OpenQodex Pre-Push Code Review
One command that runs the security, secret, dependency and lint scanners matching your changed files, then has an independent AI reviewer verify every finding before you push.
Security & ReviewIntermediate★ 422⑂ 28AI score 9/10Last updated: Oct 8, 2026
What it does
- Runs
npx openqodex reviewto review unpushed commits plus every uncommitted change, untracked files included. - Picks only the scanners that fit the changed files: gitleaks, semgrep, bandit, hadolint, shellcheck, actionlint, osv-scanner and more.
- Starts a separate reviewer process (Claude Code or Codex) that sees every changed line and re-checks every scanner finding, so raw scanner noise is never presented as a review.
- Prints a short receipt (verdict + one line per finding) and saves full reports as
report.html,report.md,report.jsonandreport.sarifunder.openqodex/reviews/. - Defines exact agent behaviour per exit code: 0 pass, 1 blocked (do not push), 2 incomplete review.
Who it's for
- Developers who want a last gate against leaked secrets and vulnerabilities before
git push. - Teams that ask coding agents to "review and fix" and want verifiable, non-hallucinated output.
- Small teams or security owners reducing manual PR review load.
- Anyone who prefers using an existing Claude Code / Codex login instead of managing API keys.
Examples
- Before pushing: run the review, read the receipt, then say "fix 2 and 5" — the agent runs
findings 2,5and patches only those. - Reviewing someone else's PR:
npx -y openqodex@0.10.0 review '#42'fetches and checks out the PR in a temp folder and reviews only what it added over its base, never running its code. - After a blocked push: use
findings allfor the full write-up (location, problem, impact, fix, source), patch, then re-run the review for a fresh receipt.
· · · Install guide · · ·
Try it now, no install
Paste this into Claude to use the skill without installing anything.
Read the instructions in this file and follow them to help me: https://raw.githubusercontent.com/openqodex/openqodex/HEAD/skills/openqodex/SKILL.md What I want: (describe your task here)
If Claude can't open the link, open it yourself and paste the contents instead.
↓ If it works for you, download the ZIP below and install it. Then it runs on its own — no pasting each time.
Install in the Claude app (no terminal)
- Download the ZIP with the button below.
- In Claude, open Settings → Capabilities and turn on 'Code execution and file creation'. (one time)
- Go to Customize → Skills → + → 'Upload a skill' and upload the ZIP.
Install in Claude Code
Let Claude do it — paste this into Claude Code
Install the skill I found on Claude Skill Mart. Copy the skills/openqodex folder from the GitHub repo openqodex/openqodex into my ~/.claude/skills/openqodex-openqodex-2/. When it's done, tell me in one line what this skill can do.
Install with a command instead
npx -y openqodex@0.10.0 init --yes --agent claude-code⚠ This is a third-party skill. Check the source repository before installing.
- Make sure Node.js 18+ and git are installed (
node -v). - Be logged into Claude Code or Codex already — no extra API key or account is required.
- Open a terminal in the repository you want reviewed:
cd /path/to/your-repo - Run the installer:
Swapnpx -y openqodex@0.10.0 init --yes --agent claude-codeclaude-codeforcodex,cursororclineif that's your agent. - The first run installs scanners and performs an initial review — allow up to 10 minutes and wait for
First review: finished. - From then on, run
npx -y openqodex@0.10.0 review, or simply ask your agent to "review my changes". - If any scanner shows
not installed, runnpx -y openqodex@0.10.0 doctor --installonce in your own terminal (outside a sandboxed agent). - Optional: in air-gapped or restricted networks, add
--offlineto skip semgrep's rule download and osv-scanner's lookup.
View source on GitHub ↗License: Apache-2.0