Agent skill

Openqodex

by openqodex in openqodex/openqodex

Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

Apache-2.0Auto-check passedDevelopment

Install Openqodex

skills CLI
$ npx skills add openqodex/openqodex --skill openqodex -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openqodex/openqodex openqodex --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openqodex/openqodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/openqodex .claude/skills/openqodex && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openqodex
GitHub stars
470
Token cost
~2.4k tokens
SKILL.md length
1,474 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

  • Works in 6 steps: From the repository, run → Wait for it. A review takes one to three… → Show the developer the receipt it… → …
  • Tasks that involve Static analysis and SAST
  • SKILL.md covers When to run, Who reviews, Procedure and Reviewing a branch or a pull…, plus 4 more sections
  • Calls npx, git and brew

What it does

Openqodex is an agent skill from openqodex/openqodex. Code review for the current change, before it is pushed. One command runs the security, secret, dependency and lint scanners that fit the changed files, a separate reviewer that checks every scanner finding and is given every changed line, and prints a short receipt with the path of the full report. Use before every git push, when asked for a code review, a security scan, or to review changes, a diff or a pull request, and when a push was blocked or warned by OpenQodex.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Static analysis and SAST, Linting and formatting and Code review. It works with Git, GitHub Actions and Semgrep. The repository describes itself as: Open source AI code review for Claude Code and Codex, before you push. Scanners (SAST, secrets, dependencies, lint) on the lines you changed, then a separate reviewer process… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Static analysis and SAST
  • Tasks that involve Linting and formatting
  • Tasks that involve Code review

Example prompts

  • “/openqodex”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. From the repository, run
  2. Wait for it. A review takes one to three minutes. Many agents stop a command after two minutes, so give it up to ten minutes, or run it in…
  3. Show the developer the receipt it printed, as printed: the verdict, one line per finding (its number, severity, category, title, file and…
  4. Ask the developer: "Fix all, or tell me which?" Do not change any code before they answer. If they already told you what to fix, for…
  5. Fix only the findings they name. This prints those findings in full (where, the problem, why it matters, the fix and the source), by their…
  6. Act on the exit code

What it can do on your machine

Read from SKILL.md and the folder at commit 49527d3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • git
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openqodex loads about 2.4k tokens when it runs. Until then it costs about 121 tokens; SKILL.md has 1,474 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~121
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openqodex/openqodex at commit 49527d3, republished under its Apache-2.0 licence (© openqodex). 1,474 words, ~2,426 tokens.

Download SKILL.mdSave it as .claude/skills/openqodex/SKILL.md (or your agent's skills folder).
name
openqodex
description
Code review for the current change, before it is pushed. One command runs the security, secret, dependency and lint scanners that fit the changed files, a separate reviewer that checks every scanner finding and is given every changed line, and prints a short receipt with the path of the full report. Use before every git push, when asked for a code review, a security scan, or to review changes, a diff or a pull request, and when a push was blocked or warned by OpenQodex.

OpenQodex: review the change before it is pushed

OpenQodex reviews a change in one command. It takes a frozen copy of the change, runs the deterministic scanners that fit the changed files (gitleaks, semgrep, bandit, hadolint, shellcheck, actionlint, osv-scanner and others), keeps what they report on changed lines, and starts its own reviewer: a separate Claude Code or Codex process that reads only that copy. The reviewer checks every scanner finding, is given every changed line and answers in a fixed shape; OpenQodex checks the answer with scripts and prints one report. No key and no account are needed beyond the developer's Claude Code or Codex login. The code goes to the model that login uses. The reviewer can also search the web and open web pages unless reviewer_web: off is set in ~/.openqodex/config.yaml. Two scanners go online, and neither sends code: semgrep downloads its rule packs from the Semgrep registry on each run, and when the change touches a dependency file, osv-scanner sends the names and versions of the dependencies to osv.dev. --offline skips both scanners.

When to run

  • Before any git push.
  • When the developer asks you to review their changes.
  • When a push was blocked or warned by the OpenQodex hook.
  • After fixing findings, to check the change again.

Who reviews

OpenQodex starts its own reviewer process for every review, with no memory of this session. You do not start a subagent for it and you do not review the change yourself: run the command and show what it prints.

If review says "Full review unavailable" and prints a way to review with the agent you are in, follow it: run the command it names and do what the brief it prints says.

Procedure

When the file ~/.openqodex/bin/openqodex exists, run it in place of npx -y openqodex@<version> in every command of this skill: it is the copy openqodex init installed. When it does not exist, this skill was installed alone, with no push check: before the first review, run npx -y openqodex@0.10.0 init --yes --agent <host> once from the repository, where <host> is the agent you are (claude-code, codex, cursor or cline). It installs OpenQodex for you, then reviews the change when a reviewer can start, so it can take five minutes: allow it up to ten, or run it in the background and wait for it to exit. When it prints First review: finished, the receipt above that line is the review's: show it as step 3 says, then go on from step 4.

  1. From the repository, run:

    npx -y openqodex@0.10.0 review

    It reviews the change: the commits not yet pushed plus everything uncommitted, untracked files included. To review the whole repository instead, run:

    npx -y openqodex@0.10.0 review --all
  2. Wait for it. A review takes one to three minutes. Many agents stop a command after two minutes, so give it up to ten minutes, or run it in the background and wait until it exits. While the reviewer works, it prints a progress line every 15 seconds on stderr. Do not start it a second time while one runs.

  3. Show the developer the receipt it printed, as printed: the verdict, one line per finding (its number, severity, category, title, file and line) and the absolute path of report.html. Do not reword it, shorten it or add findings of your own. Give them the report.html path: that page shows each changed file with each finding under its line of code.

  4. Ask the developer: "Fix all, or tell me which?" Do not change any code before they answer. If they already told you what to fix, for example "review and fix everything", do that without asking again.

  5. Fix only the findings they name. This prints those findings in full (where, the problem, why it matters, the fix and the source), by their numbers in the receipt:

    npx -y openqodex@0.10.0 findings 1,3

    findings all prints every finding. When the fixes are done, run the review again and show the developer the new receipt.

  6. Act on the exit code:

    • 0: the review is complete and nothing blocks the push.
    • 1: the review is complete and its verdict is blocked. Do not push. Show the developer the receipt and ask which findings to fix; push only if they say so after seeing the findings.
    • 2: there is no complete review. The output says what is missing (for example "Full review unavailable" when no reviewer could start, or "Review incomplete" with the reasons). Tell the developer exactly that. Never present the scanner output as a review.

Reviewing a branch or a pull request

When the developer asks you to review a branch or a pull request that is not their current work, name it:

npx -y openqodex@0.10.0 review feature/login
npx -y openqodex@0.10.0 review '#42'

Quote #42: in a shell # starts a comment. A pull request link works too. OpenQodex fetches the target, checks it out in a temporary folder and reviews what it added since it left its base. This is someone else's code: never run its tests, scripts, builds or services, and never edit it.

Show full SKILL.md (648 more words)Show less

Rules

  • Never edit code during the review. Review first, show the receipt, then fix only the findings the developer names (steps 3 to 5).
  • Never run openqodex trust without asking the developer first. It approves a custom scanner, which is a command that runs on their machine.
  • Never set OPENQODEX_SKIP. It is the developer's switch, not yours.
  • When OpenQodex prints that files it wrote for your agent are from an older version and that init refreshes them, tell the developer in one line and give them that init command. Run it only if they ask you to: it rewrites their agent files.
  • When the verdict is blocked, do not push unless the developer says so after seeing the findings.
  • When OpenQodex prints "OpenQodex had a problem. Nothing has been sent." with 1 create a GitHub issue and 2 ignore, tell the developer in one line what went wrong and give them the two choices. Never choose 1 yourself. If they say 1, run npx -y openqodex@0.10.0 report --send-last from the same folder. Anything else means 2: do nothing.

Reading the report

  • The report is in .openqodex/reviews/<time>-<id>/ in the repository: report.html to open in a browser (each changed file as a diff, each finding under its line, then coverage, the scanners and the blast radius), report.md to read as text, report.json and report.sarif for tools. The receipt gives the absolute paths of report.html and report.md. .openqodex/latest.json points at the newest review. The reports never show in git status: .openqodex/.gitignore keeps them out. The two other files in that folder, config.yaml and custom-instructions.md, are the team's and are meant to be committed.
  • The verdict is passed (with or without warnings) or blocked. It is blocked only when the repository's config (.openqodex/config.yaml, or .openqodex.yaml at the root) sets block_on_severity and a finding is at or above it. With no config, OpenQodex warns and never blocks.
  • A complete review means every stage ran, every scanner finding was checked and every changed line was put in front of the reviewer; anything not covered is named in the report. It does not mean nothing was missed: no review finds everything.
  • The coverage list says, for each scanner, whether it ran. A scanner that did not run has a one-line reason:
    • no matching files: nothing in the change is the kind of file it reads.
    • installing: it is being downloaded for the first time; it is included from the next run. Say so to the developer rather than waiting.
    • not installed: it could not be installed here; the reason says why.
    • needs Ruby or needs Go: brakeman needs Ruby 3.0 or newer, rubocop Ruby 2.7 or newer, golangci-lint needs Go. OpenQodex does not install language runtimes. If the developer wants those scanners, they install Ruby or Go the usual way for their system (for example brew install ruby go on a Mac) and run the review again.
    • untrusted: a custom scanner from the repo's config that the developer has not approved. Tell the developer; approving it is their decision (npx -y openqodex@0.10.0 trust).
    • failed: the scanner ran and broke; the reason has its error. A scanner problem never changes the exit code.

Inside a sandbox

Some agents run commands in a sandbox that cannot reach the network or write outside the project. There the first run cannot download the scanners, and the reviewer may not reach its model. Tell the developer to run this once in their own terminal, outside the agent, inside the repository:

npx -y openqodex@0.10.0 doctor --install

It downloads the scanners this repository's files call for into ~/.openqodex/tools/ and prints why for each one; --all-scanners downloads every scanner. If the review still says "Full review unavailable" inside the sandbox, the developer runs npx -y openqodex@0.10.0 review in their own terminal.

More

npx -y openqodex@0.10.0 guide prints this guide. npx -y openqodex@0.10.0 guide <topic> prints a page of the docs, offline: quickstart, config, scanners, custom-scanners, security, agents, cli.

© openqodex, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/openqodex of openqodex/openqodex.

Open the folder on GitHubat commit 49527d3

Compare with similar skills

Openqodex next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openqodex compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openqodex this skillopenqodex/openqodex470—~2.4kAutomated safety check: PassApache-2.0
ReviewdogAgentSecOps/SecOpsAgentKit2201 repos~3kAutomated safety check: PassCustom licence
GitHub Workflowtransilienceai/communitytools562—~812Automated safety check: NotesMIT
Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit260—~2kAutomated safety check: PassCustom licence
Qv Devops PR Reviewtetherto/qvac683—~2.5kAutomated safety check: PassApache-2.0
Reviewsoftspark/ai-toolkit179—~3.1kAutomated safety check: NotesApache-2.0

Similar skills

  • Reviewdog

    AgentSecOps/SecOpsAgentKit

    Automated code review and security linting integration for CI/CD pipelines using reviewdog.

    220 GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check passed
  • GitHub Workflow

    transilienceai/communitytools

    GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.

    562 GitHub stars~812 tokensUpdated 2 mo ago
    DevelopmentAuto-check: notes
  • Code Review with Beads Tasks

    maslennikov-ig/claude-code-orchestrator-kit

    Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.

    260 GitHub stars~2k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • Qv Devops PR Review

    tetherto/qvac

    PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).

    683 GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Review

    softspark/ai-toolkit

    Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 2 days ago
    SecurityAuto-check passed

Categories

Questions about Openqodex

What does Openqodex do?

Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex. Openqodex is an agent skill from openqodex/openqodex. Code review for the current change, before it is pushed.

When should I use Openqodex?

Openqodex fits situations like: tasks that involve Static analysis and SAST; tasks that involve Linting and formatting; tasks that involve Code review.

How do I install Openqodex in Claude Code?

Run `npx skills add openqodex/openqodex --skill openqodex -a claude-code`. Or copy the skill folder (skills/openqodex in openqodex/openqodex) into .claude/skills/openqodex in your project. Claude Code loads it when a task matches its description.

How do I install Openqodex in Codex?

Run `npx skills add openqodex/openqodex --skill openqodex -a codex`. Or copy the skill folder (skills/openqodex in openqodex/openqodex) into .agents/skills/openqodex in your project. Codex loads it when a task matches its description.

Can I use Openqodex in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openqodex/openqodex --skill openqodex -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openqodex, .gemini/skills/openqodex, .github/skills/openqodex and .opencode/skills/openqodex in your project.

What does Openqodex need to run?

Going by SKILL.md and its folder, Openqodex needs the command-line tools its instructions call (npx, git and brew). Our summary lists: Node.js.

Does Openqodex access the network?

SKILL.md contains no URLs. Its commands use npx and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Openqodex safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openqodex use?

Openqodex is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openqodex use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Openqodex?

Skills that share tags, products or a category with Openqodex: Reviewdog (AgentSecOps/SecOpsAgentKit, 220 stars), GitHub Workflow (transilienceai/communitytools, 562 stars), Code Review with Beads Tasks (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and Qv Devops PR Review (tetherto/qvac, 683 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openqodex?

openqodex (a GitHub organization) maintains it in openqodex/openqodex, which has 470 GitHub stars. The repository was last updated on October 8, 2026.

Source: openqodex/openqodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.