Paste this prompt into your agent
Before you start
- Node 22 or newer, and git.
- macOS or Linux. On Windows, use WSL.
- A git repository with a change in it.
1. Install into your agent
Run this in your own terminal, not inside the agent:init finds Claude Code, Cursor, Codex CLI and Cline on your machine. It prints each file it will write, then asks once. --yes skips the questions. agents lists every file for each agent.
Inside a repository, init also:
- asks whether to add the git pre-push hook, so every push from that repository gets a scan, from an agent or by hand. The default is yes.
- adds a short section to each agent’s instruction file, such as
~/.claude/CLAUDE.mdfor Claude Code: when a feature or fix is done, review it with openqodex in a separate subagent, so the agent that wrote the code does not judge its own work. It prints the section before writing it. - creates
.openqodex/config.yamland.openqodex/custom-instructions.md. Commit both. Write incustom-instructions.mdwhat a reviewer of your repository must know: conventions, what never to flag, what always to check. The review brief carries it word for word.
init also starts the scanner downloads that your repo needs, in the background. Running it outside the agent matters: some agents run commands in a sandbox that cannot download.
Codex only: open Codex, run /hooks and trust the OpenQodex hook. Codex runs a new hook only after you trust it.
2. Ask for a review
Say to your agent:openqodex review --agent. That command works out the change, runs the scanners and prints a brief. The agent verifies each scanner finding, reviews the change itself, and writes its findings to a file. Then it runs openqodex review --finalize, which checks those findings without a model and writes the report.
To review the whole repository instead of one change, say:
openqodex review --all --agent. The scanners check every file, and the brief tells the agent where to start: the most-called functions and the files with the most scanner hits. See docs/cli.md for the details.
3. Read the report
The agent tells you the verdict and the most serious findings. The full report is in.openqodex/reviews/<time>-<id>/report.md in your repo. .openqodex/.gitignore keeps the reports out of git; git status shows only the two files above and that .gitignore, the first time.
The verdict is passed unless .openqodex/config.yaml sets review.block_on_severity and a finding meets it. With no config, OpenQodex warns and never blocks.
Try it on the demo repo
demo builds a small repo with planted bugs: a secret, a SQL injection, a bad Dockerfile, a vulnerable lockfile, a shell bug and a workflow injection. It scans the change and prints the report. Then open the folder in your agent and ask for a review.
Without an agent
openqodex scan runs the scanners on the change and prints the report:
First run
Scanners download on first use into~/.openqodex/tools/. Only the scanners your change needs download. A scanner still installing after 45 seconds keeps going in the background. The report lists it as installing. It joins the next run.
One measured first run: an Apple Silicon Mac, an empty tool folder, a line of 2 MB per second. The first demo printed its report in under a minute. That report held the scanners that had finished installing and listed the rest as installing. The next scan included all eight scanners the demo needs. They take about 700 MB of disk.
To download every scanner now:
Next
config: block pushes at a severity, exclude paths, switch scanners off.custom-scanners: add any scanner by its GitHub link.security: what runs and what is sent where.