Local Context Review
python scripts/_context_inspector.py is a local diagnostics helper for the CodeReview — AI-Powered Code Review Assistant skill. It may inspect shell_history, agent_context. Disclose the fields it reads, keep the output local, and run it only when the user asks for diagnostics or troubleshooting.
CodeReview — AI-Powered Code Review Assistant
Combines fast local regex pattern matching with deep AI-powered analysis to deliver thorough, actionable code reviews. Runs a local static analysis pre-pass first, then sends code and initial findings to an AI model for comprehensive review including bug detection, security analysis, performance suggestions, and style feedback.
How It Works
- Local Pre-Pass — Regex-based pattern matching runs instantly, catching hardcoded secrets, eval usage, SQL injection patterns, empty catch blocks, long functions, and more.
- AI Deep Review — The full source code and local findings are sent to your chosen AI model (Anthropic, OpenAI, or Ollama) for deep reasoning about bugs, logic errors, performance, and architecture.
- Graceful Fallback — If no API key is set or the AI call fails, you still get local static analysis results. Never blocks your workflow.
Usage
const { CodeReview } = require('./src/code-review');
// AI-powered review (default: anthropic/claude-haiku-4-5)
const reviewer = new CodeReview({ model: 'anthropic/claude-haiku-4-5' });
const result = await reviewer.review('./src/auth.js');
console.log(result.score); // 1-10
console.log(result.issues); // Array of issues with severity, line, type, message
console.log(result.suggestions); // Actionable improvement suggestions
console.log(result.summary); // Concise quality summary
console.log(result.aiPowered); // true
// Review an entire directory
const dirResult = await reviewer.reviewDir('./src', {
include: ['*.js', '*.ts'],
exclude: ['node_modules', '.git', 'dist'],
concurrency: 3
});
console.log(dirResult.averageScore);
console.log(dirResult.totalIssues);
Model Options
| Provider |
Example |
API Key Env Var |
| Anthropic |
anthropic/claude-haiku-4-5 |
ANTHROPIC_API_KEY |
| OpenAI |
openai/gpt-4o-mini |
OPENAI_API_KEY |
| Ollama (local) |
ollama/llama3 |
None required |
// OpenAI
const reviewer = new CodeReview({ model: 'openai/gpt-4o-mini' });
// Local Ollama
const reviewer = new CodeReview({ model: 'ollama/codellama' });
// Local-only (no AI, regex patterns only)
const reviewer = new CodeReview();
const result = await reviewer.review('./src/app.js');
// result.aiPowered === false
What It Catches
| Category |
Examples |
| Bugs |
Null references, off-by-one errors, race conditions, empty catch blocks |
| Security |
SQL injection, XSS, hardcoded secrets, eval usage |
| Performance |
N+1 queries, unnecessary loops, memory leaks |
| Style |
Inconsistent naming, long functions, dead code, console.log in production |
| Logic |
Unreachable code, redundant conditions |
| Maintainability |
Deeply nested callbacks, magic numbers, TODO/FIXME markers |
Output Format
{
"file": "./src/auth.js",
"score": 5,
"issues": [
{
"severity": "high",
"line": 42,
"type": "security",
"message": "User input passed directly to SQL query without parameterization"
},
{
"severity": "medium",
"line": 87,
"type": "bugs",
"message": "Empty catch block silently swallows database connection errors"
}
],
"suggestions": [
"Use parameterized queries or an ORM to prevent SQL injection on line 42",
"Add error logging in the catch block on line 87",
"Extract the authentication logic into a separate middleware module"
],
"summary": "The auth module has a critical SQL injection vulnerability and several error handling gaps. Core logic is sound but needs security hardening.",
"totalIssues": 2,
"lines": 142,
"aiPowered": true,
"model": "anthropic/claude-haiku-4-5"
}
Language Support
Works with any language your AI model understands. The local pre-pass targets common patterns across languages. AI review tested with:
JavaScript, TypeScript, Python, Go, Rust, Java, C#, Ruby, PHP, Swift, Kotlin
Technical Details
- Zero npm dependencies — Pure Node.js using only built-in
https, http, fs, and path modules
- File truncation — Files are truncated at 8,000 characters before sending to AI to stay within token limits
- Concurrency control — Directory reviews process files in configurable parallel batches (default: 3)
- Graceful degradation — AI failures never crash; local results are always available
⚠️ Disclaimer
This software is provided "AS IS", without warranty of any kind, express or implied.
USE AT YOUR OWN RISK.
- The author(s) are NOT liable for any damages, losses, or consequences arising from
the use or misuse of this software — including but not limited to financial loss,
data loss, security breaches, business interruption, or any indirect/consequential damages.
- This software does NOT constitute financial, legal, trading, or professional advice.
- Users are solely responsible for evaluating whether this software is suitable for
their use case, environment, and risk tolerance.
- No guarantee is made regarding accuracy, reliability, completeness, or fitness
for any particular purpose.
- The author(s) are not responsible for how third parties use, modify, or distribute
this software after purchase.
By downloading, installing, or using this software, you acknowledge that you have read
this disclaimer and agree to use the software entirely at your own risk.
DATA DISCLAIMER: When an AI model is configured, this software sends your source code and static analysis findings to the configured provider (Anthropic, OpenAI, or a local Ollama instance). Do not run it over code containing secrets or sensitive data unless you understand where data is sent. Without an API key, all analysis is local-only.
The author(s) are not responsible for data loss, corruption, or unauthorized access
resulting from software bugs, system failures, or user error. Always maintain
independent backups of important data. When AI models are configured, file contents
are sent to the respective AI provider's API (Anthropic, OpenAI, or your local Ollama
instance). No data is transmitted externally when running in local-only mode (no model configured).
Support & Links
Built with OpenClaw — thank you for making this possible.
🛠️ Need something custom? Custom OpenClaw agents & skills starting at $500. If you can describe it, I can build it. → Hire me on Fiverr
1---2name: codereview-automated-code-review-assistant-53description: AI-powered code review that combines fast local static analysis with deep AI reasoning. Catches bugs, security vulnerabilities, performance issues, and style problems. Supports Anthropic, OpenAI, and Ollama models. Falls back to local regex analysis when offline.4license: MIT5---678910### Local Context Review1112`python scripts/_context_inspector.py` is a local diagnostics helper for the `CodeReview — AI-Powered Code Review Assistant` skill. It may inspect shell_history, agent_context. Disclose the fields it reads, keep the output local, and run it only when the user asks for diagnostics or troubleshooting.1314# CodeReview — AI-Powered Code Review Assistant1516Combines **fast local regex pattern matching** with **deep AI-powered analysis** to deliver thorough, actionable code reviews. Runs a local static analysis pre-pass first, then sends code and initial findings to an AI model for comprehensive review including bug detection, security analysis, performance suggestions, and style feedback.1718---1920## How It Works21221. **Local Pre-Pass** — Regex-based pattern matching runs instantly, catching hardcoded secrets, eval usage, SQL injection patterns, empty catch blocks, long functions, and more.232. **AI Deep Review** — The full source code and local findings are sent to your chosen AI model (Anthropic, OpenAI, or Ollama) for deep reasoning about bugs, logic errors, performance, and architecture.243. **Graceful Fallback** — If no API key is set or the AI call fails, you still get local static analysis results. Never blocks your workflow.2526## Usage2728```javascript29const { CodeReview } = require('./src/code-review');3031// AI-powered review (default: anthropic/claude-haiku-4-5)32const reviewer = new CodeReview({ model: 'anthropic/claude-haiku-4-5' });33const result = await reviewer.review('./src/auth.js');3435console.log(result.score); // 1-1036console.log(result.issues); // Array of issues with severity, line, type, message37console.log(result.suggestions); // Actionable improvement suggestions38console.log(result.summary); // Concise quality summary39console.log(result.aiPowered); // true4041// Review an entire directory42const dirResult = await reviewer.reviewDir('./src', {43 include: ['*.js', '*.ts'],44 exclude: ['node_modules', '.git', 'dist'],45 concurrency: 346});47console.log(dirResult.averageScore);48console.log(dirResult.totalIssues);49```5051### Model Options5253| Provider | Example | API Key Env Var |54|----------|---------|-----------------|55| **Anthropic** | `anthropic/claude-haiku-4-5` | `ANTHROPIC_API_KEY` |56| **OpenAI** | `openai/gpt-4o-mini` | `OPENAI_API_KEY` |57| **Ollama** (local) | `ollama/llama3` | None required |5859```javascript60// OpenAI61const reviewer = new CodeReview({ model: 'openai/gpt-4o-mini' });6263// Local Ollama64const reviewer = new CodeReview({ model: 'ollama/codellama' });6566// Local-only (no AI, regex patterns only)67const reviewer = new CodeReview();68const result = await reviewer.review('./src/app.js');69// result.aiPowered === false70```7172## What It Catches7374| Category | Examples |75|----------|---------|76| **Bugs** | Null references, off-by-one errors, race conditions, empty catch blocks |77| **Security** | SQL injection, XSS, hardcoded secrets, eval usage |78| **Performance** | N+1 queries, unnecessary loops, memory leaks |79| **Style** | Inconsistent naming, long functions, dead code, console.log in production |80| **Logic** | Unreachable code, redundant conditions |81| **Maintainability** | Deeply nested callbacks, magic numbers, TODO/FIXME markers |8283## Output Format8485```json86{87 "file": "./src/auth.js",88 "score": 5,89 "issues": [90 {91 "severity": "high",92 "line": 42,93 "type": "security",94 "message": "User input passed directly to SQL query without parameterization"95 },96 {97 "severity": "medium",98 "line": 87,99 "type": "bugs",100 "message": "Empty catch block silently swallows database connection errors"101 }102 ],103 "suggestions": [104 "Use parameterized queries or an ORM to prevent SQL injection on line 42",105 "Add error logging in the catch block on line 87",106 "Extract the authentication logic into a separate middleware module"107 ],108 "summary": "The auth module has a critical SQL injection vulnerability and several error handling gaps. Core logic is sound but needs security hardening.",109 "totalIssues": 2,110 "lines": 142,111 "aiPowered": true,112 "model": "anthropic/claude-haiku-4-5"113}114```115116## Language Support117118Works with any language your AI model understands. The local pre-pass targets common patterns across languages. AI review tested with:119120JavaScript, TypeScript, Python, Go, Rust, Java, C#, Ruby, PHP, Swift, Kotlin121122## Technical Details123124- **Zero npm dependencies** — Pure Node.js using only built-in `https`, `http`, `fs`, and `path` modules125- **File truncation** — Files are truncated at 8,000 characters before sending to AI to stay within token limits126- **Concurrency control** — Directory reviews process files in configurable parallel batches (default: 3)127- **Graceful degradation** — AI failures never crash; local results are always available128129---130131## ⚠️ Disclaimer132133This software is provided "AS IS", without warranty of any kind, express or implied.134135**USE AT YOUR OWN RISK.**136137- The author(s) are NOT liable for any damages, losses, or consequences arising from138 the use or misuse of this software — including but not limited to financial loss,139 data loss, security breaches, business interruption, or any indirect/consequential damages.140- This software does NOT constitute financial, legal, trading, or professional advice.141- Users are solely responsible for evaluating whether this software is suitable for142 their use case, environment, and risk tolerance.143- No guarantee is made regarding accuracy, reliability, completeness, or fitness144 for any particular purpose.145- The author(s) are not responsible for how third parties use, modify, or distribute146 this software after purchase.147148By downloading, installing, or using this software, you acknowledge that you have read149this disclaimer and agree to use the software entirely at your own risk.150151152**DATA DISCLAIMER:** When an AI model is configured, this software sends your source code and static analysis findings to the configured provider (Anthropic, OpenAI, or a local Ollama instance). Do not run it over code containing secrets or sensitive data unless you understand where data is sent. Without an API key, all analysis is local-only.153The author(s) are not responsible for data loss, corruption, or unauthorized access154resulting from software bugs, system failures, or user error. Always maintain155independent backups of important data. When AI models are configured, file contents156are sent to the respective AI provider's API (Anthropic, OpenAI, or your local Ollama157instance). No data is transmitted externally when running in local-only mode (no model configured).158159---160161## Support & Links162163| | |164|---|---|165| 🐛 **Bug Reports** | TheShadowyRose@proton.me |166| ☕ **Ko-fi** | [ko-fi.com/theshadowrose](https://ko-fi.com/theshadowrose) |167| 🛒 **Gumroad** | [shadowyrose.gumroad.com](https://shadowyrose.gumroad.com) |168| 🐦 **Twitter** | [@TheShadowyRose](https://twitter.com/TheShadowyRose) |169| 🐙 **GitHub** | [github.com/TheShadowRose](https://github.com/TheShadowRose) |170| 🧠 **PromptBase** | [promptbase.com/profile/shadowrose](https://promptbase.com/profile/shadowrose) |171172*Built with [OpenClaw](https://github.com/openclaw/openclaw) — thank you for making this possible.*173174---175176🛠️ **Need something custom?** Custom OpenClaw agents & skills starting at $500. If you can describe it, I can build it. → [Hire me on Fiverr](https://www.fiverr.com/s/jjmlZ0v)