Code Inspector for Openclaw

A command-line tool that performs AST-based static analysis on AI-generated Python code to detect bugs, security flaws, and assess production-readiness.

minirr890112-byte
v1.0.0
Jun 18, 2026
0
451
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install code-inspector

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install code-inspector using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Code Inspector?

AI code generators can output code that looks syntactically correct but harbors critical security flaws, logical errors, or serious anti-patterns. The code-inspector tool solves this by scanning your Python files against eight crucial static analysis checkpoints, ranging from hardcoded credentials to mutable defaults. By introducing a structured safety net, developers can leverage LLM agents with confidence.

As part of the Openclaw Skills ecosystem, this tool integrates seamlessly into developer workflows to inspect piped input or files directly from the terminal. It evaluates every script and outputs a production-readiness score from 0 to 100, ensuring high-risk code never makes it to production.

Code Inspector Use Cases

  • Pre-deployment scanning of Python code generated by AI coding assistants or LLM workflows.
  • Automated CI/CD pipeline checks to catch critical security vulnerabilities before production.
  • Interactive terminal review of pipe-streamed code directly from LLM output wrappers.

How Code Inspector Works

  1. The user installs the tool and points it toward a Python file or streams code through stdin.
  2. The engine parses the codebase and runs AST-based static analysis checks across 8 distinct rule categories.
  3. Points are deducted based on rule severity (Critical, High, Medium, Low vulnerabilities found).
  4. The script calculates a final production-readiness score from 0 to 100.
  5. It outputs a color-coded status report highlighting specific problematic lines and warnings.

Code Inspector Setup

# Install directly from the GitHub repository
pip install git+https://github.com/minirr890112-byte/code-inspector.git

# Scan an individual Python file
code-inspector app.py

# Stream code directly through stdin from other processes
cat app.py | code-inspector

Code Inspector Data Schema & Taxonomy

The tool processes Python abstract syntax trees (AST) in memory to run checks. The scoring severity mapping and production-readiness taxonomy are structured as follows:

Check Category Severity Examples / Target Behavior
Hardcoded secrets Critical Looks for plain-text strings assigned to key variables like 'api_key'.
Unsafe eval/exec Critical Identifies unsafe usage of dynamic execution methods.
Infinite loops Critical Flags modifications of iterators within a while-loop.
Bare except/pass Critical Checks for silent exception swallowing ('except: pass').
Mutable defaults High Flags lists, dictionaries, or sets used as default argument values in functions.
Shadowed builtins High Catches redefinition of built-in terms like 'list = [1,2,3]'.
Deep nesting Medium Pinpoints code blocks with five or more levels of nested loops.
Unused imports Low Flags imported modules that are never referenced.

Scoring Schema

  • 90-100: Production-Ready (Safe to deploy)
  • 70-89: Needs Review (Minor code smell adjustments required)
  • 50-69: High Risk (Contains high severity issues; code review mandatory)
  • 0-49: Do Not Deploy (Critical vulnerabilities or infinite loops present)

Code Inspector Advanced Features

  • Streamlined command pipeline support ('cat file.py | code-inspector') for instant evaluations.
  • High-performance, AST-based inspection engines that run in milliseconds without executing unsafe target code.
  • Easily integrable within custom automated workflows and other Openclaw Skills to safeguard agentic code output generation.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*