Quality Audit Report

OpenClaw: 180K Stars.
2,080 Violations. Score: Zero.

We pointed Rigour at OpenClaw — 180k stars. acqui-hired by openai.. The scan took 3.9s. 2,080 violations across 2,094 files.

February 17, 2026| 2,094 Files Scanned| 14,010 Patterns| 3.9s
0/100
Rigour Score
FAIL
2,080
Total Violations
4 / 10
Gates Failed
520
God Files
1,819
Complexity Violations
7
Security Flags
147
Context Drift

Quality Gate Results

Environment Alignment
Retry Loop Breaker
File Size
Content Check
Structure Check
AST Analysis
Dependency Guardian
Safety Rail
Coverage Guard
Context Drift

Violation Breakdown

File SizeFiles exceeding 400 lines
520
AST ComplexityFunctions with cyclomatic complexity violations
1,819
Context DriftImport pattern & naming inconsistencies
147
Abandoned TODOsTODO/FIXME comments never resolved
60
Max ParamsFunctions with too many parameters
27
Max MethodsClasses with too many methods
19
Security: Prototype PollutionObject.assign patterns in sensitive areas
7

520 God Files

Over half a thousand files in the OpenClaw codebase exceed 400 lines. When a single file reaches 3,000+ lines, no human and no AI agent can reason about it effectively. This is how bugs hide. This is how security vulnerabilities survive code review.

Worst Offenders

docs/gateway/configuration-reference.md3,333 lines
docs/help/faq.md2,860 lines
CHANGELOG.md2,198 lines
tests/security-audit.test.ts2,169 lines
tests/telegram-bot.test.ts1,899 lines

1,819 Complexity Violations

Nearly two thousand functions in the codebase have cyclomatic complexity that exceeds safe thresholds. High complexity means more execution paths, more edge cases, more places for bugs to live. These are not in obscure utility files — they are in core modules: the agent runner, the gateway server, the browser automation layer, and the memory manager.

7 Prototype Pollution Vectors

Rigour flagged 7 instances of Object.assign({}, ...) patterns that can propagate prototype pollution — a well-known JavaScript security vulnerability. These are in sensitive areas: the memory/embeddings system, the cron agent runner, and the agent execution pipeline.

60 Abandoned TODOs

Sixty TODO and FIXME comments scattered across the codebase. Each one is a promise an AI agent made to itself and never kept. This is the signature of vibe coding at scale — optimizing for appearing done, not for being done.

147 Context Drift Issues

Import patterns mixing relative and absolute styles across 644 files. Environment variable naming that drifts from project conventions. These are the kind of inconsistencies that accumulate when multiple AI agents work on a codebase simultaneously without architectural guardrails.

This Is Not About OpenClaw.

What Steinberger built solo is extraordinary. And OpenClaw is open source — the code is there for anyone to improve.

This is about a pattern happening everywhere right now. AI coding agents ship code fast. They claim "done" while leaving behind complexity violations, God files, abandoned TODOs, and security patterns that would fail any serious code review. Tests might pass. The app might work. But the codebase is accumulating structural debt at a rate no human team can repay.

If the most popular AI agent in the world — with 180,000 stars and OpenAI's backing — scores zero on a basic quality audit, what does your vibe-coded project look like?

Try It On Your Repo.

Rigour is open source, local-first, and runs in under 4 seconds. Zero cloud. Zero telemetry. MIT licensed.

$ npx @rigour-labs/cli init
$ npx @rigour-labs/cli check

All data generated by running rigour check against the public OpenClaw repository on February 17, 2026. Full JSON report available on request.