Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add cukas/claudes-ai-buddies/plugin install claudes-ai-buddiesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/cukas/claudes-ai-buddies/codex-review)<a href="https://agentmods.dev/skills/cukas/claudes-ai-buddies/codex-review"><img src="https://agentmods.dev/badge/skills/cukas/claudes-ai-buddies/codex-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/cukas/claudes-ai-buddies/codex-review"><img src="https://agentmods.dev/badge/skills/cukas/claudes-ai-buddies/codex-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00022 | $0.00761 |
| Opus 5 | $0.00011 | $0.00380 |
| Sonnet 5 | $0.00004 | $0.00152 |
| Haiku 4.5 | $0.00002 | $0.00076 |
Grade A, and why
codex-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 69 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/codex-review — Code Review via Codex
Get a code review from OpenAI's Codex CLI. Reviews uncommitted changes by default, or specify a branch or commit.
How to invoke
Run the wrapper script via Bash. IMPORTANT: Codex regularly takes 3-6 minutes for non-trivial tasks. You MUST set the Bash tool's timeout parameter to 420000 (7 minutes) to prevent Claude Code from killing the process before Codex finishes.
bash "${CLAUDE_PLUGIN_ROOT}/scripts/codex-run.sh" \
--prompt "Additional review instructions (optional)" \
--cwd "/path/to/repo" \
--mode review \
--review-target "uncommitted"
Then read the output file and present the review to the user.
Step-by-step workflow
- Determine what to review:
- No arguments → review uncommitted changes (
--review-target uncommitted) - User specifies a branch →
--review-target branch:branch-name - User specifies a commit →
--review-target commit:SHA
- No arguments → review uncommitted changes (
- Determine working directory. Must be inside a git repository.
- Build the prompt. The wrapper automatically fetches the diff and builds a review prompt. If the user provides extra instructions (e.g., "focus on security"), pass them as
--prompt. - Run codex-run.sh with
--mode reviewvia the Bash tool. - Read the output file using the Read tool.
- Present the review to the user. Frame it as "Codex's code review:" with clear sections.
- Add your own perspective if you see issues Codex missed, or agree with specific points.
Review targets
| Target | Flag | Example |
|---|---|---|
| Uncommitted changes | --review-target uncommitted |
/codex-review |
| Branch diff | --review-target branch:NAME |
/codex-review branch:feature/auth |
| Specific commit | --review-target commit:SHA |
/codex-review commit:abc1234 |
Options
| Flag | Default | Description |
|---|---|---|
--prompt |
"" |
Additional instructions for the review |
--cwd |
current dir | Path to the git repository |
--mode |
— | Must be review for this skill |
--review-target |
uncommitted |
What to review |
--timeout |
from config (360s) | Max seconds to wait |
--model |
from config | Override the Codex model |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 69 lines · 22 tokens per session scan A faa34b52948f
codex-review is a skill published in the GitHub repository cukas/claudes-ai-buddies (9 stars, last pushed 4mo ago), licensed MIT. It adds 22 tokens to every session and 761 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
gitnexus
A code-graph analysis add-on for examining an existing codebase, including symbols, call paths, execution flows, and effects across repositories. It can query GitNexus through its command-line or MCP interfaces.
review
5-pass structured code review — correctness, security, performance, readability, consistency.
critical-code-reviewer
Rigorously review code or pull requests for correctness, security, accessibility, maintainability, tests, and edge cases. Use when users request a critical code review, want a guided walkthrough of findings, need implementer-facing feedback, or want to prepare, create, or submit a GitHub pull request review.
brooks-sweep
Full-sweep mode: runs a unified analysis across all quality dimensions — code decay, architecture, tech debt, and test quality — then applies fixes directly to the codebase. Safe changes are auto-applied; risky changes are confirmed before execution. Drawing on twelve classic engineering books. Triggers when: user…
second-pass-review
Independent audit of sanitized specs in workspace/output/. Three parallel LLM-based reviewer roles check structural leakage, content contamination, and behavioral completeness. Run AFTER Layer 5 sanitization, BEFORE implementation handoff.
check-pr
Read-only inspection of a single GitHub PR lifecycle — checks CI, review threads, description sync, and mergeability, and returns PASS or FAIL with per-gate findings. Never invokes the merge button. Use when verifying a PR is ready to merge, polling lifecycle progress, checking mergeability, or babysitting a GitHub PR…