OpenQodex Pre-Push Code Review
One command that runs the right security, secret, dependency and lint scanners on your uncommitted/unpushed changes, then has an independent AI reviewer verify every finding before you push.
What it does
npx openqodex reviewreviews unpushed commits plus everything uncommitted, including untracked files — or the whole repo with--all.- Picks only the scanners that match the changed files: gitleaks (secrets), semgrep, bandit, hadolint, shellcheck, actionlint, osv-scanner (dependency CVEs) and more.
- Rather than dumping scanner noise, it spawns a separate Claude Code/Codex reviewer process that reads a frozen copy of the change, checks every scanner finding, sees every changed line, and answers in a fixed shape that is validated by scripts.
- Outputs a short receipt (verdict + one line per finding) plus
report.html,report.md,report.jsonandreport.sarifunder.openqodex/reviews/. - Ships strict agent rules: never edit code during review, fix only what the developer names, never push on a
blockedverdict, never setOPENQODEX_SKIP, and clear handling of exit codes 0/1/2.
Who it's for
- Developers who want secrets and obvious vulnerabilities caught before
git push. - Teams using AI agents to write code who don't want the same agent grading its own homework.
- Small teams that want an automated gate before opening a PR (
block_on_severitymakes it blocking).
Example uses
- Pre-push gate: "review my changes before pushing" → receipt appears → "fix 1 and 3" →
findings 1,3prints the full detail → fix → re-review. - Reviewing someone else's PR:
npx -y openqodex@0.10.0 review '#42'checks the PR out in a temp folder and reviews only what it added over its base — never running its tests or builds. - Sandboxed agents: if the agent's sandbox blocks downloads, the developer runs
npx -y openqodex@0.10.0 doctor --installonce in their own terminal to cache scanners in~/.openqodex/tools/.
Prerequisites: Node.js (npx) and a logged-in Claude Code or Codex session. brakeman/rubocop need Ruby, golangci-lint needs Go — OpenQodex won't install language runtimes. semgrep fetches rule packs and osv-scanner sends dependency names/versions to osv.dev; use
--offlineto skip both.
· · · Install guide · · ·
Try it now, no install
Paste this into Claude to use the skill without installing anything.
Read the instructions in this file and follow them to help me: https://raw.githubusercontent.com/openqodex/openqodex/HEAD/plugins/codex/skills/openqodex/SKILL.md What I want: (describe your task here)
If Claude can't open the link, open it yourself and paste the contents instead.
↓ If it works for you, download the ZIP below and install it. Then it runs on its own — no pasting each time.
Install in the Claude app (no terminal)
- Download the ZIP with the button below.
- In Claude, open Settings → Capabilities and turn on 'Code execution and file creation'. (one time)
- Go to Customize → Skills → + → 'Upload a skill' and upload the ZIP.
Install in Claude Code
Let Claude do it — paste this into Claude Code
Install the skill I found on Claude Skill Mart. Copy the plugins/codex/skills/openqodex folder from the GitHub repo openqodex/openqodex into my ~/.claude/skills/openqodex-openqodex/. When it's done, tell me in one line what this skill can do.
Install with a command instead
git clone https://github.com/openqodex/openqodex.git /tmp/openqodex && mkdir -p ~/.claude/skills && cp -r /tmp/openqodex/plugins/codex/skills/openqodex ~/.claude/skills/openqodex⚠ This is a third-party skill. Check the source repository before installing.
- Clone the repository:
git clone https://github.com/openqodex/openqodex.git /tmp/openqodex - Copy the skill into your Claude Code skills folder:
mkdir -p ~/.claude/skills cp -r /tmp/openqodex/plugins/codex/skills/openqodex ~/.claude/skills/openqodex - Make sure Node.js 18+ is available:
node -vandnpx -v. - Restart Claude Code and open the repository you want to review.
- Run the one-time setup from the repo root (also installs the push hook):
The first run downloads scanners and can take up to ten minutes.npx -y openqodex@0.10.0 init --yes --agent claude-code - From then on, say "review my changes before I push" in Claude Code, or run
npx -y openqodex@0.10.0 reviewyourself. - On restricted networks, pre-install tools with
npx -y openqodex@0.10.0 doctor --installand add--offlineto review runs.