mcpbeat Sign in

Codex Review Agent Skill

Run an independent code review using the OpenAI Codex CLI in headless mode. Gets a second opinion from a different model family (the current Codex models) on recent changes, a PR, a commit, or the whole app — covering bugs, regressions, security, data consistency, UX/state bugs, performance risks, and testing gaps. Saves a severity-prioritised report to .jez/reviews/. Triggers: 'codex review', 'review with codex', 'independent code review', 'what does codex think', 'get codex to review'.

2k tokens
context cost
the whole folder, loaded on every use
2
files
instructions only
0
copies elsewhere
how many repositories repackaged it
953
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/jezweb/claude-skills --skill codex-review

The instruction itself

8 sections, as written by the author

Codex Review

Run an independent code review via the OpenAI Codex CLI (codex review). The value is a second opinion from a different model family than the one that wrote the code — Codex catches things Claude misses due to author bias.

Complements brains-trust (generic multi-model opinions). This skill is specialised: git-aware, uses a tuned review prompt, saves structured output.

When to Use

  • After a meaningful change, before committing or shipping
  • Before opening a PR, to self-review with an independent reviewer
  • When something feels off but you can't articulate what
  • Periodic whole-app reviews for projects in active development
  • When the user explicitly asks for an "independent" or "second opinion" review

Do NOT use for:

  • Trivial changes (typos, one-line fixes)
  • Research questions or architecture discussions — use brains-trust instead
  • Auto-fixing issues — this is advisory only

Preflight

  • Confirm Codex CLI is installed:
   which codex

If missing: tell the user to install it (brew install codex on macOS, or see https://github.com/openai/codex) and stop. Do not continue.

  • Confirm auth: the first codex review call will fail clearly if not logged in. If that happens, instruct the user to run codex login and stop.

Determine scope

Pick the scope flag based on what the user asked for:

| User intent | Flag |

|---|---|

| "codex review" / "review the app" / "full review" / default | no flag (reviews whole app at current HEAD) |

| "review my changes" / "review what I just did" / "review uncommitted" | --uncommitted |

| "review this branch vs main" / "review the PR" | --base main (or the branch they name) |

| "review commit abc123" | --commit abc123 |

Default is whole-app review. A bare "codex review" with no qualifier means review the entire codebase at HEAD — not just uncommitted changes. Only use --uncommitted if the user specifically refers to their recent/uncommitted work.

If ambiguous, ask once. Don't guess on commits or branches.

Run the review

The canonical review prompt lives in prompt.md next to this skill. Pipe it via stdin to avoid shell escaping:

mkdir -p .jez/reviews
TS=$(date +%Y-%m-%d-%H%M)
OUT=".jez/reviews/codex-${TS}.md"
SKILL_DIR="$(dirname "$0")"  # or use the skill's absolute path

# Example: uncommitted changes
cat "${SKILL_DIR}/prompt.md" | codex review --uncommitted - 2>&1 | tee "$OUT"

Other scopes:

# Vs base branch
cat prompt.md | codex review --base main - 2>&1 | tee "$OUT"

# Specific commit
cat prompt.md | codex review --commit abc123 - 2>&1 | tee "$OUT"

# Current HEAD (no scope flag)
cat prompt.md | codex review - 2>&1 | tee "$OUT"

codex review can take several minutes on a large diff. Let it run.

Summarise for the user

After Codex finishes:

  • Print the output path: Report saved to .jez/reviews/codex-<timestamp>.md
  • Read the saved report and extract the top findings (anything under Critical and High)
  • Show them inline in the chat, with file:line references intact
  • Offer to action specific findings: "Want me to fix the SQL injection in auth.ts:42?"

Rules

  • Advisory only. Never auto-apply Codex's suggestions. Read the findings, discuss with the user, fix with their approval.
  • Don't leak Claude's reasoning into the prompt. The prompt.md file is deliberately neutral — Codex reviews the code, not Claude's narrative about the code. Independence is the whole point.
  • Save to .jez/reviews/, never .claude/ (protected directory).
  • One report per run. Don't overwrite — the timestamp makes each run unique so the user can compare.
  • Report what Codex actually found. Don't soften, editorialise, or skip findings you disagree with. If you think Codex is wrong about something, say so as your own opinion after showing what Codex said.

Verification

The skill is working if:

  • Preflight correctly detects a missing codex binary
  • The right scope flag is chosen based on user intent
  • The report file appears in .jez/reviews/ with a sensible timestamp
  • The file contains severity-prioritised findings with file:line refs
  • Claude surfaces the top findings without auto-fixing them

Other skills for the same job

different authors, same section of the catalogue
Performance Testing Review AI Review
by ComeOnOliver
×2

You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices. Leverage AI tools (GitHub Copilot, Qodo, GPT-5, C

6k tokens
Ruby Pro
by ComeOnOliver
×2

Write idiomatic Ruby code with metaprogramming, Rails patterns, and performance optimization. Specializes in Ruby on Rails, gem development, and testing frameworks. Use PROACTIVELY for Ruby refactoring, optimization, or complex Ruby features.

3k tokens
Tdd Workflows Tdd Refactor
by ComeOnOliver
×2

Use when working with tdd workflows tdd refactor

4k tokens
Setup Pre Commit
by aiskillstore
×1

Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo. Use when user wants to add pre-commit hooks, set up Husky, configure lint-staged, or add commit-time formatting/typechecking/testing.

7k tokens
Pair Programming
by Microck
×1

AI-assisted pair programming with multiple modes (driver/navigator/switch), real-time verification, quality monitoring, and comprehensive testing. Supports TDD, debugging, refactoring, and learning sessions. Features automatic role switching, continuous code review, security scanning, and performance optimization with truth-score verification.

6k tokens
Audit Prep Assistant
by christophacham
×1

Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes dead code, ensures accessibility, and generates documentation (flowcharts, user stories, inline comments).

2k tokens
Component Refactoring
by ComeOnOliver
×1

Refactor high-complexity React components in Dify frontend. Use when `pnpm analyze-component --json` shows complexity > 50 or lineCount > 300, when the user asks for code splitting, hook extraction, or complexity reduction, or when `pnpm analyze-component` warns to refactor before testing; avoid for simple/well-structured components, third-party wrappers, or when the user explicitly wants testing without refactoring.

20k tokens
Csharp Pro
by ComeOnOliver
×1

Write modern C# code with advanced features like records, pattern matching, and async/await. Optimizes .NET applications, implements enterprise patterns, and ensures comprehensive testing. Use PROACTIVELY for C# refactoring, performance optimization, or complex .NET solutions.

3k tokens

How to use it

Copy the folder

Take jezweb/codex-review from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.

Install what it needs

The instructions reference brew. Without those the skill loads but fails at the first command.