A comprehensive three-tier code quality defense and security audit orchestration layer for users of Openclaw Skills.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install codex-review
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install codex-review using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Codex Review provides a robust three-tier code quality defense, acting as a unified orchestration layer for deep code analysis. It dynamically adjusts audit depth—from L1 quick scans to L3 cross-validation—ensuring that every line of code meets high standards for security and performance. This is a critical tool within the ecosystem of Openclaw Skills for developers who prioritize reliability and automated quality assurance.
By combining external model intelligence with local agent audits, Codex Review identifies critical vulnerabilities, logic errors, and tech-stack-specific pitfalls. It operates with a security-first mindset, using read-only permissions and local-only artifacts to protect your intellectual property while delivering actionable, severity-graded reports that empower teams to ship cleaner code faster.
To integrate this tool into your Openclaw Skills workflow, configure your environment variables for the optional external model:
export CODEX_REVIEW_API_BASE="https://api.openai.com/v1"
export CODEX_REVIEW_API_KEY="your_api_key_here"
export CODEX_REVIEW_MODEL="gpt-4o"
Ensure curl is installed on your system. While it operates independently, having the bug-audit skill available will unlock the full potential of Level 2 and Level 3 deep audits.
Codex Review organizes analysis data through ephemeral files and structured reporting formats:
| Component | Type | Description |
|---|---|---|
| Hotspot File | JSON | Ephemeral file in the temp directory used for L1 to L2 handoff summary data. |
| Audit Report | Markdown | Comprehensive severity-graded output including file paths, line numbers, and fix snippets. |
| Check Matrix | Logical | Dynamic, project-specific checklist generated based on detected tech stacks (e.g., Node.js, Python). |
| Credentials | Env Vars | Sensitive API keys are handled exclusively via environment variables for maximum security. |
Loading
A powerful AI-driven browser automation skill that handles complex multi-step web workflows, logins, and anti-bot measures using the Browser-Use framework.

A Python-powered skill for fetching Strava activity data and workout statistics through your AI agent.

A CLI-driven tracking tool for monitoring Product Hunt launch metrics and leaderboards in real-time.

A specialized tool for managing social media workspaces and automating post scheduling through AI-driven workflows.

A rigorous, five-phase framework for AI agents to perform systematic root cause analysis and safe code deployment.

A comprehensive framework of mandatory quality standards and checklists designed to eliminate cross-state bugs and optimize game performance across all platforms.








































