Review your agent's change before you push it.
OpenQodex is open source AI code review for Claude Code and Codex. One command runs the scanners that fit your change, then starts a separate reviewer. In a full review, the agent that wrote the code does not review it.
- Apache 2.0
- No telemetry
- Mac and Linux
npx openqodex initRun it in your terminal. It finds your coding agents, prints every file it will write and asks once.
npx skills add openqodex/openqodexOr paste this prompt into your agent:
Install the OpenQodex skill with `npx skills add openqodex/openqodex`. Then review my current change with openqodex and tell me the verdict and the findings.
Sets upClaude CodeCursorCodexCline
openqodex reviewOr say "review my change with openqodex" to your agent. A review takes one to three minutes and uses your own Claude Code or Codex plan.
It needs Claude Code or Codex installed and logged in, and no other key, account or server.
Try it on a repo with planted bugs
This builds a small repo with planted bugs on your machine and scans it.
npx openqodex demoScanners first, then a separate reviewer, then script checks
One command, openqodex review, works out your change: the commits not yet pushed plus everything uncommitted. It runs the scanners that fit the changed files, then starts its own reviewer, a separate Claude Code or Codex process. Scripts check the answer and OpenQodex prints one report.
Your change
The commits not yet pushed plus everything uncommitted, as a frozen copy.
- Passes on: findings on changed lines
Scanners
No modelThirteen are built in. Each runs only when the change holds a file it reads, and only findings on the lines you changed are kept. A code graph lists the callers and importers of the code you touched.
- Passes on: the reviewer's answer
The reviewer process
Claude Code or CodexA separate process that OpenQodex starts on your own login, with none of your settings, plugins or hooks. It reads the frozen copy and edits nothing. It checks every scanner finding and is given every changed line.
- Passes on: a verdictthe report
Script checks
No modelScripts check the answer. Every scanner finding must be raised or dropped with a reason, and every changed line must have been in front of the reviewer.
- No other key. It needs Claude Code or Codex installed and logged in, and no other key, account or server.
- A separate reviewer. The reviewer is a fresh process with no memory of the session that wrote the code.
- A push gate. In Claude Code and Codex, a gate checks your current work for a review. The optional git pre-push hook checks exactly what is pushed. Both warn by default.
Scanners first
Before the reviewer starts, OpenQodex runs the static analysis, secret scanning, dependency and lint scanners that fit the files you changed. It keeps only the findings on the lines you changed.
- semgrep project on GitHubcode patterns
Risky code patterns, from three Semgrep registry rule packs
- gitleaks project on GitHubsecrets
Secrets in the change, such as keys and passwords
- osv-scanner project on GitHubdependencies
Dependencies with known vulnerabilities, from your lockfile
- actionlint project on GitHubworkflows
Mistakes in GitHub workflow files
- hadolint project on GitHubDockerfile
Dockerfile mistakes
Mistakes in shell scripts
- ruff project on GitHubPython
Python lint errors
- bandit project on GitHubPython
Python security issues
- oxlint project on GitHubJS and TS
JavaScript and TypeScript lint errors
Go lint errors
Needs Go on your machine
Rails security issues
Needs Ruby 2.7 or newer. Its licence is not open source.
Ruby lint errors
Needs Ruby 2.7 or newer
- sqllintbuilt in
Common mistakes in Postgres migrations, such as a privileged function every role can call
- Not on the list?
Add any scanner by its GitHub link. See how
Scanners download on first use, and only the ones your change needs. Every downloaded scanner is pinned to one version. OpenQodex is open source. One scanner is not: brakeman is under the Brakeman Public Use License. OpenQodex does not bundle it, and scanners.disable: [brakeman] switches it off. What each scanner reads and sends
Your team's scanner, by its GitHub link
Add the link and how to run it. Approve it once. Its findings join the same review.
- Trust shows you the version, the release asset, its sha256 and the run line, then asks yes or no.
- The download waits in a quarantine folder. Nothing is installed or run before your yes.
- An edited entry needs a new approval, and the run line is never passed through a shell.
# .openqodex/config.yaml scanners: custom: - source: https://github.com/aquasecurity/trivy run: trivy config --format sarif --output {report} {target}
npx openqodex trustA custom scanner is a command on your machine, so it never runs until you approve that exact entry.
In your agent, in your terminal, in CI
The review runs on your machine, from your coding agent or your terminal. The GitHub Action and the pre-commit hook run the scanners only. They are not a review.
Coding agent
Say "review my change with openqodex". Your agent runs openqodex review and shows you the report. Cursor and Cline can run it, but neither is the reviewer: the review needs Claude Code or Codex installed too.
- Claude Code
- Cursor
- Codex
- Cline
Terminal
Run openqodex review yourself. review --all reviews the whole repository. review <branch> and review '#42' review a branch or a pull request that is not your current work.
CI and pre-commit
A GitHub Action and a pre-commit hook run the scanners only (openqodex scan). They are not a review.
- 13 built in
- Pinned versions
The scanners are the same in all three places. Only a review on your machine adds the reviewer.
No telemetry
OpenQodex sends no telemetry and collects no usage data. It has no server and no account. A scrubbed problem report goes to GitHub only when you choose to send it.
OpenQodex and the built-in scanners send no code anywhere. The reviewer sends the review brief and what it reads to the model your own Claude Code or Codex login uses. By default the reviewer can also search the web, and reviewer_web: off in ~/.openqodex/config.yaml removes that.
OpenQodex and Qodex, side by side
OpenQodex reviews your change on your machine, before the push. Want this on every pull request for the whole team? That is Qodex, the hosted product from the same team.
| OpenQodex | Qodex | |
|---|---|---|
| What it is | Open source, Apache 2.0 | The hosted product |
| Where it runs | On your machine, from your coding agent or your terminal | Hosted, installed as a GitHub app |
| When | Before the push | On every pull request |
| Who it is for | You and your coding agent | The whole team |
| Model | A separate Claude Code or Codex reviewer, on your own login | Two frontier models from different labs |
| Team memory | No. A committed instructions file tells the reviewer what never to flag. | Yes. Dismiss a finding once and it stops coming back. |
| Gate | A push gate that warns by default. It blocks only when your repo sets review.block_on_severity. | A merge gate you configure for each repo |
| Dashboard | No. The report is on your machine. | Yes, for the whole team |
| Setup | One command. It needs Claude Code or Codex logged in, and no other key or account. | Install the GitHub app |
| Price | Free. A review uses your own Claude Code or Codex plan. | Paid per developer |
Nothing that is open today becomes paid later. Everything in the repo stays free.
Get started with QodexNot yet
- A separate reviewer other than Claude Code or Codex
- Cursor as the reviewer
- Codex as the reviewer inside Codex's own sandbox
- A review on your own API key, without Claude Code or Codex
- A tool server for agents (MCP)
- A Homebrew formula, an install script or a Docker image
- Windows outside WSL
- An offline copy of the vulnerability database
A review takes one to three minutes and uses your own Claude Code or Codex plan. No review finds everything. The promise is that every stage runs, every scanner finding is checked, every changed line is put in front of the reviewer, and anything skipped is named. The changelog records every change. Changelog
Questions developers ask first
How is this different from asking my agent to review its own change?
In a full review, the agent that wrote the code does not review it. openqodex review starts a separate Claude Code or Codex process that reads a frozen copy of the change, with none of your settings, plugins or hooks and no memory of the session that wrote the code. The scanners that fit the changed files run first, and the reviewer has to raise or drop every scanner finding with a reason.
Is this just a wrapper around a prompt?
No. The scanners run first with no model, and only findings on the lines you changed are kept. The reviewer is a separate process that reads a frozen copy of the change. Scripts then check its answer: every scanner finding must be raised or dropped with a reason, and every changed line must have been put in front of the reviewer. A review that falls short prints "Review incomplete" with what is missing.
Why not just run semgrep or gitleaks myself in pre-commit?
You can, and if that works for you, keep it. OpenQodex picks the scanners that fit the changed files from thirteen built in, pins every downloaded scanner to one version and keeps only findings on the lines you changed. In a review, a separate reviewer then checks every scanner finding. OpenQodex also has a pre-commit hook and a GitHub Action, but those run the scanners only and are not a review.
Does it need an API key or an account?
It needs Claude Code or Codex installed and logged in, and no other key, account or server. A review uses your own Claude Code or Codex plan. Without either, openqodex review prints "Full review unavailable", says what is missing and saves the scanner findings to a file as unchecked.
Which model does the AI code review use?
The model your Claude Code or Codex login uses. OpenQodex starts Claude Code or Codex as the reviewer and adds no other model. By default it picks the agent you run the command from, then Claude Code, then Codex, and --reviewer picks one. Cursor and Cline can run the review, but neither is the reviewer.
Where does my code go?
OpenQodex and the built-in scanners send no code anywhere, and OpenQodex sends no telemetry. The reviewer sends the review brief and what it reads to the model your Claude Code or Codex login uses, as any Claude Code or Codex session does. By default the reviewer can also search the web, and reviewer_web: off in ~/.openqodex/config.yaml removes that. When the change holds a lockfile, the dependency check sends dependency names and versions to osv.dev, never code.
Will it block my push?
Not by default. The push gate for Claude Code and Codex checks your current work for a review, and the optional git pre-push hook checks exactly what is pushed. Neither scans or reviews by itself. They warn by default and block only when .openqodex/config.yaml sets review.block_on_severity. OPENQODEX_SKIP=1 lets a push through and says so.
What is the paid Qodex product, and what stays free?
Qodex is the hosted product: review on every pull request for a whole team, with team memory, merge gates and a dashboard. What stays free is everything in the repo, and nothing that is open today becomes paid later.
Try it on the branch you have open right now.
Open source AI code review for Claude Code and Codex, before you push.
npx openqodex initRun it in your terminal. It finds your coding agents, prints every file it will write and asks once.
npx skills add openqodex/openqodexOr paste this prompt into your agent:
Install the OpenQodex skill with `npx skills add openqodex/openqodex`. Then review my current change with openqodex and tell me the verdict and the findings.
Sets upClaude CodeCursorCodexCline