A professional security automation skill that integrates CodeQL static analysis with LLM intelligence to detect, analyze, and prioritize code vulnerabilities.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install li-codeql-llm
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install li-codeql-llm using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Li CodeQL LLM skill represents a significant leap in automated security auditing by merging the precision of GitHub's CodeQL engine with the contextual intelligence of Large Language Models. Built for the Openclaw Skills framework, this tool automates the tedious lifecycle of security scanning—from environment setup and database creation to the final report generation. It goes beyond simple pattern matching by using LLMs to interpret raw SARIF data, identifying false positives, and providing human-readable remediation advice tailored to the specific code context.
To get started with this addition to your Openclaw Skills library, ensure you have the CodeQL CLI installed.
# Download and install CodeQL CLI
wget https://github.com/github/codeql-cli-binaries/releases/latest/download/codeql-linux64.zip
unzip codeql-linux64.zip -d /opt/codeql
ln -s /opt/codeql/codeql/codeql /usr/local/bin/codeql
# Verify installation
codeql --version
Once installed, you can trigger a scan by providing the project path to the AI agent.
The Li CodeQL LLM skill organizes its output into structured reports and standardized formats to ensure interoperability within Openclaw Skills workflows:
| Output File | Description |
|---|---|
| CODEQL_SECURITY_REPORT.md | A comprehensive executive summary including severity distribution and code-level fix suggestions. |
| Vulnerability_Checklist.md | An actionable list for security testers including payloads, expected results, and verification steps. |
| codeql-results.sarif | Standardized Static Analysis Results Interchange Format for use in IDEs or CI/CD dashboards. |
Loading
A high-performance IPv4 geolocation lookup tool powered by Juhe Data for automated IP intelligence.

A specialized behavioral protocol that forces AI agents to prioritize shipping code and maintaining execution momentum over conversational chatter.

An AI-powered assistant for managing Tencent Cloud architectures, performing Well-Architected assessments, and generating secure console access links.

A specialized relocation intelligence skill designed to help expats, digital nomads, and professionals navigate the complexities of moving to and living in China.

A specialized AI tool for generating structured nonprofit grant proposal outlines that align project goals with budgets and impact metrics.

A structured AI tool for designing Day 1, 7, and 30 onboarding milestones for customers and employees.








































