codex-review

A command that asks Codex to examine current code changes as a second reviewer.

In plain words
What is it for?
Reviewing uncommitted work, differences from a branch, or the changes introduced by a specific commit.
Why use it?
It helps find issues that the original author may have missed, including changes in new untracked files.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/arystos/skill-codex/codex-review
Clone the repo
git clone --depth 1 https://github.com/Arystos/skill-codex
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 845 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00845
Opus 5 $0.00000 $0.00423
Sonnet 5 $0.00000 $0.00169
Haiku 4.5 $0.00000 $0.00085

Measured 2d ago against content hash b202bc0489b3, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

codex-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

commands/codex-review.md · 47 lines

How it starts

The opening of the file, as written. The whole thing — 47 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Codex Code Review

Review the current changes using Codex as a second reviewer.

Instructions

You are invoking Codex for a second-opinion code review. Follow these steps:

  1. Determine what to review based on $ARGUMENTS:

    • If empty or "uncommitted": first run git status --short to see ALL changes, including new untracked files (lines starting with ??). Collect tracked modifications via git diff and staged changes via git diff --cached, and include the full contents of any new untracked files — read them directly, or use git diff --no-index -- /dev/null <file>. Plain git diff is blind to untracked files, so a review that skips this step will miss brand-new files entirely. If there are no changes at all, inform the user and stop.
    • If it looks like a branch name: get changes via git diff <branch>...HEAD
    • If it looks like a commit SHA: get changes via git show <sha>
  2. Check the diff size:

    • If the diff is empty, tell the user and stop.
    • If the diff exceeds 50,000 characters, summarize it first and warn that Codex will see a truncated version.
  3. Call the codex_exec MCP tool with:

    • prompt: "Review the following code changes. For each finding, specify: severity (CRITICAL/HIGH/MEDIUM/LOW), file and line, description, and suggested fix.\n\nFocus on: bugs, security issues, performance problems, error handling gaps, and readability.\n\ndiff\n<the diff>\n"
    • mode: "exec"
    • requireGit: true

    Option B (native Codex review): Default to the Claude-assembled diff above, since the user prefers Claude-led review. You may instead call codex_exec with review: true to use codex exec review; add reviewBase for a branch or reviewCommit for a SHA. The prompt is optional focus instructions.

  4. Assign an overall verdict from the findings (you are the final judge — weigh Codex's findings, don't just echo them):

    • BLOCKED — one or more CRITICAL/HIGH issues that should be fixed before merge
    • WARNING — only MEDIUM/LOW issues; safe to proceed with awareness
    • APPROVED — no substantive issues State it explicitly, e.g. Verdict: BLOCKED — 2 CRITICAL, 1 MEDIUM.

Read the full file on GitHub · 47 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 47 lines · 0 tokens per session scan A b202bc0489b3

Subscribe to this mod's changes

codex-review is a command published in the GitHub repository Arystos/skill-codex (5 stars, last pushed 1mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 845 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.