Library / SDK
openclaw/clawpatch avatar
openclaw/clawpatch

clawpatch turns your coding agent into a review-by-feature machine with receipts

Review code. Patch bugs. Land PRs.

814 stars121 forksTypeScriptMIT

At a glance

What is it?
The openclaw project maps a repository into semantic feature slices, has an installed agent review each slice, and keeps evidence-backed findings until a patch lands and revalidates.
Who is it for?
clawpatch earns its place by making agent review a pipeline instead of a chat. Feature-sliced mapping, persisted evidence-backed findings, one patch attempt per finding with validation, git-guarded revalidation, and a separate PR step give maintainers something rare: a review trail they can resume, audit, and diff across agents.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What clawpatch does

clawpatch, from the openclaw organization, sits in a gap that plain agent sessions leave open. It maps a repository into semantic feature slices, asks an installed coding agent to review each slice, and stores evidence-backed findings for later repair. Review, patching, and revalidation stay explicit and resumable: findings and run records persist under .clawpatch/ in the project, so interrupted work continues instead of starting over.

It is an npm package (clawpatch) requiring Node.js 22 or newer, MIT licensed, with a website at clawpatch.ai. The positioning line in the README is accurate: review by feature, fix by finding. Nothing in the tool calls a model API directly; it drives agents you already have installed, which keeps credentials and model transport with the harness you chose.

Install and first run

Install globally with pnpm or npm:

bash
pnpm add -g clawpatch

Then start inside a Git repository:

bash
cd /path/to/repository
clawpatch init
clawpatch map
clawpatch status

Initialization creates project-local state under .clawpatch/ and the default mapper inspects repository structure without calling a model, so map is fast and deterministic. With a supported coding agent installed and authenticated, the first real pass looks like this:

bash
clawpatch doctor
clawpatch review --limit 3
clawpatch report

doctor verifies the agent setup, review runs bounded parallel reviews, and report assembles the findings. Review progress goes to stderr while machine-readable results stay on stdout for --json commands, which makes the whole thing scriptable.

A workflow with named stages

The command set maps one-to-one onto the review lifecycle, and the README presents it as a table. init detects the project and writes configuration. map creates durable semantic feature records. review runs bounded, parallel reviews and persists findings. next, show, and report prioritize and examine evidence. fix applies one explicit patch attempt per finding ID and runs configured validation. revalidate re-checks a finding against the current code. open-pr commits the recorded patch files, pushes a branch, and opens a pull request.

That staging matters because it separates concerns that agent sessions usually blur. The finding is recorded before any fix is attempted. The fix is recorded before any commit is made. The commit happens only through open-pr, which is a separate command. Each step produces artifacts the next step consumes, which is what makes the process resumable after interruption and auditable after the fact.

Feature mapping across languages

The mapper detects reviewable boundaries across Node.js and TypeScript, Python, Ruby, PHP, Go, Rust, C and C++, Java and Kotlin, .NET, and Swift projects. It uses manifests, framework conventions, routes, packages, targets, tests, and nearby context to find the seams, and it skips generated directories and symlinked directories by default.

Mapping is deterministic unless you ask otherwise. The --source auto and --source agent options can add provider-assisted slices when a repository needs deeper interpretation, but the default path never touches a model. For CI-sized repositories that distinction is practical: a deterministic map of ten thousand files runs in seconds and costs nothing, and you spend agent budget only on the slices worth reviewing.

Providers: the agent is pluggable

The default provider is the local Codex CLI. Clawpatch also integrates ACP-compatible agents through ACPX and ships adapters for Claude Code, Grok Build, OpenCode, Pi, and an experimental Cursor Agent path. Because clawpatch does not call model APIs itself, authentication, model transport, and agent execution remain with the selected harness, and docs/providers.md covers setup, model selection, permissions, and isolation per provider.

This design ages well. When a new agent CLI appears, it becomes an adapter rather than a new integration surface inside clawpatch. It also means the same review run can compare providers: map once, review the same slices through two different agents, and diff the findings, since every finding is stored with its evidence rather than as prose in a chat transcript that evaporates.

Safety rails

The safety section of the README is short and strict. Review and revalidation request read-only provider execution. fix requires a finding ID, refuses a dirty source worktree by default, records the changed files and validation results, and does not commit or push. Creating a commit and pull request requires the separate open-pr command, and clawpatch never merges changes.

The one honest caveat the project makes is that provider sandboxes and tool restrictions differ, so it tells you to read docs/safety.md before using write-capable providers on untrusted code. That framing, where the tool constrains what it can and states clearly what it cannot, is what you want from anything that lets a model near your working tree.

CI mode and the v0.8.1 release

For pipelines there is a source-read-only loop:

bash
clawpatch ci --since origin/main --output clawpatch-report.md

That runs init, map, review, and report against a diff scope and writes a markdown report, without touching the working tree. Development-wise the project tests on Node.js 22, 24, and 26 with Vitest 5, and pnpm test:coverage produces V8 coverage with JSON and HTML reports.

The v0.8.1 release (2026-09-14) shows the kind of edge cases real usage surfaces: nested-project repairs now ignore their own state and sibling changes, fingerprint project-relative source paths, and record both sides of renames, and failed patch attempts keep the edits a provider already wrote instead of discarding them. That last change acknowledges reality: a failed attempt is still evidence for the next one.

Editorial conclusion

clawpatch earns its place by making agent review a pipeline instead of a chat. Feature-sliced mapping, persisted evidence-backed findings, one patch attempt per finding with validation, git-guarded revalidation, and a separate PR step give maintainers something rare: a review trail they can resume, audit, and diff across agents. If you already pay for a coding agent, running it over your codebase with clawpatch is the most productive use of that subscription.

Frequently asked questions

Does clawpatch need its own API key?

No. clawpatch never calls model APIs directly. It drives installed coding agents such as the Codex CLI, Claude Code, OpenCode, Grok Build, or ACP-compatible agents, so authentication, model transport, and agent execution stay with the harness you already set up.

Will clawpatch commit changes to my repository?

Not on its own. fix requires a finding ID, refuses a dirty worktree by default, and records changes without committing or pushing. Only the separate open-pr command creates a commit and pull request, and clawpatch never merges. Review and revalidation run read-only.

Which languages can clawpatch map into feature slices?

The mapper covers Node.js and TypeScript, Python, Ruby, PHP, Go, Rust, C and C++, Java and Kotlin, .NET, and Swift projects, using manifests, framework conventions, routes, packages, targets, tests, and nearby context. Generated and symlinked directories are skipped.

Official sources

  1. License: MIT
  2. openclaw/clawpatch on GitHub
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/openclaw-clawpatch.svg)](https://hysenlabs.com/projects/openclaw-clawpatch)