OpenQodex Pre-Push Code Review
One command that scans your uncommitted and unpushed changes with the right security, secret, dependency and lint scanners, then has an independent AI reviewer verify every finding before you push.
Security & ReviewIntermediate★ 244⑂ 11AI score 9/10Last updated: Oct 7, 2026
What it does
- Runs
npx openqodex reviewto freeze your current change — unpushed commits, uncommitted edits and untracked files — into a single review target. - Picks and runs only the deterministic scanners that match the changed file types (gitleaks, semgrep, bandit, hadolint, shellcheck, actionlint, osv-scanner and more) and keeps findings on changed lines.
- Spawns a separate reviewer process (Claude Code or Codex) with no memory of your session; it validates each scanner finding, reads every changed line, and answers in a fixed shape that scripts then verify.
- Writes
report.md,report.jsonandreport.sarifunder.openqodex/reviews/, and defines exactly how the agent should react to verdicts (passed/blocked) and exit codes 0/1/2. - Can review a branch, a PR number (
#42) or a PR link by checking it out into a temp folder — with hard rules never to run or edit someone else's code.
Who it's for
- Developers who want secrets and obvious security flaws caught locally, before anything hits the remote.
- Small teams and solo devs without a dedicated reviewer.
- Teams trying to fail fast locally instead of burning CI minutes.
- Security/platform engineers who want SARIF output for existing tooling.
Example uses
- Guarded push — ask "review my changes before pushing"; the agent runs
npx -y openqodex@0.8.1 review, and on exit code 1 (blocked) it refuses to push and shows the findings verbatim. - Pull request review —
npx -y openqodex@0.8.1 review '#42'fetches the PR and reviews only what it added since its base branch. - Sandboxed agent — if the report says "Full review unavailable", run
npx -y openqodex@0.8.1 doctor --installin your own terminal to pre-download scanners, or use--offlineto skip the two network-dependent scanners.
· · · Install guide · · ·
Try it now, no install
Paste this into Claude to use the skill without installing anything.
Read the instructions in this file and follow them to help me: https://raw.githubusercontent.com/openqodex/openqodex/HEAD/plugins/claude-code/skills/openqodex/SKILL.md What I want: (describe your task here)
If Claude can't open the link, open it yourself and paste the contents instead.
↓ If it works for you, download the ZIP below and install it. Then it runs on its own — no pasting each time.
Install in the Claude app (no terminal)
- Download the ZIP with the button below.
- In Claude, open Settings → Capabilities and turn on 'Code execution and file creation'. (one time)
- Go to Customize → Skills → + → 'Upload a skill' and upload the ZIP.
Install in Claude Code
Let Claude do it — paste this into Claude Code
Install the skill I found on Claude Skill Mart. Copy the plugins/claude-code/skills/openqodex folder from the GitHub repo openqodex/openqodex into my ~/.claude/skills/openqodex/. When it's done, tell me in one line what this skill can do.
Install with a command instead
git clone https://github.com/openqodex/openqodex.git /tmp/openqodex && mkdir -p ~/.claude/skills && cp -r /tmp/openqodex/plugins/claude-code/skills/openqodex ~/.claude/skills/openqodex⚠ This is a third-party skill. Check the source repository before installing.
- Confirm prerequisites: Node.js (18+ recommended) and git — check with
node -vandgit --version. - Make sure you are logged into Claude Code or Codex; the reviewer uses that login, so no extra API key or account is needed.
- Clone the repository:
git clone https://github.com/openqodex/openqodex.git /tmp/openqodex - Install the skill:
mkdir -p ~/.claude/skills && cp -r /tmp/openqodex/plugins/claude-code/skills/openqodex ~/.claude/skills/openqodex - Recommended: pre-download the scanners with
npx -y openqodex@0.8.1 doctor --install(essential if your agent runs in a network-restricted sandbox). - Restart Claude Code, open a git repository, and say "review my changes before I push".
- Optional: commit a
.openqodex/config.yamlwithblock_on_severityso the team gets hard blocks; without config OpenQodex only warns. Reviews take 1–3 minutes, so allow a long timeout or run it in the background.
View source on GitHub ↗License: Apache-2.0