Codex Review for Openclaw

A comprehensive three-tier code quality defense and security audit orchestration layer for users of Openclaw Skills.

abczsl520
v2.1.0
Mar 7, 2026
0
1k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install codex-review

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install codex-review using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Codex Review?

Codex Review provides a robust three-tier code quality defense, acting as a unified orchestration layer for deep code analysis. It dynamically adjusts audit depth—from L1 quick scans to L3 cross-validation—ensuring that every line of code meets high standards for security and performance. This is a critical tool within the ecosystem of Openclaw Skills for developers who prioritize reliability and automated quality assurance.

By combining external model intelligence with local agent audits, Codex Review identifies critical vulnerabilities, logic errors, and tech-stack-specific pitfalls. It operates with a security-first mindset, using read-only permissions and local-only artifacts to protect your intellectual property while delivering actionable, severity-graded reports that empower teams to ship cleaner code faster.

Codex Review Use Cases

  • Rapidly scanning new pull requests or code snippets for immediate bug feedback.
  • Performing exhaustive security audits before major production deployments to catch vulnerabilities.
  • Cross-validating complex code logic using multiple independent AI perspectives to minimize false positives.
  • Executing adversarial testing on security fixes to ensure they cannot be easily bypassed.

How Codex Review Works

  1. The skill gathers code from local files, git repositories, or snippets while automatically excluding non-essential directories like node_modules.
  2. In Level 1, it initiates an automated scan using an external API followed by a deep supplementary pass by the local agent to merge and dedup findings.
  3. In Level 2, it executes a full deep audit flow, leveraging project dissection and dependency graphing to verify every logic path.
  4. In Level 3, it performs dual independent audits, compares results for conflicts, and triggers adversarial testing to validate fix robustness.
  5. The process concludes with a detailed Markdown report categorized by severity (Critical, High, Medium, Low) with concrete fix suggestions.

Codex Review Setup

To integrate this tool into your Openclaw Skills workflow, configure your environment variables for the optional external model:

export CODEX_REVIEW_API_BASE="https://api.openai.com/v1"
export CODEX_REVIEW_API_KEY="your_api_key_here"
export CODEX_REVIEW_MODEL="gpt-4o"

Ensure curl is installed on your system. While it operates independently, having the bug-audit skill available will unlock the full potential of Level 2 and Level 3 deep audits.

Codex Review Data Schema & Taxonomy

Codex Review organizes analysis data through ephemeral files and structured reporting formats:

Component Type Description
Hotspot File JSON Ephemeral file in the temp directory used for L1 to L2 handoff summary data.
Audit Report Markdown Comprehensive severity-graded output including file paths, line numbers, and fix snippets.
Check Matrix Logical Dynamic, project-specific checklist generated based on detected tech stacks (e.g., Node.js, Python).
Credentials Env Vars Sensitive API keys are handled exclusively via environment variables for maximum security.

Codex Review Advanced Features

  • Multi-level orchestration that cascades from quick scans to adversarial security testing.
  • Automated hotspot gap analysis to ensure deep audits cover all issues flagged during initial scans.
  • Adversarial testing mode that specifically attempts to find bypasses for implemented security fixes.
  • Intelligent batching for large projects to maintain context and accuracy across thousands of lines of code.
  • Support for custom trigger mapping, allowing users to define the depth of the audit via natural language.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*