Code Auditor
/install code-auditor
Code Auditor
Audit any GitHub repository or raw code for security vulnerabilities, code quality issues, and best practices. Supports targeted audits by focus area. Returns a score, severity-scored findings, and actionable summary.
When to Use
- Security review before deploying code
- Evaluating third-party dependencies or libraries
- Code quality assessment for repositories
- Solidity/smart contract gas optimization
- Finding vulnerabilities in open source projects
Usage Flow
- Provide a GitHub repo URL or paste raw code directly
- Optionally specify a
focus:security,quality, orgas(default: full audit) - AIProx routes to the code-auditor agent
- Returns score (0-100), findings array with severity levels, severity counts, and summary
Security Manifest
| Permission | Scope | Reason |
|---|---|---|
| Network | aiprox.dev | API calls to orchestration endpoint |
| Env Read | AIPROX_SPEND_TOKEN | Authentication for paid API |
Make Request
curl -X POST https://aiprox.dev/api/orchestrate \
-H "Content-Type: application/json" \
-H "X-Spend-Token: $AIPROX_SPEND_TOKEN" \
-d '{
"task": "security audit",
"repo_url": "https://github.com/user/repo",
"focus": "security"
}'
Response
{
"score": 72,
"findings": [
{"severity": "critical", "file": "config.js", "line": "12", "issue": "Hardcoded API key", "fix": "Move to environment variable"},
{"severity": "high", "file": "handler.js", "line": "45", "issue": "No input validation on user-supplied data", "fix": "Validate and sanitize inputs"}
],
"severity_counts": {"critical": 1, "high": 2, "medium": 3, "low": 1},
"summary": "Repository has moderate security concerns. Critical: 1 hardcoded secret. High: missing input validation. Recommend immediate remediation."
}
Trust Statement
Code Auditor analyzes public repository contents or provided code only. No code is executed. Analysis is performed by Claude via LightningProx. Your spend token is used for payment; no other credentials are stored or transmitted.
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install code-auditor - 安装完成后,直接呼叫该 Skill 的名称或使用
/code-auditor触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
Code Auditor 是什么?
Audit any GitHub repo or raw code for security, quality, or gas optimization. Returns score, findings, severity counts, and summary. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 409 次。
如何安装 Code Auditor?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install code-auditor」即可一键安装,无需额外配置。
Code Auditor 是免费的吗?
是的,Code Auditor 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Code Auditor 支持哪些平台?
Code Auditor 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Code Auditor?
由 unixlamadev-spec(@unixlamadev-spec)开发并维护,当前版本 v1.1.0。