autoreview skillA
autoreview is agent-read markdown (skill) from openclaw/carapace: Pre-commit/ship code review: Codex default; optional Claude or Pi..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Auto Review Run the bundled structured review helper as a closeout check. This is code review, not Guardian `auto_review` approval routing. Codex review is the default when no engine is set. It uses `gpt-5.6-sol` with `high` reasoning by default, then retries once with `gpt-5.6-terra` only when the account cannot access Sol. Claude review is optional and uses `claude-fable-5` by default. For user-visible behavior, pair autoreview with `behavior-validator`. Autoreview is source-aware and judges the change bundle; behavior validation is source-blind and judges the running product or tool against a behavior contract. A clean autoreview is not proof that a UI, CLI, API, or generated artifact works from the user's perspective. Use when: - user asks for Codex review / Claude review / Pi review / autoreview / second-model review - after non-trivial code edits, before final/commit/ship - reviewing a local branch or PR branch after fixes ## Contract - Treat review output as advisory. Never blindly apply it. - Verify every finding by reading the real code path and adjacent files. - Read dependency docs/source/types when the finding depends on external behavior. …
Read the whole file at its exact version.
How to install
mdr add openclaw/carapace/autoreview@git:20260712.9f26ffcmdr add openclaw/carapace/autoreview@sha256:8d92cf5decaf57d8Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_vyzidobthq6rc3tt)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260712.9f26ffc latest | 2026-07-12 | 9f26ffc | 31,876 B | A | view · diff |
| git:20260711.f4206ab | 2026-07-11 | f4206ab | 30,337 B | A | view · diff |
| git:20260709.047fab3 | 2026-07-09 | 047fab3 | 29,863 B | B | view · diff |
| git:20260709.12f5a78 | 2026-07-09 | 12f5a78 | 29,645 B | B | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (31876 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
openclaw/carapace · 6 stars · license MIT · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_vyzidobthq6rc3tt GET https://markdownregistry.com/api/v1/resolve?ref=openclaw/carapace/autoreview GET https://markdownregistry.com/api/v1/blob/8d92cf5decaf57d8c934118e93cc484055c37e97b8537fc3d105893a6b975c2f
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.
More from openclaw/carapace
Every file in openclaw/carapace