Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/sansec-ai/codeclaw-vscode/code-reviewnpx skills add sansec-ai/codeclaw-vscode --skill code-reviewgit clone --depth 1 https://github.com/sansec-ai/codeclaw-vscodeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00054 | $0.02684 |
| Opus 5 | $0.00027 | $0.01342 |
| Sonnet 5 | $0.00011 | $0.00537 |
| Haiku 4.5 | $0.00005 | $0.00268 |
Grade A, and why
code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 226 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Code Review Checklist
Thorough, structured approach to reviewing code. Work through each dimension systematically rather than scanning randomly.
Installation
OpenClaw / Moltbot / Clawbot
npx clawhub@latest install code-review
Review Dimensions
| Dimension | Focus | Priority |
|---|---|---|
| Security | Vulnerabilities, auth, data exposure | Critical |
| Performance | Speed, memory, scalability bottlenecks | High |
| Correctness | Logic errors, edge cases, data integrity | High |
| Maintainability | Readability, structure, future-proofing | Medium |
| Testing | Coverage, quality, reliability of tests | Medium |
| Accessibility | WCAG compliance, keyboard nav, screen readers | Medium |
| Documentation | Comments, API docs, changelog entries | Low |
Security Checklist
Review every change for these vulnerabilities:
- SQL Injection — All queries use parameterized statements or an ORM; no string concatenation with user input
- XSS — User-provided content is escaped/sanitized before rendering;
dangerouslySetInnerHTMLor equivalent is justified and safe - CSRF Protection — State-changing requests require valid CSRF tokens; SameSite cookie attributes are set
- Authentication — Every protected endpoint verifies the user is authenticated before processing
- Authorization — Resource access is scoped to the requesting user's permissions; no IDOR vulnerabilities
- Input Validation — All external input (params, headers, body, files) is validated for type, length, format, and range on the server side
- Secrets Management — No API keys, passwords, tokens, or credentials in source code; secrets come from environment variables or a vault
- Dependency Safety — New dependencies are from trusted sources, actively maintained, and free of known CVEs
- Sensitive Data — PII, tokens, and secrets are never logged, included in error messages, or returned in API responses
- Rate Limiting — Public and auth endpoints have rate limits to prevent brute-force and abuse
- File Upload Safety — Uploaded files are validated for type and size, stored outside the webroot, and served with safe Content-Type headers
- HTTP Security Headers — Content-Security-Policy, X-Content-Type-Options, Strict-Transport-Security are set
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 226 lines · 54 tokens per session scan A dd1241323156
code-review is a skill published in the GitHub repository sansec-ai/codeclaw-vscode (2 stars, last pushed 5mo ago), licensed MIT. It adds 54 tokens to every session and 2,684 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
wemp-operator
微信公众号自动化运营。触发词:采集热点、公众号日报、周报、检查评论、回复评论、生成文章。依赖 wemp skill。.
tmux
Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output.
summarize
Summarize or extract text/transcripts from URLs, podcasts, and local files (great fallback for “transcribe this YouTube/video”).
add-matrix
Add Matrix channel integration via Chat SDK. Works with any Matrix homeserver.
add-resend
Add Resend (email) channel integration via Chat SDK.
add-macos-statusbar
Add a macOS menu bar status indicator for NanoClaw. Shows a bolt icon with a green/red dot indicating whether NanoClaw is running, with Start, Stop, and Restart controls. macOS only.