Codebase scan
Why scan your app?
OpenPush recommends useful journeys, templates, in-app messages, and segments from events and destinations your app already supports. The scan happens in your repository. You review a small JSON manifest before anything leaves your computer; OpenPush never receives your source code.
Install
Code
Run the skill
Run /openpush-scan in your app repository. The scanner inventories SDK calls, the program reviewer explains matches and asks what to share, the instrumenter offers local event-call edits you approve, and the documenter records the setup in OPENPUSH.md. Without parallel agents, the router performs the same steps sequentially.
Review what you share
| Category | Default | What OpenPush does with it |
|---|---|---|
platforms | Shared | Selects platform-specific programs and instrumentation snippets. |
sdk | Shared | Checks which OpenPush modules and version hints are already installed. |
app_version | Shared | Detects releases and keeps version-specific suggestions current. |
events | Shared | Matched against journey and in-app triggers; unhandled events become suggested follow-ups. |
event_property_keys | Shared | Shows which event properties can safely power filters and personalization. |
tags | Shared | Shows which user facts can safely power segments and personalization. |
tag_value_samples | Not shared | Provides example tag values for draft targeting; values remain optional. |
triggers | Shared | Matches in-app messages to trigger keys the app already sets. |
trigger_value_samples | Not shared | Provides example trigger values for draft rules; values remain optional. |
outcomes | Shared | Connects existing outcome names to measurable draft programs. |
aliases | Shared | Shows which external identity labels are already available for targeting. |
identity | Shared | Avoids suggesting identity-dependent programs when login is not integrated. |
deep_links | Shared | Limits draft calls to action to destinations the app declares. |
deep_links_full_urls | Not shared | Provides exact example destinations, with URL query strings removed. |
capabilities | Shared | Avoids suggesting channels and features the installed SDK cannot render. |
locales | Shared | Creates locale-aware drafts only for languages the app already ships. |
local_notifications | Shared | Shows reminder trigger kinds so push suggestions do not duplicate them. |
local_notification_copy | Not shared | Shares existing reminder copy as optional tone and overlap evidence. |
screens | Not shared | Provides app screen names and routes as optional journey evidence. |
strings | Not shared | Used only as tone and vocabulary examples when AI writes copy; never shown to other tenants. |
release_notes | Not shared | Becomes the text of a suggested What's-new in-app message for this version; nothing else. |
inferences | Shared | Adds closed category and lifecycle hints reviewed from local code context. |
goal | Shared | Ranks suggestions so the ones serving this moment come first. |
Never shared: file paths, source code, or anything matching a redaction rule. Dynamic calls the scanner cannot safely evaluate are counted, not guessed. Your selected goal controls ranking, not what can be sent.
Set a goal
Choose the moment to improve—such as onboarding, purchase, retention, or cart recovery—and optionally name its event. Suggestions serving the moment rank above generic ideas; those also binding the event rank first.
Upload
With MCP, the skill uses openpush_prepare_manifest, shows the exact diff and affected references, and waits before openpush_confirm_action. The REST fallback is PUT /v1/apps/{app}/manifest with a full-scope key. The manifest is capped at 512 KiB and rechecked for secrets server-side.
Read your suggestions
Open Suggestions. Every card names its evidence, goal rank, reach basis, and fireability. Creating one makes an editable draft only. Suggested journeys also appear under Journeys → New journey; in-app suggestions can be reusable templates.
Instrument missing events
OpenPush provides exact Swift, Kotlin, or C# snippets. The instrumenter changes only files you approve. Re-scan after the event ships; daily refresh marks the program ready once the event arrives.
Document your setup
Keep OPENPUSH.md in the repository. It records scanner commands, reviewed categories, goal, manifest version, and approved instrumentation without secrets.
CI check
Run openpush-scan ci. --on-version-change shares only for a new app version and performs the first share when no server manifest exists. Network failures return a concise non-zero result without a traceback.
FAQ
Does OpenPush see my code?
No. It receives only the reviewed manifest JSON. .openpush/scan-share.json stays local and is not uploaded.
Can the curator send anything?
No. Every rung stops at drafts. Auto mode is capped, budgeted, kill-switchable, and cannot schedule, activate, or send.