Reviewdog
AgentSecOps/SecOpsAgentKit
Automated code review and security linting integration for CI/CD pipelines using reviewdog.
Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.
$ npx skills add openqodex/openqodex --skill openqodex -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openqodex/openqodex openqodex --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openqodex/openqodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/openqodex .claude/skills/openqodex && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "openqodex" agent skill from https://github.com/openqodex/openqodex/tree/main/skills/openqodex into .claude/skills/openqodex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openqodex", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openqodex/openqodex/tree/main/skills/openqodexType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openqodex/openqodex --skill openqodex -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openqodex/openqodex openqodex --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqodex/openqodex.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/openqodex .agents/skills/openqodex && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "openqodex" agent skill from https://github.com/openqodex/openqodex/tree/main/skills/openqodex into .agents/skills/openqodex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openqodex", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openqodex/openqodex --skill openqodex -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openqodex/openqodex openqodex --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqodex/openqodex.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/openqodex .cursor/skills/openqodex && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "openqodex" agent skill from https://github.com/openqodex/openqodex/tree/main/skills/openqodex into .cursor/skills/openqodex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openqodex", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openqodex/openqodex.git --path skills/openqodex--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openqodex/openqodex --skill openqodex -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openqodex/openqodex openqodex --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqodex/openqodex.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/openqodex .gemini/skills/openqodex && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "openqodex" agent skill from https://github.com/openqodex/openqodex/tree/main/skills/openqodex into .gemini/skills/openqodex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openqodex", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openqodex/openqodex openqodexInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openqodex/openqodex --skill openqodex -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openqodex/openqodex.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/openqodex .github/skills/openqodex && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "openqodex" agent skill from https://github.com/openqodex/openqodex/tree/main/skills/openqodex into .github/skills/openqodex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openqodex", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openqodex/openqodex --skill openqodex -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openqodex/openqodex openqodex --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openqodex/openqodex.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/openqodex .opencode/skills/openqodex && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "openqodex" agent skill from https://github.com/openqodex/openqodex/tree/main/skills/openqodex into .opencode/skills/openqodex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openqodex", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
openqodexCode review for the current change, before it is pushed. An agent skill from openqodex/openqodex.
Openqodex is an agent skill from openqodex/openqodex. Code review for the current change, before it is pushed. One command runs the security, secret, dependency and lint scanners that fit the changed files, a separate reviewer that checks every scanner finding and is given every changed line, and prints a short receipt with the path of the full report. Use before every git push, when asked for a code review, a security scan, or to review changes, a diff or a pull request, and when a push was blocked or warned by OpenQodex.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Static analysis and SAST, Linting and formatting and Code review. It works with Git, GitHub Actions and Semgrep. The repository describes itself as: Open source AI code review for Claude Code and Codex, before you push. Scanners (SAST, secrets, dependencies, lint) on the lines you changed, then a separate reviewer process… The licence is Apache-2.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 49527d3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxgitbrewFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Openqodex loads about 2.4k tokens when it runs. Until then it costs about 121 tokens; SKILL.md has 1,474 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openqodex/openqodex at commit 49527d3, republished under its Apache-2.0 licence (© openqodex). 1,474 words, ~2,426 tokens.
.claude/skills/openqodex/SKILL.md (or your agent's skills folder).OpenQodex reviews a change in one command. It takes a frozen copy of the change, runs the deterministic scanners that fit the changed files (gitleaks, semgrep, bandit, hadolint, shellcheck, actionlint, osv-scanner and others), keeps what they report on changed lines, and starts its own reviewer: a separate Claude Code or Codex process that reads only that copy. The reviewer checks every scanner finding, is given every changed line and answers in a fixed shape; OpenQodex checks the answer with scripts and prints one report. No key and no account are needed beyond the developer's Claude Code or Codex login. The code goes to the model that login uses. The reviewer can also search the web and open web pages unless reviewer_web: off is set in ~/.openqodex/config.yaml. Two scanners go online, and neither sends code: semgrep downloads its rule packs from the Semgrep registry on each run, and when the change touches a dependency file, osv-scanner sends the names and versions of the dependencies to osv.dev. --offline skips both scanners.
git push.OpenQodex starts its own reviewer process for every review, with no memory of this session. You do not start a subagent for it and you do not review the change yourself: run the command and show what it prints.
If review says "Full review unavailable" and prints a way to review with the agent you are in, follow it: run the command it names and do what the brief it prints says.
When the file ~/.openqodex/bin/openqodex exists, run it in place of npx -y openqodex@<version> in every command of this skill: it is the copy openqodex init installed. When it does not exist, this skill was installed alone, with no push check: before the first review, run npx -y openqodex@0.10.0 init --yes --agent <host> once from the repository, where <host> is the agent you are (claude-code, codex, cursor or cline). It installs OpenQodex for you, then reviews the change when a reviewer can start, so it can take five minutes: allow it up to ten, or run it in the background and wait for it to exit. When it prints First review: finished, the receipt above that line is the review's: show it as step 3 says, then go on from step 4.
From the repository, run:
npx -y openqodex@0.10.0 reviewIt reviews the change: the commits not yet pushed plus everything uncommitted, untracked files included. To review the whole repository instead, run:
npx -y openqodex@0.10.0 review --allWait for it. A review takes one to three minutes. Many agents stop a command after two minutes, so give it up to ten minutes, or run it in the background and wait until it exits. While the reviewer works, it prints a progress line every 15 seconds on stderr. Do not start it a second time while one runs.
Show the developer the receipt it printed, as printed: the verdict, one line per finding (its number, severity, category, title, file and line) and the absolute path of report.html. Do not reword it, shorten it or add findings of your own. Give them the report.html path: that page shows each changed file with each finding under its line of code.
Ask the developer: "Fix all, or tell me which?" Do not change any code before they answer. If they already told you what to fix, for example "review and fix everything", do that without asking again.
Fix only the findings they name. This prints those findings in full (where, the problem, why it matters, the fix and the source), by their numbers in the receipt:
npx -y openqodex@0.10.0 findings 1,3findings all prints every finding. When the fixes are done, run the review again and show the developer the new receipt.
Act on the exit code:
blocked. Do not push. Show the developer the receipt and ask which findings to fix; push only if they say so after seeing the findings.When the developer asks you to review a branch or a pull request that is not their current work, name it:
npx -y openqodex@0.10.0 review feature/login
npx -y openqodex@0.10.0 review '#42'Quote #42: in a shell # starts a comment. A pull request link works too. OpenQodex fetches the target, checks it out in a temporary folder and reviews what it added since it left its base. This is someone else's code: never run its tests, scripts, builds or services, and never edit it.
openqodex trust without asking the developer first. It approves a custom scanner, which is a command that runs on their machine.OPENQODEX_SKIP. It is the developer's switch, not yours.init refreshes them, tell the developer in one line and give them that init command. Run it only if they ask you to: it rewrites their agent files.blocked, do not push unless the developer says so after seeing the findings.1 create a GitHub issue and 2 ignore, tell the developer in one line what went wrong and give them the two choices. Never choose 1 yourself. If they say 1, run npx -y openqodex@0.10.0 report --send-last from the same folder. Anything else means 2: do nothing..openqodex/reviews/<time>-<id>/ in the repository: report.html to open in a browser (each changed file as a diff, each finding under its line, then coverage, the scanners and the blast radius), report.md to read as text, report.json and report.sarif for tools. The receipt gives the absolute paths of report.html and report.md. .openqodex/latest.json points at the newest review. The reports never show in git status: .openqodex/.gitignore keeps them out. The two other files in that folder, config.yaml and custom-instructions.md, are the team's and are meant to be committed.passed (with or without warnings) or blocked. It is blocked only when the repository's config (.openqodex/config.yaml, or .openqodex.yaml at the root) sets block_on_severity and a finding is at or above it. With no config, OpenQodex warns and never blocks.no matching files: nothing in the change is the kind of file it reads.installing: it is being downloaded for the first time; it is included from the next run. Say so to the developer rather than waiting.not installed: it could not be installed here; the reason says why.needs Ruby or needs Go: brakeman needs Ruby 3.0 or newer, rubocop Ruby 2.7 or newer, golangci-lint needs Go. OpenQodex does not install language runtimes. If the developer wants those scanners, they install Ruby or Go the usual way for their system (for example brew install ruby go on a Mac) and run the review again.untrusted: a custom scanner from the repo's config that the developer has not approved. Tell the developer; approving it is their decision (npx -y openqodex@0.10.0 trust).failed: the scanner ran and broke; the reason has its error. A scanner problem never changes the exit code.Some agents run commands in a sandbox that cannot reach the network or write outside the project. There the first run cannot download the scanners, and the reviewer may not reach its model. Tell the developer to run this once in their own terminal, outside the agent, inside the repository:
npx -y openqodex@0.10.0 doctor --installIt downloads the scanners this repository's files call for into ~/.openqodex/tools/ and prints why for each one; --all-scanners downloads every scanner. If the review still says "Full review unavailable" inside the sandbox, the developer runs npx -y openqodex@0.10.0 review in their own terminal.
npx -y openqodex@0.10.0 guide prints this guide. npx -y openqodex@0.10.0 guide <topic> prints a page of the docs, offline: quickstart, config, scanners, custom-scanners, security, agents, cli.
© openqodex, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/openqodex of openqodex/openqodex.
Open the folder on GitHubat commit 49527d3
Openqodex next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Openqodex this skillopenqodex/openqodex | 470 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| ReviewdogAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3k | Automated safety check: Pass | Custom licence | |
| GitHub Workflowtransilienceai/communitytools | 562 | — | ~812 | Automated safety check: Notes | MIT | |
| Code Review with Beads Tasksmaslennikov-ig/claude-code-orchestrator-kit | 260 | — | ~2k | Automated safety check: Pass | Custom licence | |
| Qv Devops PR Reviewtetherto/qvac | 683 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Reviewsoftspark/ai-toolkit | 179 | — | ~3.1k | Automated safety check: Notes | Apache-2.0 |
AgentSecOps/SecOpsAgentKit
Automated code review and security linting integration for CI/CD pipelines using reviewdog.
transilienceai/communitytools
GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.
maslennikov-ig/claude-code-orchestrator-kit
Reviews staged changes, a branch, a PR or a path for bugs, security gaps and performance issues, then writes an evidence-based report and creates Beads tasks.
tetherto/qvac
PR review for DevOps changes — runs the generic /qv-pr-review flow then layers a structured GitHub Actions security audit (action pinning, permissions, OIDC, secrets handling).
softspark/ai-toolkit
Reviews code for quality, security, correctness. An agent skill from softspark/ai-toolkit.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
Works with
Categories
Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex. Openqodex is an agent skill from openqodex/openqodex. Code review for the current change, before it is pushed.
Openqodex fits situations like: tasks that involve Static analysis and SAST; tasks that involve Linting and formatting; tasks that involve Code review.
Run `npx skills add openqodex/openqodex --skill openqodex -a claude-code`. Or copy the skill folder (skills/openqodex in openqodex/openqodex) into .claude/skills/openqodex in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openqodex/openqodex --skill openqodex -a codex`. Or copy the skill folder (skills/openqodex in openqodex/openqodex) into .agents/skills/openqodex in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openqodex/openqodex --skill openqodex -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openqodex, .gemini/skills/openqodex, .github/skills/openqodex and .opencode/skills/openqodex in your project.
Going by SKILL.md and its folder, Openqodex needs the command-line tools its instructions call (npx, git and brew). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Openqodex is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Openqodex: Reviewdog (AgentSecOps/SecOpsAgentKit, 220 stars), GitHub Workflow (transilienceai/communitytools, 562 stars), Code Review with Beads Tasks (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and Qv Devops PR Review (tetherto/qvac, 683 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openqodex (a GitHub organization) maintains it in openqodex/openqodex, which has 470 GitHub stars. The repository was last updated on October 8, 2026.
Source: openqodex/openqodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.