
# Adhoc / single-file (no PR diff-base)
./scripts/collect-adhoc-evidence.sh --file /path/to/Foo.java
# After review reasoning:
./scripts/render-review-html.sh --dir <OUT_DIR>Default OUT_DIR: <repo>/.codexqa-review/<run-id>/ with runtime manifest.json
(+ 09-language-profile.json). templates/evidence-manifest.json is schema-only —
never written by collectors.
codexqa after the Preflight gate, which builds PATH. Never vendor / unzip / import @openqa-cn/codexqa. A default-PATH miss is not a missing CLI.confidence: UNKNOWN. Never fake green from test/ paths.REPO) + reviewable change (--diff-base). Else status: blocked.derive-sast.sh may run Semgrep,
Bandit, gosec, gitleaks, osv-scanner, ruff, and eslint as a secondary
deterministic pass (23-sast-signals.json). Missing/invalid pack →
missing_gate: missing_codexqa_engine (or specific gate).09-language-profile.json / manifest.primary_language /
review_language_focus before findings; apply
references/review-dimensions.md
(references/language-profile.md).
Override with --primary-lang only when detection is wrong. Label uncertainty for
reflection / dynamic dispatch / cross-language FFI — do not leave CodexQA.| Mode | When | Script |
|---|---|---|
| PR/diff (default) | Branch/PR vs base | scripts/collect-pr-evidence.sh |
| Full-repo (optional) | Health / architecture / hotspots | scripts/collect-fullrepo-evidence.sh |
| Adhoc (single-file) | Upload one/few files without PR | scripts/collect-adhoc-evidence.sh |
Full-repo deliverables: hotspot modules (ranked by edges-in, not from_count), layering drift (入口 → 应用 → 领域 → 存储),
entry concentration, hardening backlog P0/P1/P2. Never invent PR change_status.
No product scorecard / 产品评测打分.
Adhoc: bootstraps a mini git repo when --repo is omitted so CodexQA index gates pass. An empty root commit is the diff base, then build-review-digest.py writes 26–31 while the source is still on disk. Validate with --mode adhoc. Judgment reads 31-model-brief.json once. 29 stays for seal.
| Capability | Pack evidence |
|---|---|
| Change localization | 03-change-groups / 05-changed-symbols / diffs/*.diff.json |
| PR review digest | 26-review-digest.json (commits behind/ahead, three-dot file classes vs two-dot drift, deduped disposition: report lines). The judgment pass reads 31-model-brief.json instead. |
| Model brief | 31-model-brief.json (the only file the judgment pass opens: closed shapes, candidate hits, still-open shapes, oracle flags, and method source). Short callees used by a kept method are included. An empty open_suspects[].source with source_ref points at methods[].source for that method, or at judgment-work/ when source_ref.where is judgment-work. |
| Judgment packet | 29-judgment-packet.json stays for seal. A review of at most 2000 pending lines, including one file of about 800 lines, does not create judgment-work/. Scripted suspects are closed in judgment-seed.json before that pass. Question fan-out starts only when the source left for the model exceeds 2000 lines. That question fan-out writes at most four judgment-work/group-*.json files, each holding only methods that own a suspect, a business rule, or a lock-order pair. One-line getters stay out. magic_number and rate_literal are seeded as conventions in judgment-seed.json and are not re-judged. Report rows are closed by seal. Group findings are a union. Past that, whole methods pack into chunks of about 800 lines, at most four concurrent judgment-work/group-*.json files. A method is cut only when it is longer than the chunk. Each chunk carries field lines and the lock-order summary. Rule text stays once in shared.json. Extra agents on the same change are security, correctness, and quality passes over the full change, not line windows, and the packet does not emit them by default. A suspect with slice_ref points at the method slice and does not repeat the source. identical_to_base matches the base tip and is not a defect. A csv/markdown/txt keyword hit does not force T0. Confirmed magic numbers seal as conventions, not P1. 30-conclusion-skeleton.json is sealed into the conclusion at render. |
| Design fit | 10-design-fit-signals.json (path + package/import layers, import_cross_layer, dead_nested_symbols confirmed via empty edges-in; full: imports/ + on-disk fallback) |
| Complexity | 11-complexity-signals.json (method LOC / decisions / nesting / YAGNI hints) |
| Dependencies | 12-dependency-signals.json (manifest/lock SNAPSHOT, lock drift, license clues, local audit) |
| Privacy | 13-privacy-signals.json (PII fields, log exposure, retention gaps, consent/transfer clues) |
| Resilience | 14-resilience-signals.json (timeout, retry, swallow, partial fail, idempotency/compensation) — signal hits → findings hard gate |
| Change / rollout | 15-rollout-signals.json (migration, dual-write, flags, compat window, breaking announce, rollback) |
| Observability | 16-observability-signals.json (catch without log/metric/trace) |
| Contract | 17-contract-signals.json (breaking hints, XSS/HTML sinks, public-sig volume) |
| Maintainability | 18-maintainability-signals.json (TODO/FIXME, magic numbers, long files) |
| Performance | 21-performance-signals.json (hot path, N+1, unbounded allocation) |
| Agent LLM judgment | 22-llm-judgment.json (host-agent semantic CR + dedupe merge vs heuristic findings) |
| Deterministic SAST | 23-sast-signals.json (per hit disposition: report / drop / suspect; class policy allow / suppress_obvious / dedupe_loci) |
| Annotation callbacks | 19-annotation-edges.json (Spring/Resilience4j synthetic callers when edges-in empty) |
| Risk tier (blast-radius triage) | 20-risk-tier.json (T0–T3 from paths + tags + sensitive + rollout surfaces; auth/pay/migration/IaC → T0) |
| Blast radius | impact/*/edges-in.json / reach-in.json (PR + full-repo top hotspots) |
| Entry / flow | 07-tags.json + impact/*/paths/ |
| Test gaps | tested_count + tests-reach.json (not test directory / test path names) |
| Sensitive paths | 06-sensitive-hits.json + callers |
| Hot-but-thin | 08-hot-but-thin.json |
| Full-repo architecture | stats / summary / imports/ + Design fit signals |
| Primary language | 09-language-profile.json + manifest stamps |
This step is the Preflight gate. In a shell where codexqa_cli_path has not yet been executed, stop. Do not start 1b, collect, index, or review from a command -v miss.
source scripts/lib/codexqa-preflight.sh
codexqa_cli_path
command -v jq >/dev/null
codexqa --versionSAST install is step 1b and starts only after that probe has printed a path (or an install from empty stdout has been probed again):
./scripts/lib/install-sast-tools.shPer-tool commands (the installer runs these only when that binary is missing):
| Tool | Install command |
|---|---|
| semgrep | python3 -m pip install --user --break-system-packages 'semgrep>=1.80' |
| bandit | python3 -m pip install --user --break-system-packages bandit |
| ruff | python3 -m pip install --user --break-system-packages ruff |
| eslint | npm install -g eslint |
| gitleaks | go install github.com/gitleaks/gitleaks/v8@latest |
| gosec | go install github.com/securego/gosec/v2/cmd/gosec@latest |
| osv-scanner | go install github.com/google/osv-scanner/cmd/osv-scanner@latest |
codexqa-preflight.sh, install-sast-tools.sh, and derive-sast.sh all source scripts/lib/sast-tool-path.sh and call sast_refresh_path. That is the only PATH policy. It prepends a directory when the directory contains the CodexQA CLI, a SAST binary, or the runtime that installs it. Do not hardcode install prefixes. codexqa_cli_path prints the resolved CLI. npm bins (codexqa, eslint) come from the prefix in ~/.npmrc, $npm_config_prefix, and npm prefix -g (<prefix>/bin on Unix; the prefix directory itself on Windows, where the file is eslint.cmd). pip bins (semgrep, bandit, ruff) come from each Python's sysconfig scripts path (bin on Unix, Scripts on Windows). Go bins (gitleaks, gosec, osv-scanner) come from $GOBIN, $GOPATH, and go env (Windows lists split on ;); if go is not on PATH it is found with brew --prefix, asdf where, or a depth-capped search for go or go.exe, then go env supplies the bin dir. Lookup also accepts .exe, .cmd, and .bat. Node shims come from $NVM_DIR, $VOLTA_HOME, $FNM_DIR, and $ASDF_DATA_DIR. A gitleaks / gosec / osv-scanner file that fails --version is moved aside so a truncated download is not treated as installed. The GitHub release download runs only when no go binary runs, or go install still leaves that tool missing.
Do not set CODEXQA_SAST_SKIP_INSTALL=1 on a real review.
PR: REPO + DIFF_BASE. Full-repo: REPO only. Prefer absolute repo paths.
Blocked until the Preflight gate has run once in this shell. Collectors append command traces to commands.log and print the primary language, the pack path, and validate-evidence status. Shared helpers: scripts/lib/codexqa-preflight.sh.
Options: --full, --github-pr owner/repo#N, --primary-lang <Lang>, --skip-index, --skip-validate, --out DIR.
A changed --diff-base misses the index cache and forces --full. An incremental index that parses 0 files while the three-dot diff or the GitHub PR file list is non-empty is re-run with --full.
PR collect writes 26-review-digest.json after the signal files. Judgment reads that digest for commits behind/ahead, file-class counts, report rows, and dimension cards. Full path lists stay in 26-review-digest-detail.json. Do not recompute the split with git or open every signal file for the dimension verdict. Residual reading opens each 24-coverage-ledger.json read_groups entry once and still writes one closure row per pending symbol. Non-source files are not residual symbols. Byte-identical copies are scanned once; findings keep every path. Files whose bytes differ are both scanned.
./scripts/validate-evidence.sh --dir <OUT_DIR> --mode pr # or --mode fullFails: missing CodexQA provenance; empty change-groups; all change_status=default;
lang_stats present but primary_language null. Legacy packs may WARN and still pass.
stubs≥20 (numeric or {total:N}) → cap edge/reach findings at UNKNOWN; do not treat from_count as real fan-in — prefer edges-in callers.
31-model-brief.json is absent, read prompts/pr-diff-review.md or
prompts/full-repo-review.md. When it exists, do not open those prompts.manifest.engine is codexqa (or legacy codexqa in commands). Else blocked.manifest.json + 09-language-profile.json.diffs/, impact/<id>/, paths/, then tags / hot-but-thin / sensitive.disposition: report are filed from 23-sast-signals.json.
drop is discarded. Only suspects[] go to the SAST suspect channel.
allow records a scanner gap and does not rescan that class. CodexQA
stays the primary engine.31-model-brief.json exists, jq still_open, open_suspects, test_oracle_open, and output only. Findings in judgment.json are already copied from candidate_hits. Do not rewrite title, risk, fix, line, or severity. If those three lists are empty, do not add a finding, do not read methods or judgment-work, and render. If a list is non-empty, judge each shape once and read only its hosts. Do not restate look_for, do_not_report, or closed_lines. Do not open rule-construction or review-conclusion.json. A different shape is a separate finding. Copy preset under oracle, judge only questions, and leave a preset key unchanged. boundary_missed stays false unless preset is true. title, risk, and fix are Chinese; leave the English fields empty. An id already in suspect_hits is closed. A failed render names the sentence to edit. Do not grep seal or validate scripts for fields. Do not walk 24, regroup closed rows, or open templates, examples, dimension docs, or seal-conclusion.py. When 31 is absent, follow prompts/llm-judgment-pass.md.
On that legacy path, SAST suspects, business logic, and semantic candidates are separate prompts. The residual
read visits every pending symbol in 24-coverage-ledger.json; scanner hits do not dequeue it.
The host embedded model reviews those packets, then scripts/lib/merge-llm-findings.py
dedupes p0/p1/p2 against heuristic findings (22-llm-judgment.json).review-conclusion.json is already in the pack. Do not replace it../scripts/render-review-html.sh --dir <OUT_DIR> → REVIEW-REPORT.html
and review-comments.json (same defect id, no score).
Render runs scripts/lib/seal-conclusion.py before
scripts/lib/validate-conclusion.py. The seal fills report-row cards,
span_hash, test_gaps, rule shapes, default oracle skips, and unconfirmed
per-line skips from the pack. The model writes judgment.json only.
The gate still refuses HTML when any check fails after that fill:disposition: report row is the primary line of a finding,
or an also_lines entry with same_fix: true. A line number written only in
prose does not close the row. One finding cannot close two rule_id,
pattern_class, or kind values. Magic numbers, long files, and stale imports close
in conventions, not in P0/P1/P2. A sentence that says another card covers
a defect must name a line that a finding lists.test_oracle_inventory row has oracle.unsafe_pass,
oracle.boundary_missed, and oracle.branch_uncovered, plus that row's
extra questions. Skip is legal only when every flag is false.tested_count == 0 are in test_gaps.symbols or
waived_symbols inside review-conclusion.json. The HTML report does not
render that table. A static initializer, a type or constructor, a get/set/is
accessor, or a private helper goes to waived_symbols. A rule whose look-for has several shapes lists
every shape; the first hit does not close the rest.Cover: 页头四块(能否合入、最高严重级别、行为缺陷数与证据行数、必测三条路径)、一张卡一个失败场景、规范项(不计缺陷)、回归必测清单、敏感路径。有问题的维度和调用链默认折叠,排在发现项之后。ok/none 维度不进报告。seal-conclusion.py 在渲染前用信号文件补上结论里空着的维度(风险分档、架构契合、复杂度、依赖、韧性、隐私、变更发布、性能、模型语义评审),所以判定稿不写维度长文时,HTML 仍会展示有信号的维度。
不渲染: 测试缺口表、建议修复顺序、残留风险与假设、独立影响面示意。test_gaps 仍写入 review-conclusion.json 供闭合校验,不进 HTML。
render-review-html.sh 会过滤干净维度;仍须在 review-conclusion.json 写全评估结果与
dimensions_covered。Final findings must already be dedupe-merged (no duplicate
heuristic + LLM cards for the same defect).
High-severity findings cite: symbol id/file/lines, callers or entry path,
tested_count / tests-reach, confidence (high|medium|low|UNKNOWN).
Human-facing prose (dimension hotspots, finding risk/evidence, summary) must
explain risks in plain language — see references/review-dimensions.md
Reader prose.
Card voice (scanner cards in scripts/lib/seal-conclusion.py, model cards in
prompts/llm-judgment-pass.md):
title: SARIF shortDescription,规则名,例如 SQL 注入。不写规则编号,不写 这一行不是…。risk: Semgrep / SARIF message。在第 N 行检测到 \代码`。接一条影响。不写不会/不是/而不是`。fix: SARIF fix / Sonar recommendation。将第 N 行 \代码` 改为:接安全写法。不写不用/不要/而不是`。call_chain: 谁会走到这一行. No recorded caller stays 未记录调用方, not 没有入边 and not a dead function. Do not add that the index is thin, that stubs capped confidence at UNKNOWN, or that real edges may be missing.manifest.index_quality. Do not put them in REVIEW-REPORT.html or in the user-facing summary.既有代码.Bilingual HTML: Write primary prose in Chinese (summary, intent, scope,
dimension risk/yagni/evidence, finding title/risk/evidence/fix,
call_chain.title, regression/test-gap notes, sensitive). On judgment.json
findings, leave title_en, risk_en, and fix_en empty. seal-conclusion.py
copies the Chinese text into those English fields at render. The HTML
toolbar switches data-zh/data-en; a hand-written English card is not required
for delivery.
### Code Review Blocked
- status: blocked
- missing_gate: missing_codexqa_engine | missing_code_identity | missing_reviewable_change | ...
- supplied: ...
- required: ...
- next_commands: ...Do not emit P0/P1/P2 or merge advice when blocked.
End-to-end walkthrough: examples/pr-review-walkthrough.md
scripts/validate-skill.sh + evals/eval.yamlscripts/audit-plan-coverage.sh → examples/plan-coverage-audit.mdtest/” / test directory names with tests edges
(tested_count > 0). Path names do not prove coverage.references/rule-construction.md.codexqa wiki / chat unless the user asks (LLM cost).@branch on repo_id; do not guess.command -v codexqa is not a missing CLI. The npm prefix is often off the default PATH. Run the Preflight gate once before install, collect, or review.© openqa-cn, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 178 other files (scripts, references, assets) in skills/codexqa-code-reviewer of openqa-cn/codexqa.
Open the folder on GitHubat commit 7839542
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in openqa-cn/codexqa, which our catalogue first saw on October 7, 2026.
Codexqa Code Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codexqa Code Reviewer this skillopenqa-cn/codexqa | 152 | 1 repos | ~7.2k | Automated safety check: Warn | Apache-2.0 | |
| Openqodexopenqodex/openqodex | 303 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Trailmark Graph Evolutiontrailofbits/skills | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Understand Diff AnalysisEgonex-AI/Understand-Anything | 86k | 1 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Open Code Review CLIalibaba/open-code-review | 44k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 |
openqodex/openqodex
Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
Egonex-AI/Understand-Anything
Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
modem-dev/hunk
Interacts with live Hunk diff review sessions via CLI. Inspects review focus, navigates files, hunks, and exact lines, reloads session contents, adds inline…
openqa-cn/codexqa
Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page.
openqa-cn/codexqa
Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.
openqa-cn/codexqa
Auto-routes a user request to the matching codexqa skill, then ensures that skill is on disk and follows its SKILL.md.
openqa-cn/codexqa
Constructs test data against real backends and writes it back into test cases as executable preconditions.
openqa-cn/codexqa
Generates test plans and test cases from local requirements for APP, Web, and server.
openqa-cn/codexqa
Constructs catalog products (standard or limited), catalog orders, and account-credit enrollment, including product-then-credit scenes.
Works with
Categories
Graph-evidence AI code review (codexqa-code-reviewer) for ANY language repo using ONLY the CodexQA CLI symbol graph (call chains, classes, methods, configs, blast radius, test edges), then an…. Codexqa Code Reviewer is an agent skill from openqa-cn/codexqa. Graph-evidence AI code review (codexqa-code-reviewer) for ANY language repo using ONLY the CodexQA CLI symbol graph (call chains, classes, methods, configs, blast radius, test edges), then an order-16 Agent LLM judgment pass by the host agent's embedded model with deterministic dedupe/merge against heuristic findings.
Codexqa Code Reviewer fits situations like: the user asks for codexqa-code-reviewer (former name ai-code-reviewer); impact analysis; regression scope; full-repo health review.
Run `npx skills add openqa-cn/codexqa --skill codexqa-code-reviewer -a claude-code`. Or copy the skill folder (skills/codexqa-code-reviewer in openqa-cn/codexqa) into .claude/skills/codexqa-code-reviewer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openqa-cn/codexqa --skill codexqa-code-reviewer -a codex`. Or copy the skill folder (skills/codexqa-code-reviewer in openqa-cn/codexqa) into .agents/skills/codexqa-code-reviewer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openqa-cn/codexqa --skill codexqa-code-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codexqa-code-reviewer, .gemini/skills/codexqa-code-reviewer, .github/skills/codexqa-code-reviewer and .opencode/skills/codexqa-code-reviewer in your project.
Going by SKILL.md and its folder, Codexqa Code Reviewer needs JavaScript for the scripts in its folder and the command-line tools its instructions call (npm, go, python3, npx, brew and asdf). Our summary lists: Python 3; Node.js. Compatibility (from SKILL.md): Requires Node.js >= 18, bash 3.2+, jq, Python 3.10+ (via `scripts/acr-python`), and the `codexqa` CLI for every language. Resolve it with the Preflight gate (`codexqa_cli_path` after sourcing `scripts/lib/codexqa-preflight.sh`), not with `command -v` on the default PATH. Install only when that probe prints nothing. Collect / validate / render / merge-llm-findings need no external LLM API; review prose and the order-16 semantic pass use the host agent's embedded model. Data lands under `<repo>/.codexqa-review/<run-id>/`. .
SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Codexqa Code Reviewer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.2k tokens (SKILL.md is roughly 29k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 46k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Codexqa Code Reviewer: Openqodex (openqodex/openqodex, 303 stars), Trailmark Graph Evolution (trailofbits/skills, 7.4k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openqa-cn (a GitHub organization) maintains it in openqa-cn/codexqa, which has 152 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 3, 2026.
Source: openqa-cn/codexqa on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.