code-quality-guardian代码质量检测器 - 检测代码异味、复杂度、安全漏洞、风格规范等 | Code Quality Guardian - Detect code smells, complexity, security vulnerabilities and style issues
Install via ClawdBot CLI:
clawdbot install kaiyuelv/code-quality-guardianGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
Report → https://github.com/clawhub/code-quality-guardian/issuesPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://github.com/kaiyuelv/code-quality-guardianAudited Apr 17, 2026 · audit v1.0
Generated Aug 17, 2026
In a CI/CD pipeline, code quality guardian runs automatically on every pull request, checking for code smells, complexity, security vulnerabilities, and style issues. If the fail-on threshold is met, the build fails, preventing poor quality code from merging.
Developers integrate the tool as a pre-commit hook. Before each commit, it scans the changed files and provides immediate feedback on issues, helping developers fix problems before they reach the codebase.
A team uses the tool to assess a legacy project's maintainability and complexity. By generating reports, they identify high-risk modules needing refactoring and prioritize improvements based on issue severity.
For regulated industries, the tool scans Python/JS/Go code for known security vulnerabilities using Bandit and other tools. This ensures code meets security standards before deployment, aiding compliance with audits.
The tool is open-source, but offers paid enterprise support, custom rule development, and dedicated integrations. Revenue comes from support subscriptions and consulting services.
Offer the tool as a cloud-based service that integrates with GitHub/GitLab. Users pay a monthly fee based on the number of repos and analysis runs.
Provide a free version with basic analysis, and charge for advanced features like multi-language support, complex report formats, and priority execution.
💬 Integration Tip
Start with default configuration and integrate into CI pipeline via the provided GitHub Action. Adjust thresholds and ignore patterns based on your project's needs.
Scored Jun 29, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...