Install
$ agentstack add skill-minghinmatthewlam-agent-guards-codex-review ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Codex Review
Use Codex's dedicated review command as an independent fallback check. This is codex review, not OpenClaw autoreview, not Guardian approval auto_review, and not a generic "ask a subagent to review" pass.
For plain "autoreview" or normal closeout review requests, use the autoreview skill instead. Use this skill only when the user explicitly asks for built-in Codex review, when comparing review tools, or when autoreview is unavailable.
Use when:
- the user asks specifically for built-in Codex review or
codex review - comparing
codex reviewagainstautoreview autoreviewfails or is unavailable and a fallback review is still useful- reviewing a local dirty tree, branch, commit, or PR branch after fixes
Contract
- Treat review output as advisory. Verify every finding against the real code path before changing code.
- Prefer small fixes at the right ownership boundary. Do not add broad refactors just to satisfy a speculative finding.
- Reject findings that depend on unstated assumptions, unrealistic edge cases, intentional behavior, or over-complicated fixes.
- If a review finding causes a code change, rerun the focused proof/tests and rerun Codex review.
- Keep looping until the final review has no accepted/actionable findings, or until a remaining finding is explicitly rejected with a short reason.
- Do not push only to run review. Push only when the user asked for push, ship, or PR update.
Pick The Target
Dirty local work:
codex review --uncommitted
Use this only when the working tree actually has staged, unstaged, or untracked changes. A clean --uncommitted run only proves there is no local patch.
Branch or PR work:
git fetch origin
codex review --base origin/main
If an open PR exists, review against its actual base:
base=$(gh pr view --json baseRefName --jq .baseRefName)
codex review --base "origin/$base"
Committed single change:
codex review --commit HEAD
Custom review prompt:
codex review "Review the error handling in the new auth flow."
Current Codex CLI targets are mutually exclusive. Do not combine --base, --commit, or --uncommitted with a positional custom prompt.
Helper
This skill includes a helper that chooses a sensible target and can run focused tests in parallel:
~/.agents/skills/codex-review/scripts/codex-review --help
After sync, Claude can call the same helper here:
~/.claude/skills/codex-review/scripts/codex-review --help
The helper:
- chooses dirty
--uncommittedfirst in--mode auto - otherwise uses the current PR base if
gh pr viewworks - otherwise uses
origin/mainfor non-main branches - supports
--mode local,--mode branch,--base,--commit,--dry-run, and--parallel-tests - supports
--full-accessfor nested Codex review runs that need the local command to bypass Codex sandbox prompts - prints
codex-review clean: no accepted/actionable findings reportedwhen the selected review command exits 0 and no priority findings are detected
Format first if formatting can move line numbers, then it is OK to run tests and review together:
~/.agents/skills/codex-review/scripts/codex-review --parallel-tests "npm test -- --runInBand"
If tests or review lead to edits, rerun the affected tests and rerun review. Once the final review/helper run exits cleanly, stop. Do not run an extra review just to get nicer wording.
Subagent Filter
codex review is already a dedicated review harness with a review-specific rubric, constrained tools, fresh context, and structured findings. A normal subagent reviewer is more flexible but easier to bias with the main agent's framing.
For larger diffs, use a subagent as a filter over codex review when available. Ask it to run the review and return only:
- findings it accepts as actionable
- findings it rejects, with one-line reasons
- exact files and tests to rerun
For tiny changes, run the review inline.
Final Report
Include:
- review command used
- tests or proof run
- accepted findings and fixes
- rejected findings with short reasons
- final clean review result, or why any remaining finding was consciously rejected
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: minghinmatthewlam
- Source: minghinmatthewlam/agent-guards
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.