2026-10-11 16:37 UTC

Codacy claims its released Analysis CLI and Code Review skills let coding agents scan and fix working-tree issues locally against repository rules, moving static-analysis remediation ahead of commits and reducing pull-request feedback round trips.

state: seedheat: mediumuncertainty: mediumconvergesscott: mediumcoding-agents agent-harnesses developer-toolsCodacyAlejandro Rizzo

What is this?

Codacy has introduced Skills that let coding assistants invoke its analysis and review tooling: its launch snippets describe an Analysis CLI Skill for scanning and fixing code locally before committing, and a separate Code Review Skill for reviewing open pull requests. The documentation says the current Analysis CLI detects the repository’s stack and runs analyzers locally, with optional uploads; authenticated remote configuration can align local checks with Codacy’s pull-request rules. This supports the proposed shift toward pre-commit remediation, but the snippets do not establish measured reductions in feedback round trips, explicitly confirm account-free scanning, or establish Alejandro Rizzo’s role; local analysis also existed in a legacy CLI, so that capability alone is not new.

Why it matters to Scott

Codacy’s agent-callable local analysis converges with Scott’s Superlever architecture, where Codex edits a bounded worktree and deterministic code validates before publication, and offers a concrete tool to evaluate for earlier repair feedback. This is not evidence of an equivalent release gate or measured savings in PR round trips; the actionable addition is the Skills integration, not local static analysis itself.
dev:project.superleverdev:concept.validated-release-preview-boundary
queries asked of Scott's wikis
  • coding agent harness local verification repair loops
  • pre-commit quality gates versus pull request feedback latency
  • repository rules shared local CI enforcement
  • agent skills CLI integration deterministic analysis tools
  • AI generated code independent validation static analysis

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 674h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-13 14:00⭐ origin echo-reconstructedCodacy introduces local Analysis CLI and Code Review skills for coding agents; local scanning requires no account, while cloud-linked PR rev
Alejandro Rizzo, Codacy on blog (echo) · attributed from hn.story.49715638
—
09-15 17:15first on hacker news · published · +51.3hShow HN: Local static analysis for coding agents
claudiacsf
—
09-15 17:15amplified on hacker news 👑hn.story.49715638
claudiacsf
peak 1 · 0 comments · 106% of case engagement
09-15 17:23our radar first saw it · +51.4hdiscovery anchor: hn.story.49715638—
pace: p9 vs 1032 stories at the 336h mark (now 674h old) — behind addom-local-coding-harness (0.5x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Local static analysis for coding agents
Retrieved article excerpt

Open article · Retrieved 2026-09-15T17:26:10.291361+00:00

[Home](https://www.codacy.com/) [All Posts](https://blog.codacy.com) Introducing Codacy Skills (Part 4): Scan and fix your code before you push

[Codacy Platform](https://blog.codacy.com/tag/codacy-platform),
[New Features](https://blog.codacy.com/tag/new-features),
[AI in Software Engineering](https://blog.codacy.com/tag/ai-in-software-engineering),
[Codacy Skills](https://blog.codacy.com/tag/codacy-skills)

14/09/2026

# Introducing Codacy Skills (Part 4): Scan and fix your code before you push

Alejandro Rizzo

[Alejandro Rizzo](https://blog.codacy.com/author/alejandro-rizzo)

6 mins read

In this article:

Subscribe to our blog:

Codacy Skills teach coding agents like Claude Code to run Codacy from the terminal where the code is written: working findings, tuning rules, wiring up test coverage.

This is the final post in the series, and it covers the two skills that move the analysis loop itself onto your machine, at the two moments it pays off most. The Analysis CLI Skill scans and fixes your code before you commit, so your pull requests open without the issues Codacy would have flagged. The Code Review Skill works an open PR locally, so a red check gets cleared with a single push instead of a push per round trip. The first half of this post needs no Codacy account.

#### TL;DR

- The Analysis CLI Skill scans and fixes your code locally, before you commit
- The Code Review Skill reviews an open PR against everything the gate checks
- Fixes happen on your machine, so PRs open clean and red checks clear in a single push

  

## **Scan and fix before you commit**

You have finished a change. Before it goes anywhere, hand it to your agent:

*"Scan my changes with Codacy and fix what it finds before I commit."*

The agent runs Codacy's static analysis on your machine, reads the results, and makes the fixes, covering quality issues and security findings alike, on the code as it sits in your working tree. The findings that would have shown up on your pull request an hour later get fixed before the pull request exists. Your PRs open with zero new issues from the tools you run locally.

Under the hood, the skill runs the [Codacy Analysis CLI,](https://docs.codacy.com/codacy-analysis-cli/) which detects the languages in your repo and picks the matching tools: Trivy, Opengrep, Checkov, ESLint and more. Analysis runs on the whole repo, or scoped to whatever slice you ask for: specific files, your staged changes, your branch, an open pull request. If your team is already on Codacy, the CLI can sync the repo's ruleset, so the local scan checks against the same standards that your merge gate enforces. And everything the skill does, you can also run yourself directly from the Analysis CLI, with no agent involved.

The install has no login step:

npm i -g @codacy/analysis-cli

Next, install the plugin:

claude plugin marketplace add codacy/codacy-skills  
claude plugin install codacy-skills@codacy

The skills work with Claude Code, OpenAI Codex, GitHub Copilot, and others through the Agent Skills standard. You can do all of this right now, without creating a Codacy account.

## **Work a red PR locally, push once**

Your pull request came back red. Instead of reading findings in the open PR or on codacy.com and fixing them one push at a time, you ask:

*"Review pull request 42 with Codacy."*

Back comes one structured review: the quality gate status, new issues combined from the local scan and Codacy's cloud analysis, with critical and high flagged as blockers, the coverage delta and the new code your tests miss, whether the change matches the ticket and the PR description, and proposed test scenarios. One summary where that used to be a walk across tabs.

From there, the agent fixes the real findings on your machine and can dismiss the false positives with a logged reason, and everything travels together. One push, then the gate re-runs. Where [Part 1](https://blog.codacy.com/introducing-codacy-skills-unblock-pull-requests-with-one-prompt) had the cloud re-run the analysis after each fix, this loop runs on your machine.

Coverage criteria still need your CI to run the tests and upload the report (read [Part 3](https://blog.codacy.com/introducing-codacy-skills-part-3-let-your-agent-set-up-test-coverage) on setting up coverage reporting), so the local loop covers the analysis side of the gate. And this half needs a Codacy account.

If you followed Parts 1 to 3, you already have everything: the Code Review Skill uses the Analysis CLI together with the Cloud CLI, and one login covers both. If not, two commands close the gap:

npm install -g @codacy/codacy-cloud-cli  
codacy login

## What the four skills add up to

[Part 1](https://blog.codacy.com/introducing-codacy-skills-unblock-pull-requests-with-one-prompt) gave your agent Codacy's findings and the controls to unblock a pull request from the terminal.

[Part 2](https://blog.codacy.com/introducing-codacy-skills-part-2-configure-your-rules-to-cut-pr-noise) auto-tuned your rules to cut false positives at the source.

[Part 3](https://blog.codacy.com/introducing-codacy-skills-part-3-let-your-agent-set-up-test-coverage) set up coverage reporting and merge gates.

Part 4 (this post) moves the loop onto your machine: issues get fixed where the code is written, and the cloud check becomes a confirmation rather than the place you discover problems. Together the four skills cover a change's whole path, from first edit to merged pull request, in the surface where the code is now written.

## Try it for yourself

Install [Codacy Skills](https://docs.codacy.com/codacy-skills/) and put your agent to work. If you don't have a Codacy account, start with the [Codacy Analysis CLI](https://docs.codacy.com/codacy-analysis-cli/) and sign up when you want the full PR review, quality gates and coverage included.

## Try it for yourself

Install Codacy Skills and put your agent to work

[Get Codacy Skills](https://docs.codacy.com/codacy-skills/)

######
claudiacsf10
🟧 echo.blog ⭐Codacy introduces local Analysis CLI and Code Review skills for coding agents; local scanning requires no account, while cloud-linked PR revAlejandro Rizzo, Codacy——

Interpretation history

Decision trace