Claude Skill MartBrowse skillsQuick linesLearn by videoTerminal guideWhat is a Skill?
← Back to list

OpenQodex Pre-Push Code Review

One command that runs the right security, secret, dependency and lint scanners on your uncommitted/unpushed changes, then has an independent AI reviewer verify every finding before you push.

Security & ReviewIntermediate★ 422⑂ 28AI score 9/10Last updated: Oct 8, 2026

What it does

  • npx openqodex review reviews unpushed commits plus everything uncommitted, including untracked files — or the whole repo with --all.
  • Picks only the scanners that match the changed files: gitleaks (secrets), semgrep, bandit, hadolint, shellcheck, actionlint, osv-scanner (dependency CVEs) and more.
  • Rather than dumping scanner noise, it spawns a separate Claude Code/Codex reviewer process that reads a frozen copy of the change, checks every scanner finding, sees every changed line, and answers in a fixed shape that is validated by scripts.
  • Outputs a short receipt (verdict + one line per finding) plus report.html, report.md, report.json and report.sarif under .openqodex/reviews/.
  • Ships strict agent rules: never edit code during review, fix only what the developer names, never push on a blocked verdict, never set OPENQODEX_SKIP, and clear handling of exit codes 0/1/2.

Who it's for

  • Developers who want secrets and obvious vulnerabilities caught before git push.
  • Teams using AI agents to write code who don't want the same agent grading its own homework.
  • Small teams that want an automated gate before opening a PR (block_on_severity makes it blocking).

Example uses

  1. Pre-push gate: "review my changes before pushing" → receipt appears → "fix 1 and 3" → findings 1,3 prints the full detail → fix → re-review.
  2. Reviewing someone else's PR: npx -y openqodex@0.10.0 review '#42' checks the PR out in a temp folder and reviews only what it added over its base — never running its tests or builds.
  3. Sandboxed agents: if the agent's sandbox blocks downloads, the developer runs npx -y openqodex@0.10.0 doctor --install once in their own terminal to cache scanners in ~/.openqodex/tools/.

Prerequisites: Node.js (npx) and a logged-in Claude Code or Codex session. brakeman/rubocop need Ruby, golangci-lint needs Go — OpenQodex won't install language runtimes. semgrep fetches rule packs and osv-scanner sends dependency names/versions to osv.dev; use --offline to skip both.

· · · Install guide · · ·

Try it now, no install

Paste this into Claude to use the skill without installing anything.

Read the instructions in this file and follow them to help me:
https://raw.githubusercontent.com/openqodex/openqodex/HEAD/plugins/codex/skills/openqodex/SKILL.md

What I want: (describe your task here)

If Claude can't open the link, open it yourself and paste the contents instead.

↓ If it works for you, download the ZIP below and install it. Then it runs on its own — no pasting each time.

Install in the Claude app (no terminal)
  1. Download the ZIP with the button below.
  2. In Claude, open Settings → Capabilities and turn on 'Code execution and file creation'. (one time)
  3. Go to Customize → Skills → + → 'Upload a skill' and upload the ZIP.
↓ Download ZIP
Install in Claude Code

Let Claude do it — paste this into Claude Code

Install the skill I found on Claude Skill Mart.
Copy the plugins/codex/skills/openqodex folder from the GitHub repo openqodex/openqodex into my ~/.claude/skills/openqodex-openqodex/.
When it's done, tell me in one line what this skill can do.

Install with a command instead

git clone https://github.com/openqodex/openqodex.git /tmp/openqodex && mkdir -p ~/.claude/skills && cp -r /tmp/openqodex/plugins/codex/skills/openqodex ~/.claude/skills/openqodex

⚠ This is a third-party skill. Check the source repository before installing.

  1. Clone the repository:
    git clone https://github.com/openqodex/openqodex.git /tmp/openqodex
    
  2. Copy the skill into your Claude Code skills folder:
    mkdir -p ~/.claude/skills
    cp -r /tmp/openqodex/plugins/codex/skills/openqodex ~/.claude/skills/openqodex
    
  3. Make sure Node.js 18+ is available: node -v and npx -v.
  4. Restart Claude Code and open the repository you want to review.
  5. Run the one-time setup from the repo root (also installs the push hook):
    npx -y openqodex@0.10.0 init --yes --agent claude-code
    
    The first run downloads scanners and can take up to ten minutes.
  6. From then on, say "review my changes before I push" in Claude Code, or run npx -y openqodex@0.10.0 review yourself.
  7. On restricted networks, pre-install tools with npx -y openqodex@0.10.0 doctor --install and add --offline to review runs.
View source on GitHub ↗License: Apache-2.0