惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Recorded Future
Recorded Future
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
S
SegmentFault 最新的问题
博客园 - 司徒正美
Last Week in AI
Last Week in AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
云风的 BLOG
云风的 BLOG
雷峰网
雷峰网
博客园 - 叶小钗
The GitHub Blog
The GitHub Blog
MyScale Blog
MyScale Blog
腾讯CDC
博客园 - 聂微东
D
DataBreaches.Net
博客园 - Franky
人人都是产品经理
人人都是产品经理
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 【当耐特】
量子位
宝玉的分享
宝玉的分享
D
Docker
T
Tailwind CSS Blog
IT之家
IT之家
Engineering at Meta
Engineering at Meta
P
Proofpoint News Feed
C
CERT Recently Published Vulnerability Notes
Scott Helme
Scott Helme
Project Zero
Project Zero
Microsoft Azure Blog
Microsoft Azure Blog
AWS News Blog
AWS News Blog
Google DeepMind News
Google DeepMind News
H
Heimdal Security Blog
W
WeLiveSecurity
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
有赞技术团队
有赞技术团队
Simon Willison's Weblog
Simon Willison's Weblog
NISL@THU
NISL@THU
C
Cybersecurity and Infrastructure Security Agency CISA
Google DeepMind News
Google DeepMind News
T
Threatpost
TaoSecurity Blog
TaoSecurity Blog
N
News and Events Feed by Topic
aimingoo的专栏
aimingoo的专栏
Recent Commits to openclaw:main
Recent Commits to openclaw:main
www.infosecurity-magazine.com
www.infosecurity-magazine.com
SecWiki News
SecWiki News
S
Securelist

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4 test: trim doctor command hotspots · openclaw/openclaw@c66f16a test: isolate agent auth and spawn hotspots · openclaw/openclaw@9285935 test: stabilize MCP startup disposal race · openclaw/openclaw@dd9d2eb test: merge browser contract server suites · openclaw/openclaw@5817a76 test: narrow ollama provider discovery setup · openclaw/openclaw@a0d9598 build: declare qa-lab aimock runtime dependency · openclaw/openclaw@24431e5 test: speed up safe-bins exec harness · openclaw/openclaw@ee856ab test: preserve tool helpers in embedded runner mocks · openclaw/openclaw@acd86a0 refactor: move memory embeddings into provider plugins · openclaw/openclaw@77e6e4c test: reuse system-run temp fixtures · openclaw/openclaw@7e9ff0f test: trim hotspot wait overhead · openclaw/openclaw@12a59b0 Check: avoid duplicate boundary prep · openclaw/openclaw@baf11b8 test: reduce hotspot fixture overhead · openclaw/openclaw@3a59edd feat(ui): overhaul settings and slash command UX (#67819) thanks @Bun… · openclaw/openclaw@2cfb660 QA Matrix: exit cleanly on failure · openclaw/openclaw@42805d2 QA Matrix: isolate scenario coverage · openclaw/openclaw@7e659e1 Matrix: refresh crypto bootstrap state · openclaw/openclaw@94081d8 QA Lab: add provider registry · openclaw/openclaw@bb7e982 Matrix: add plugin changelog · openclaw/openclaw@4acab55 test: trim more hotspot overhead · openclaw/openclaw@f485311 test: trim remaining hotspot tests · openclaw/openclaw@6ba8626 test: narrow hotspot mocks · openclaw/openclaw@dbc8179 test: isolate gemini embedding request helpers · openclaw/openclaw@cd330f5 test: trim memory and mcp hotspots · openclaw/openclaw@fd48dfa test: slim provider registry mocks · openclaw/openclaw@2e08c77 test: harden Parallels update smoke · openclaw/openclaw@1a98090 feat: default Anthropic to Opus 4.7 · openclaw/openclaw@628b454 fix: harden node-host shell payload mutability checks · openclaw/openclaw@75c551e fix: land node-host approval binding for native binaries (#66731) (th… · openclaw/openclaw@29919bb CI: add daily schedule to CodeQL workflow (#67645) · openclaw/openclaw@69d25f5 fix(gateway): capture config hash after plugin auto-enable to prevent… · openclaw/openclaw@8c11210 fix: repair sanitized replay tool results before send (#67620) (thank… · openclaw/openclaw@c3c7a99 fix: restrict HTML timeout short-circuit to transient statuses · openclaw/openclaw@de129a6 fix: keep TUI watchdog bound to active run (#67401) (thanks @xantorres) · openclaw/openclaw@3525273 Gateway/skills: dedupe skills prefix-match + drop dead fallback on log · openclaw/openclaw@d7f489f Extensions/lmstudio: back off inference preload after consecutive fai… · openclaw/openclaw@b555214 TUI/streaming: add watchdog that resets the activity indicator after … · openclaw/openclaw@f44ab20 Agents/tool-loop: enable unknown-tool stream guard by default · openclaw/openclaw@36ed367 Gateway/skills: invalidate session skills snapshot on config write · openclaw/openclaw@b23d59a fix: classify HTML provider error pages correctly (#67642) (thanks @s… · openclaw/openclaw@e588e90 fix(skills): remove unused model-usage import (#67641) · openclaw/openclaw@55f05df docs(changelog): credit codex fix superseded PRs · openclaw/openclaw@e485f24 fix(openai-codex): normalize stale transport metadata in resolution a… · openclaw/openclaw@90801ba CI: pin Docker-related GitHub Actions (#67632) · openclaw/openclaw@f697b01 Android: modernize WebView and discovery API usage (#67627) · openclaw/openclaw@44a6e50 fix(deps): bump hono to 4.12.14 and @hono/node-server to 1.19.14 (GHS… · openclaw/openclaw@fbccc18 fix(deps): bump dompurify to 3.4.0 (#67614) · openclaw/openclaw@2c2dc00 CI: add explicit permissions to all workflow jobs (fixes code-scannin… · openclaw/openclaw@01b7516 fix: register bundled TTS providers and route overrides correctly (#6… · openclaw/openclaw@6ea3cdd fix: align host tilde paths with OS home (#62804) (thanks @stainlu) · openclaw/openclaw@ecfaf64 fix: flush creds queue before reconnect socket open (#67464) (thanks … · openclaw/openclaw@405c63f fix: strip standalone <function> tool call tags from visible text (#6… · openclaw/openclaw@78df859 fix(agents): preserve cli session metadata before transcript persist … · openclaw/openclaw@898fd04 docs(changelog): move cli transcript entry · openclaw/openclaw@c1817c6 fix(agents): normalize cli transcript api field · openclaw/openclaw@3a3fae0 docs(changelog): note cli transcript persistence · openclaw/openclaw@6c343f1 fix(agents): persist cli transcript turns · openclaw/openclaw@b8ef507 fix(msteams): harden security-sensitive flows (#65841) · openclaw/openclaw@c56b56e [Dashboard] Fix exec approval modal overflow for long command content… · openclaw/openclaw@053c5b0 Docs: remove QA changelog entry · openclaw/openclaw@7fd5771 QA: fix private runtime source loading (#67428) · openclaw/openclaw@d5933af docs(gateway): correct protocol.md schema path, hello-ok example, aut… · openclaw/openclaw@489404d CI: pin Node 22 runners to 22.18.0 · openclaw/openclaw@4ffa621 models.authStatus: normalize provider ids + tighten env-backed escape… · openclaw/openclaw@f2fdb9d Update CHANGELOG.md · openclaw/openclaw@7694a92 test(parallels): clean up npm update guard jobs · openclaw/openclaw@045ea7b Plugins: prefer scanDir override paths · openclaw/openclaw@b2974da fix(dreaming): default storage.mode to "separate" so phase blocks sto… · openclaw/openclaw@8c392f0 fix(memory-core): skip dreaming transcript ingestion via session stor… · openclaw/openclaw@a1b01f0 fix: dedupe replayed exec.finished node events (#67281) · openclaw/openclaw@5dcf526
feat: update autoreview skill · openclaw/openclaw@88ad5cb
steipete · 2026-05-22 · via Recent Commits to openclaw:main

@@ -1,16 +1,16 @@

11

---

22

name: autoreview

3-

description: "Autoreview closeout: local dirty changes, PR branch vs main, parallel tests."

3+

description: "Auto Review closeout. Codex review is the default when no engine is set and is the recommended reviewer."

44

---

556-

# Autoreview

6+

# Auto Review

778-

Run Codex's built-in code review as a closeout check. This is code review (`codex review`), not Guardian `auto_review` approval routing.

8+

Run the bundled structured review helper as a closeout check. This is code review, not Guardian `auto_review` approval routing.

9910-

Codex native review mode performs best and is recommended. Non-Codex reviewers are fallback/second-opinion paths that receive a generated diff prompt, not the full Codex review-mode runtime.

10+

Codex review is the default when no engine is set. It usually delivers the best review results and should remain the normal final closeout engine.

11111212

Use when:

13-

- user asks for Codex review / autoreview / second-model review

13+

- user asks for Codex review / Claude review / autoreview / second-model review

1414

- after non-trivial code edits, before final/commit/ship

1515

- reviewing a local branch or PR branch after fixes

1616

@@ -21,60 +21,63 @@ Use when:

2121

- Read dependency docs/source/types when the finding depends on external behavior.

2222

- Reject unrealistic edge cases, speculative risks, broad rewrites, and fixes that over-complicate the codebase.

2323

- Prefer small fixes at the right ownership boundary; no refactor unless it clearly improves the bug class.

24-

- Keep going until the selected review path returns no accepted/actionable findings.

25-

- If a review-triggered fix changes code, rerun focused tests and rerun the review helper.

26-

- Default to Codex review with no fallback. Prefer Codex for final closeout because it uses native review mode; non-Codex reviewers use a Codex-inspired generated diff prompt. Use `--fallback-reviewer auto|claude|pi|opencode|droid|copilot` only when a second-model fallback is explicitly wanted and authenticated. The helper runs nested Codex review in yolo/full-access mode by default; use `--no-yolo` only when intentionally testing sandbox behavior.

27-

- Stop as soon as the review command/helper exits 0 with no accepted/actionable findings. Do not run an extra direct `codex review` just to get a nicer "clean" line, a second opinion, or clearer closeout wording.

24+

- Keep going until structured review returns no accepted/actionable findings.

25+

- If a review-triggered fix changes code, rerun focused tests and rerun the structured review helper.

26+

- For security-audit suppression changes, verify accepted findings remain auditable: suppressed findings stay in structured output, active output keeps an unsuppressible suppression notice, and aggregate findings cannot hide unrelated active risk.

27+

- Never switch or override the requested review engine/model. If the review hits model capacity, retry the same command a few times with the same engine/model.

28+

- Tools are useful in review mode. The helper allows read-only inspection tools and web search by default so reviewers can check dependency contracts, upstream docs, and current behavior.

29+

- Security perspective is always included, but it should not cripple legitimate functionality. Report security findings only when the change creates a concrete, actionable risk or removes an important safety check.

30+

- Do not invoke built-in `codex review`, nested reviewers, or reviewer panels from inside the review. The helper builds one bundle, calls one selected engine, validates one structured result, and stops.

31+

- Stop as soon as the helper exits 0 with no accepted/actionable findings. Do not run an extra review just to get a nicer "clean" line, a second opinion, or clearer closeout wording.

2832

- Treat the helper's successful exit plus absence of actionable findings as the clean review result, even if the underlying Codex CLI output is terse.

2933

- If rejecting a finding as intentional/not worth fixing, add a brief inline code comment only when it explains a real invariant or ownership decision that future reviewers should know.

30-

- If creating or updating a PR while rejecting any autoreview finding, record the rejected finding and reason in the PR description so later reviewers can distinguish intentional design decisions from missed review output.

34+

- If `gh`/Gitcrawl reports `database disk image is malformed`, run `gitcrawl doctor --json` once to let the portable cache repair before retrying review; do not bypass the shim unless repair fails and freshness requires live GitHub.

35+

- If Gitcrawl reports a portable manifest mismatch, source/runtime DB health error, or stale portable-store checkout, run `gitcrawl doctor --json` and inspect `source_db_health`, `runtime_db_health`, and `portable_store_status` before falling back to live GitHub.

3136

- Do not push just to review. Push only when the user requested push/ship/PR update.

32-

- For OpenClaw maintainers, keep autoreview validation Crabbox/Testbox-aware when maintainer validation mode is enabled (`OPENCLAW_TESTBOX=1` or `AUTOREVIEW_OPENCLAW_MAINTAINER_VALIDATION=1`). A review pass may inspect files and run cheap non-Node probes, but it must not start local `pnpm`, Vitest, `tsgo`, `npm test`, or `node scripts/run-vitest.mjs` from a Codex/worktree review unless the operator explicitly requested local proof. For runtime proof, use existing evidence or route through Crabbox/Testbox and report the id. Do not apply this rule to ordinary contributors who do not have maintainer Testbox access.

33373438

## Pick Target

35393640

Dirty local work:

37413842

```bash

39-

codex review --uncommitted

43+

<autoreview-helper> --mode local

4044

```

41454246

Use this only when the patch is actually unstaged/staged/untracked in the

43-

current checkout. For committed, pushed, or PR work, point Codex at the commit

47+

current checkout. For committed, pushed, or PR work, point the helper at the commit

4448

or branch diff instead; do not force `--mode local` / `--uncommitted` just

45-

because the helper docs mention dirty work first. A clean `--uncommitted` review

49+

because the helper docs mention dirty work first. A clean local review

4650

only proves there is no local patch.

47514852

Branch/PR work:

49535054

```bash

51-

git fetch origin

52-

codex review --base origin/main

55+

<autoreview-helper> --mode branch --base origin/main

5356

```

545755-

Do not pass any prompt with `--base`, `--commit`, or `--uncommitted`. Codex CLI

56-

review targets and custom review prompts are mutually exclusive: target modes

57-

generate their own review prompt internally. Use plain target review for native

58-

Codex closeout, or use custom prompt review (`codex review -`) only when you

59-

intentionally want a generated diff prompt instead of native target review.

58+

Optional review context is first-class:

59+60+

```bash

61+

<autoreview-helper> --mode branch --base origin/main --prompt-file /tmp/review-notes.md --dataset /tmp/evidence.json

62+

```

60636164

If an open PR exists, use its actual base:

62656366

```bash

6467

base=$(gh pr view --json baseRefName --jq .baseRefName)

65-

codex review --base "origin/$base"

68+

<autoreview-helper> --mode branch --base "origin/$base"

6669

```

67706871

Committed single change:

69727073

```bash

71-

codex review --commit HEAD

74+

<autoreview-helper> --mode commit --commit HEAD

7275

```

73767477

or with the helper:

75787679

```bash

77-

.agents/skills/autoreview/scripts/autoreview --mode commit --commit HEAD

80+

/Users/steipete/Projects/agent-scripts/skills/autoreview/scripts/autoreview --mode commit --commit HEAD

7881

```

79828083

Use commit review for already-landed or already-pushed work on `main`. Reviewing

@@ -87,46 +90,53 @@ with `--base`.

8790

Format first if formatting can change line locations. Then it is OK to run tests and review in parallel:

88918992

```bash

90-

.agents/skills/autoreview/scripts/autoreview --parallel-tests "<focused test command>"

93+

scripts/autoreview --parallel-tests "<focused test command>"

9194

```

92959396

Tradeoff: tests may force code changes that stale the review. If tests or review lead to code edits, rerun the affected tests and rerun review until no accepted/actionable findings remain. Once that rerun exits cleanly, stop; do not spend another long review cycle on redundant confirmation.

94979598

## Context Efficiency

969997-

Codex review is usually noisy. Default to a subagent filter when subagents are available. Ask it to run the review and return only:

98-

- actionable findings it accepts

99-

- findings it rejects, with one-line reason

100-

- exact files/tests to rerun

101-102-

Run inline only for tiny changes or when subagents are unavailable.

100+

Run the helper directly so target selection, engine choice, structured validation, and exit status all stay in one path. If output is noisy, summarize the completed helper output after it returns; do not ask another agent or reviewer to rerun the review.

103101104102

## Helper

105103106-

Bundled helper:

104+

OpenClaw repo-local helper:

107105108106

```bash

109107

.agents/skills/autoreview/scripts/autoreview --help

110108

```

111109110+

`agent-scripts` checkout helper:

111+112+

```bash

113+

skills/autoreview/scripts/autoreview --help

114+

```

115+116+

Global helper from `agent-scripts`:

117+118+

```bash

119+

~/.codex/skills/agent-scripts/autoreview/scripts/autoreview --help

120+

```

121+122+

If installed from `agent-scripts`, path is:

123+124+

```bash

125+

/Users/steipete/Projects/agent-scripts/skills/autoreview/scripts/autoreview --help

126+

```

127+112128

The helper:

113-

- chooses dirty `--uncommitted` first

129+

- chooses dirty local changes first

114130

- otherwise uses current PR base if `gh pr view` works

115131

- otherwise uses `origin/main` for non-main branches

116-

- auto-runs `PNPM_CONFIG_PM_ON_FAIL=ignore PNPM_CONFIG_VERIFY_DEPS_BEFORE_RUN=false PNPM_CONFIG_OFFLINE=true pnpm run check` in parallel when a repo has `package.json`, `pnpm-lock.yaml`, `node_modules`, and a `check` script; disable with `AUTOREVIEW_AUTO_TESTS=0`

132+

- supports `--engine codex` and `--engine claude`; default is `AUTOREVIEW_ENGINE` or `codex`; Codex should remain the default when nothing is set

117133

- use `--mode commit --commit <ref>` for already-committed work, especially clean `main` after landing

118134

- should be left in `--mode auto` or forced to `--mode branch` for PR/branch work; do not force `--mode local` after committing

119-

- supports `--reviewer codex|claude|pi|opencode|droid|copilot|auto`; `auto` means Codex first

120-

- supports `--fallback-reviewer auto|claude|pi|opencode|droid|copilot|none`; default is `none`

121-

- falls back only when Codex is unavailable or exits nonzero, not when Codex reports findings

122-

- writes only to stdout unless `--output` or `AUTOREVIEW_OUTPUT` is set

123-

- supports `--dry-run`, `--parallel-tests`, and commit refs

124-

- runs nested review with `--dangerously-bypass-approvals-and-sandbox --sandbox danger-full-access` by default

125-

- with `OPENCLAW_TESTBOX=1` or `AUTOREVIEW_OPENCLAW_MAINTAINER_VALIDATION=1`, disables auto local `pnpm run check` and routes Codex through generated prompt review (`codex review -`) so the no-local-heavy-tests policy is included; native Codex target review cannot accept extra prompt text

126-

- non-Codex reviewers receive the generated diff prompt and maintainer validation policy text when maintainer validation is active

127-

- keeps accepting `--full-access`; use `--no-yolo` or `AUTOREVIEW_YOLO=0` to opt out

128-

- still accepts legacy `CODEX_REVIEW_*` env vars when the matching `AUTOREVIEW_*` var is unset

135+

- writes only to stdout unless `--output` or `--json-output` is set

136+

- supports `--dry-run`, `--parallel-tests`, `--prompt`, `--prompt-file`, `--dataset`, `--no-tools`, `--no-web-search`, and commit refs

137+

- allows read-only tools and web search by default; forbids nested review in the prompt; Codex is run through `codex exec` with read-only sandbox and structured output

129138

- prints `autoreview clean: no accepted/actionable findings reported` when the selected review command exits 0

139+

- exits nonzero when accepted/actionable findings are present

130140131141

## Final Report

132142

@@ -136,11 +146,4 @@ Include:

136146

- findings accepted/rejected, briefly why

137147

- the clean review result from the final helper/review run, or why a remaining finding was consciously rejected

138148139-

Do not run another Codex review solely to improve the final report wording. If the final helper run exited 0 and produced no accepted/actionable findings, report that exact run as clean.

140-141-

## PR / CI Closeout

142-143-

- Prefer direct run/job APIs after CI starts: `gh run view <run-id> --json jobs`; use PR rollup only for final mergeability.

144-

- After rebase, compare `origin/main..HEAD`; drop CI-fix commits already upstream before pushing.

145-

- For prompt snapshot CI failures, prove/generate with Linux Node 24 before rerunning the failed job.

146-

- Update PR body once near the final head unless proof labels are missing or stale enough to block CI.

149+

Do not run another review solely to improve the final report wording. If the final helper run exited 0 and produced no accepted/actionable findings, report that exact run as clean.