by openqodex
Open source AI code review for Claude Code and Codex, before you push. Scanners (SAST, secrets, dependencies, lint) on the lines you changed, then a separate reviewer process that checks every scanner finding and is given every changed line. No other API key.
# Add to your Claude Code skills
git clone https://github.com/openqodex/openqodexSee how openqodex compares with popular alternatives.
openqodex is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by openqodex. Open source AI code review for Claude Code and Codex, before you push. Scanners (SAST, secrets, dependencies, lint) on the lines you changed, then a separate reviewer process that checks every scanner finding and is given every changed line. No other API key. It has 220 GitHub stars.
openqodex's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/openqodex/openqodex" and add it to your Claude Code skills directory (see the Installation section above).
openqodex is primarily written in TypeScript. It is open-source under openqodex on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh openqodex against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
OpenQodex is open source AI code review for Claude Code and Codex. It runs before you push, from your coding agent or your terminal. One command, openqodex review, works out your change: the commits not yet pushed plus everything uncommitted. It runs the scanners that fit the changed files and keeps only findings on the lines you changed. Then it starts its own reviewer, a separate Claude Code or Codex process that reads a frozen copy of the change. The reviewer checks every scanner finding and is given every changed line. OpenQodex checks its answer with scripts and prints one report. It needs Claude Code or Codex installed and logged in, and no other key, account or server.
For humans, in your terminal:
npx openqodex init
init finds Claude Code, Cursor, Codex CLI and Cline on your machine. It prints every file it will write and asks once. Then it reviews your change, or asks what to review when there is none. After that, say to your agent "review my change with openqodex", or run openqodex review yourself.
For agents:
npx skills add openqodex/openqodex
Or paste this prompt into your agent:
Install the OpenQodex skill with `npx skills add openqodex/openqodex`.
Then review my current change with openqodex and tell me the verdict and the findings.
OpenQodex needs Node 22 or newer and git. It runs on macOS and Linux. On Windows, use WSL.
Four commands: init, review, update and trust. The commands hooks and agents call are listed in docs/plumbing.md.
openqodex review runs the whole review in one command: a frozen copy of the change, the scanners, the code graph, a reviewer process OpenQodex starts, script checks of its answer, and one report in the terminal and in report.md, report.json and report.sarif.openqodex review --all reviews the whole repository. openqodex review <branch> and openqodex review '#42' review a branch or a pull request that is not your current work. OpenQodex fetches it, checks it out in a temporary folder and reviews what it added since it left its base.claude -p) or Codex (codex exec). auto picks the agent you run the command from, then Claude Code, then Codex; --reviewer or reviewer: in ~/.openqodex/config.yaml picks one.~/.codex/AGENTS.md, and its event stream does not show every command, so the report says its reads were not recorded. docs/internal-reviewer-drivers.md gives the tests.# nosec, and a changed scanner settings file are shown, since the scanner then stays silent: the reviewer checks each one, and a scan counts it as a minor finding.openqodex trust..openqodex/config.yaml sets review.block_on_severity.openqodex scan) without one. A pre-commit hook that runs the scanners only; it is not a review.npx openqodex demo builds a small repo with planted bugs and scans it.review prints "Full review unavailable", says what is missing, saves the unchecked scanner findings to a file it names, and names the command with which the agent you are in reviews the change itself (review --agent). That report says which agent reviewed.cursor-agent has no way to limit its tools to reading or to skip your rules and settings.openqodex review runs inside Codex's own sandbox: a second Codex does not start there. review then prints "Full review unavailable" and the review --agent command.Scanners download on first use into ~/.openqodex/tools/. Only the scanners your change needs download. The table below gives each download size.
Installed scanners take more disk than their downloads. The eight scanners the demo needs take about 700 MB of disk on an Apple Silicon Mac. semgrep with its Python takes about 440 MB of that.
A scanner install that takes longer than 45 seconds keeps going in the background. The report lists that scanner as installing. The scanner joins the next run. To install every scanner up front, run npx openqodex doctor --install.
One measured first run: an Apple Silicon Mac, an empty tool folder, a line of 2 MB per second. The first openqodex demo printed its report in under a minute. That report held the scanners that had finished installing and listed the rest as installing. The next scan included all eight scanners. Your times depend on your line.
OpenQodex does not install language runtimes. brakeman and rubocop need Ruby 2.7 or newer. golangci-lint needs Go. Without them, the report lists those scanners as not installed, with the reason.
| Scanner | Version | Runs when the change holds | Needs | Download (Apple Silicon, Linux x64) |
|---|---|---|---|---|
| semgrep | 1.94.0 | any file | Python 3.11, downloaded through uv | about 86 MB with bandit, measured on Apple Silicon |
| gitleaks | 8.21.2 | any file | nothing | 2.9 MB, 3.0 MB |
| bandit | 1.9.4 | .py, .pyi |
the same Python as semgrep | included with semgrep |
| ruff | 0.8.4 | .py, .pyi |
nothing | 9.9 MB, 11.2 MB |
| oxlint | 1.71.0 | .js, .jsx, .ts, .tsx, .mjs, .cjs, .mts, .cts |
npm, which ships with Node | 7.3 MB, 8.2 MB |
| osv-scanner | 1.9.2 | a lockfile, such as package-lock.json or go.sum |
network access to osv.dev | 31.8 MB, 32.1 MB |
| actionlint | 1.7.7 | .github/workflows/*.yml |
nothing | 2.0 MB, 2.1 MB |
| hadolint | 2.15.1 | a Dockerfile | nothing | 102.6 MB, 55.7 MB |
| shellcheck | 0.10.0 | .sh, .bash |
xz to unpack |
7.2 MB, 2.4 MB |
| golangci-lint | 2.12.2 | .go |
Go | 14.4 MB, 15.0 MB |
| brakeman | 6.2.1 | a Ruby or Rails file, in a repo with a Gemfile and an app/ folder |
Ruby 2.7 or newer; see its licence below | from RubyGems, not measured |
| rubocop | 1.69.2 | .rb, .rake, .gemspec, Gemfile, Rakefile |
Ruby 2.7 or newer | from RubyGems, not measured |
| sqllint | built in | .sql |
nothing, it runs inside OpenQodex | none |
docs/scanners.md lists every file each scanner reads and what each one sends.
brakeman's licence is the Brakeman Public Use License, which is not an open source licence. OpenQodex does not bundle brakeman. It downloads brakeman at run time onto your machine. scanners.disable: [brakeman] switches it off.
Add a scanner by its GitHub link in your repo's .openqodex/config.yaml:
scanners:
custom:
- source: https://github.com/aquasecurity/trivy
run: trivy config --format sarif --output {report} {target}
A custom scanner is a command that runs on your machine. It never runs until you approve it:
npx openqodex trust
trust picks the release asset for your machine and downloads it. It shows the version, the asset, its sha256 and the run line, then asks yes or no. An edited entry needs a new approval. docs/custom-scanners.md explains each step.