OpenClaw: 180K Stars.
2,080 Violations. Score: Zero.
We pointed Rigour at OpenClaw — 180k stars. acqui-hired by openai.. The scan took 3.9s. 2,080 violations across 2,094 files.
Quality Gate Results
Violation Breakdown
520 God Files
Over half a thousand files in the OpenClaw codebase exceed 400 lines. When a single file reaches 3,000+ lines, no human and no AI agent can reason about it effectively. This is how bugs hide. This is how security vulnerabilities survive code review.
Worst Offenders
docs/gateway/configuration-reference.md3,333 linesdocs/help/faq.md2,860 linesCHANGELOG.md2,198 linestests/security-audit.test.ts2,169 linestests/telegram-bot.test.ts1,899 lines1,819 Complexity Violations
Nearly two thousand functions in the codebase have cyclomatic complexity that exceeds safe thresholds. High complexity means more execution paths, more edge cases, more places for bugs to live. These are not in obscure utility files — they are in core modules: the agent runner, the gateway server, the browser automation layer, and the memory manager.
7 Prototype Pollution Vectors
Rigour flagged 7 instances of Object.assign({}, ...) patterns that can propagate prototype pollution — a well-known JavaScript security vulnerability. These are in sensitive areas: the memory/embeddings system, the cron agent runner, and the agent execution pipeline.
60 Abandoned TODOs
Sixty TODO and FIXME comments scattered across the codebase. Each one is a promise an AI agent made to itself and never kept. This is the signature of vibe coding at scale — optimizing for appearing done, not for being done.
147 Context Drift Issues
Import patterns mixing relative and absolute styles across 644 files. Environment variable naming that drifts from project conventions. These are the kind of inconsistencies that accumulate when multiple AI agents work on a codebase simultaneously without architectural guardrails.
This Is Not About OpenClaw.
What Steinberger built solo is extraordinary. And OpenClaw is open source — the code is there for anyone to improve.
This is about a pattern happening everywhere right now. AI coding agents ship code fast. They claim "done" while leaving behind complexity violations, God files, abandoned TODOs, and security patterns that would fail any serious code review. Tests might pass. The app might work. But the codebase is accumulating structural debt at a rate no human team can repay.
If the most popular AI agent in the world — with 180,000 stars and OpenAI's backing — scores zero on a basic quality audit, what does your vibe-coded project look like?
Try It On Your Repo.
Rigour is open source, local-first, and runs in under 4 seconds. Zero cloud. Zero telemetry. MIT licensed.
All data generated by running rigour check against the public OpenClaw repository on February 17, 2026. Full JSON report available on request.