Code Analyzer

SkillDev tools

Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk. Use when the user mentions codexqa-code-analyzer, code-analyzer, codexqa, 符号图, 代码知识图谱, 建索引, 查调用, 影响面, --diff-base, 变更审查, 回归范围, 测试缺口, or asks to install / run the codexqa CLI (index, query). Former skill name: code-analyzer. Not CodexQA evidence-pack HTML review (that is codexqa-code-reviewer), not SAST + Agent LLM Detection code-risk scan reports (that is codexqa-defect-analyzer), and not architecture wiki reports (that is codexqa-code-wiki), and not full exception RCA reports (that is codexqa-rootcause-analyzer).

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Code Analyzer skill

What this skill tells your AI

The instructions your AI receives, as published by openqa-cn/codexqa in skills/codexqa-code-analyzer/SKILL.md and read by ahel’s review.

Local symbol graph for quality work: index first, then answer what changed, who is hit, what is untested, and where an error comes from.

There is no codexqa diff or codexqa review. Review a change with:

index --diff-base <ref>  →  change-groups  →  symbol-diff  →  callers / tests / entries

Pick the scenario before acting. Do not query or review a diff until an index exists. Do not run full-text search unless the user asked. README.md / README.zh-CN.md are human-facing. Do not load them at runtime.

Documents (load on demand)

Read this file first. Read another file only when the row below applies. Do not preload the whole tree.

FileLoad when
SKILL.md (this file)always: routing, report contract, reject conditions
references/playbook.mdentering a scenario (index health / change / defect / implementation / architecture)
references/diagrams.mdbefore drawing; copy init and classDef verbatim
references/cli.mdCLI missing, PATH, LLM, or maintenance
references/mcp.jsongraph-query tool schema is needed
README.md, README.zh-CN.mdhuman-facing; not needed by the agent

Scenario routing

Open references/playbook.md and jump to the named section.

User is asking…Playbook section
Review a PR / what changed / vs mainReview one change (index health first)
Who is hit / what to regression-testRegression scope under that change section
Any unit tests / coverage gapsTest gaps under that change section
Which HTTP / RPC / MQ path reaches thisEntry risk under that change section
Auth, payments, password, tokenSensitive paths under that change section
Logs, stack, error text, commentsLocate a defect
How does this function work / who calls itUnderstand an implementation
Module ownership / wrong layerArchitecture drift
Results are empty / every change is defaultIndex health / Analysis blockers

Report contract

Deliver a Mermaid evidence report (graph conclusions + diagrams). Not a product review, and not Archify / interactive HTML. Read references/diagrams.md before drawing. A diagram that misses the quality bar fails the report.

Report body is only these blocks:

  • Must-read groups (by risk)
  • What changed (trust only symbol-diff / file-source vs file-base)
  • Must-test callers / entries (must come from edges / reach / path / tagged)
  • Test gaps (a tests directory is not a tests edge)
  • Sensitive paths (write "none" if there are none)
  • Diagrams: at least one, and it must pass the quality bar

Reject the whole report and rewrite if any of these hold:

  • Written as a generic project review (product intro, use cases, scored pros/cons)
  • Evidence comes from README / a website / guesswork, not this run of summary / imports / source / edges / reach / change-groups / symbol-diff
  • Only names large files or high fan-in; never uses edges / reach to say who is hit
  • Infers "covered" from a tests directory name; never checked tested_count or reach --direction in --edge-kinds tests
  • Mermaid is missing the Claude paper init, the three classDef lines, or a core module that should be risk has no class ... risk
  • Architecture subgraph titles are package names (Renderer / Compiler / Shared) instead of Entry → Application → Domain → Storage
  • Interactive HTML / Archify canvas was generated (this skill does not ask for that)

Signals

GitHub stars
60
Forks
2
Last commit
Sep 2026

ahel review

  • K1binfo
    installs-packages (in README.md)
  • K1binfo
    installs-packages (in README.zh-CN.md)
  • K1binfo
    installs-packages (in references/cli.md)

Automated review, not a security audit. Ruleset v1+k2.

Advanced
Item type
skill
Key
codexqa-code-analyzer
Source
github.com/openqa-cn/codexqa