code-review

code-review is a skill for Claude Code, Codex from Yeachan-Heo/oh-my-codex. It costs 8 tokens per session (1,275 once invoked), scanned A, original, MIT.

A workflow for examining code for problems and weaknesses.

In plain words
What is it for?
Use it when you need a broad review of a code change or codebase.
Why use it?
It helps identify issues that may be missed during ordinary development.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: mentions AGENTS.md; $skill-name invocation.

Good fit Use it when you need a broad review of a code change or codebase.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/yeachan-heo/oh-my-codex/code-review
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add Yeachan-Heo/oh-my-codex --skill code-review
Clone the repo
git clone --depth 1 https://github.com/Yeachan-Heo/oh-my-codex

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for code-review

README.md
[![agentmods](https://agentmods.dev/badge/skills/yeachan-heo/oh-my-codex/code-review.svg)](https://agentmods.dev/skills/yeachan-heo/oh-my-codex/code-review)
Your own site
<a href="https://agentmods.dev/skills/yeachan-heo/oh-my-codex/code-review"><img src="https://agentmods.dev/badge/skills/yeachan-heo/oh-my-codex/code-review.svg" alt="Measured on agentmods" height="20"></a>
Per session 8 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,275 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. ✓ AI security review Fable 5.1 · 6 Sept 2026 📄 Read the review Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00008 $0.01275
Opus 5 $0.00004 $0.00638
Sonnet 5 $0.00002 $0.00255
Haiku 4.5 $0.00001 $0.00128

Measured 8d ago against content hash be16f9bb2bc5, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

code-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/oh-my-codex/skills/code-review/SKILL.md · 119 lines

How it starts

The opening of the file, as written. The whole thing — 119 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Code Review Task Card

Use this explicit opt-in for a merge-readiness review. Shared operating invariants live in templates/AGENTS.md; this card only defines review-specific behavior.

When to use

  • The user asks for a code review or quality/security assessment.
  • A change is ready for review before merge, or a major feature needs an independent review.
  • Do not activate this card for implementation, broad planning, or automatic cleanup.

Inputs

  • Scope: the requested files, commit, PR, or whole diff.
  • Requirements/specification, acceptance criteria, and relevant test/CI evidence.
  • Existing review artifacts and known risks, if any.
  • If the user says continue, advance the current verified review step rather than restarting discovery.

Start by recording the scope:

git status --short
git diff --stat
git diff -- <scope>

Execution

  1. Identify changed files and review boundaries; do not silently widen the scope.
  2. Launch the code-reviewer and architect agents in parallel. Both lanes run in parallel on a clean context with explicit scope and artifacts. If either lane cannot be launched or does not return evidence, report independent review unavailable; do not substitute the current/authoring lane, and do not approve or mark the review merge-ready.
  3. Respect the user's current model and reasoning/effort selection. Do not pass model or reasoning_effort overrides in review-lane calls.
task(
  agent_type="code-reviewer",
  prompt="CODE REVIEW TASK

Review the supplied scope for spec compliance, security, quality, performance, and maintainability.
Return files reviewed, severity-rated findings with file:line evidence and concrete fixes,
and a recommendation: APPROVE / REQUEST CHANGES / COMMENT. Do not review architecture.
Scope: [scope and artifacts]"
)

task(
  agent_type="architect",
  prompt="ARCHITECTURE / DEVIL'S-ADVOCATE REVIEW TASK

Review the same scope for boundaries, interfaces, hidden coupling, long-term tradeoffs,
and the strongest counterargument against approval. Return file:line evidence,
recommendations, and Architectural Status: CLEAR / WATCH / BLOCK.
Scope: [scope and artifacts]"
)

Read the full file on GitHub · 119 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 119 lines · 8 tokens per session scan A be16f9bb2bc5

Subscribe to this mod's changes

code-review is a skill published in the GitHub repository Yeachan-Heo/oh-my-codex (33,014 stars, last pushed today), licensed MIT. It adds 8 tokens to every session and 1,275 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.