Agent skill

Codex Review Loop

by aafqaq in aafqaq/codex-lb-enhanced

Adversarial PR code review using Codex CLI. An agent skill from aafqaq/codex-lb-enhanced.

MITAuto-check passedDevOps & Cloud

Install Codex Review Loop

skills CLI
$ npx skills add aafqaq/codex-lb-enhanced --skill codex-review-loop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aafqaq/codex-lb-enhanced codex-review-loop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aafqaq/codex-lb-enhanced.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/codex-review-loop .claude/skills/codex-review-loop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex-review-loop
GitHub stars
102
Token cost
~1.7k tokens
SKILL.md length
824 words
Files
4 (incl. scripts, references)
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Adversarial PR code review using Codex CLI. An agent skill from aafqaq/codex-lb-enhanced.

  • Works in 5 steps: Scope Resolution → Codex Review → Finding Analysis → …
  • DevOps & Cloud work in your project
  • SKILL.md covers Arguments, Phases, Phase 1: Scope Resolution and Phase 2: Codex Review, plus 5 more sections
  • Runs Shell scripts from its folder; calls bash, gh and codex

What it does

Codex Review Loop is an agent skill from aafqaq/codex-lb-enhanced. Adversarial PR code review using Codex CLI. Codex review (~20-50 min) - structured findings - HITL approval - fix loop.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/prompts/adversarial-review.md`, `references/schemas/review-findings.md` and `scripts/codex-subagent.sh`).

It sits in DevOps & Cloud. The repository describes itself as: Production-ready Codex-compatible account-pool gateway with seamless failover, full-session recovery, native quota headers, WebSocket/HTTP bridge, and observability. The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/codex-review-loop”

Requirements

  • Node.js
  • A Bash shell

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Scope Resolution
  2. Codex Review
  3. Finding Analysis
  4. Atomic Fix Loop
  5. Re-review Loop

What it can do on your machine

Read from SKILL.md and the folder at commit c0e9e18. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • gh
    • codex
    • uvx
    • uv
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, uvx, uv and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex Review Loop loads about 1.7k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 35 tokens; SKILL.md has 824 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aafqaq/codex-lb-enhanced at commit c0e9e18, republished under its MIT licence (© aafqaq). 824 words, ~1,698 tokens.

Download SKILL.mdSave it as .claude/skills/codex-review-loop/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
codex-review-loop
description
Adversarial PR code review using Codex CLI. Codex review (~20-50 min) -> structured findings -> HITL approval -> fix loop.
metadata.author
codex-lb
metadata.version
2.0.0
metadata.argument-hint
[--pr <N>] [--base <branch>] [--uncommitted]

Codex Review Loop

Adversarial code review via Codex CLI, structured finding analysis, HITL-gated fix loop, optional re-verification.

Arguments

  • --pr <N> — review PR number N (default: auto-detect most recent open PR)
  • --base <branch> — review changes against base branch
  • --uncommitted — review uncommitted local changes

Phases

  1. Scope Resolution — determine review target (PR/branch/uncommitted)
  2. Codex Review — launch adversarial review via Codex CLI (~20-50 min)
  3. Finding Analysis — parse raw output into structured findings
  4. Atomic Fix Loop — fix, verify, commit each approved finding
  5. Re-review Loop — re-run review until 0 findings (max 3 iterations)
  6. Final Report — summary of all findings, fixes, and verification status

Phase 1: Scope Resolution

Determine the review target and extract the base branch.

  • PR mode (default): Use gh pr view / gh pr list to resolve base branch and display PR metadata (title, file count, additions/deletions).
  • Branch mode (--base): Use specified base branch directly.
  • Uncommitted mode (--uncommitted): Review working tree changes.

If no argument is given, auto-detect the user's most recent open PR and confirm.


Phase 2: Codex Review

Launch the adversarial review as a background process.

  1. Run the review script with run_in_background=true:
    bash <skill-dir>/scripts/codex-subagent.sh --base <branch>
    Note: Codex CLI v0.105.0+ does not support combining --base/--commit with a custom prompt. The built-in review logic is used automatically. For --uncommitted mode (no diff target), pipe stdin for custom instructions:
    cat <prompt-file> | bash <skill-dir>/scripts/codex-subagent.sh --uncommitted
  2. Inform the user the review is running (~20-50 min).
  3. The script parses Codex output and returns the final review text. Review rollouts intentionally remain persistent. If terminal output is lost, use codex resume --include-non-interactive to locate the review, or codex resume <SESSION_ID> when its ID is known. Do not add --ephemeral to the wrapper. The wrapper also relies on the configured non-interactive approval/sandbox policy because Codex CLI 0.147.0 removed the historical --full-auto argument from exec review.
Error handling
Exit codeMeaningAction
0SuccessProceed to Phase 3
1Codex errorShow error, offer retry or abort
127codex not foundGuide: npm i -g @openai/codex
Environment overrides
VariablePurpose
CODEX_REVIEW_MODELOverride Codex model
CODEX_REVIEW_REASONINGOverride reasoning effort

Phase 3: Finding Analysis

Parse the raw Codex output into structured findings.

References
  • Schema: references/schemas/review-findings.md — field definitions, severity/category/effort enums, status lifecycle
  • Convention rules: .agents/skills/project-conventions/conventions.md — project coding conventions to cross-reference
Severity escalation/downgrade guide
  • Escalate to Critical: Unvalidated external input, secret exposure, injection vectors, data integrity compromise
  • Escalate to High: API contract change without test update, possible NoneType error, blocking I/O in async context
  • Downgrade to Medium: Correct functionality but violates conventions, duplicate logic, unnecessary complexity
  • Downgrade to Low: Pure style, unused import, missing docstring
Convention-to-category mapping
  • Typing violations (dict, Mapping, object, getattr) -> typing
  • Anti-patterns (speculative fallbacks, duplicate state) -> convention
  • Structure violations (core/modules boundary, DI bypass) -> architecture
  • Testing gaps (contract change without test update) -> testing
Process
  1. Parse each finding from the raw output
  2. Assign severity and category using the schema definitions and guide above
  3. Cross-reference with project conventions
  4. Estimate fix effort
  5. Deduplicate (keep the most severe instance)
  6. Sort: severity desc, file path asc

Show full SKILL.md (331 more words)Show less

HITL Gate 1: Finding Review

Present all findings to the user as a summary table (ID, severity, category, file:line, title, effort).

Ask the user to choose a fix scope:

  • Fix all (recommended)
  • Fix Critical/High only
  • Report only (no fixes)

Phase 4: Atomic Fix Loop

For each approved finding, execute an atomic fix-verify-commit cycle.

Per finding:
  1. Fix: Read target file(s), apply the fix.
  2. HITL Gate 2 (conditional): For Critical/High findings that modify existing logic (not just adding new code), show the current and proposed code to the user for confirmation. Medium/Low findings are auto-fixed.
  3. Verify (all must pass):
    • uvx ruff check .
    • uvx ruff format --check . (auto-fix and re-check if needed)
    • uv run ty check
    • uv run pytest (mapped test files, or full suite if no mapping found)
  4. Commit: fix(review): P{i} - {title}
  5. On failure: Roll back changes, mark finding as skipped, continue to next.

Phase 5: Re-review Loop

After all fixes are committed, automatically re-run the Codex review to check for regressions or new issues introduced by the fixes.

Loop behaviour
  1. Re-run Codex review (--base <branch>) against the same base.
  2. Parse findings (Phase 3) and present to user (HITL Gate 1).
  3. If 0 findings → loop terminates, proceed to Final Report.
  4. If findings exist → execute Phase 4 (fix-verify-commit), then repeat from step 1.
Safety limits
  • Max iterations: 3 (initial review + 2 re-reviews). After 3 iterations, terminate the loop regardless of remaining findings and output the Final Report with unresolved items noted.
  • Escalation: If the same finding recurs across 2 consecutive iterations, mark it as wont_fix and skip in subsequent iterations.
HITL override

At each re-review result, the user may choose:

  • Continue — proceed with fixes (default when findings > 0)
  • Stop — terminate the loop early and output Final Report

Final Report

Output a summary including:

  • PR metadata (number, title, base/head)
  • Loop iteration count and termination reason (clean / max iterations / user stop)
  • Findings table (ID, severity, category, title, status, commit hash)
  • Commit stack
  • Verification status (ruff, ty, pytest)

© aafqaq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in .agents/skills/codex-review-loop of aafqaq/codex-lb-enhanced.

  • SKILL.md
  • references/prompts/adversarial-review.md
  • references/schemas/review-findings.md
  • scripts/codex-subagent.sh

Open the folder on GitHubat commit c0e9e18

Compare with similar skills

Codex Review Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex Review Loop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex Review Loop this skillaafqaq/codex-lb-enhanced102—~1.7kAutomated safety check: PassMIT
Debugsbusso/claudeclaw1941 repos~3.3kAutomated safety check: NotesMIT
AI ServerOpentrons/opentrons521—~2.5kAutomated safety check: NotesApache-2.0
Kopiur Designhome-operations/kopiur113—~2.4kAutomated safety check: PassAGPL-3.0
GitHub Actions Patbifrost-proxy/bifrost160—~2kAutomated safety check: PassMIT
Linear Deploy Integrationjeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Debug

    sbusso/claudeclaw

    Debug container agent issues. An agent skill from sbusso/claudeclaw.

    194 GitHub starsUsed in 1 repo~3.3k tokens
    DevOps & CloudAuto-check: notes
  • AI Server

    Opentrons/opentrons

    Conventions for the opentrons-ai-server FastAPI service — project structure, uv dependency management, settings, testing, Docker, and deployment.

    521 GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Kopiur Design

    home-operations/kopiur

    Design norms and locked decisions for the Kopiur Kopia-native Kubernetes backup operator (Rust/kube-rs).

    113 GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • GitHub Actions Pat

    bifrost-proxy/bifrost

    用 Personal Access Token 通过 GitHub REST API 分析 Actions CI 的失败 run/job/step、拉取日志、轮询运行状态、做 PR code review,并驱动 fix → push → watch → iterate 的闭环。Token 只从 GITHUBTOKEN 环境变量读取,不落盘、不回显。适合在 bifrost remote /…

    160 GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Linear Deploy Integration

    jeremylongshore/tons-of-skills-marketplace

    Connect deployment evidence to Linear work without granting the deploy pipeline broad issue-edit authority.

    2.8k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Spine Service

    jeremylongshore/tons-of-skills-marketplace

    Build a new production-ready service from scratch — config management, health checks, graceful shutdown, structured logging.

    2.8k GitHub stars~804 tokensUpdated today
    DevOps & CloudAuto-check: notes

More from aafqaq/codex-lb-enhanced

  • Openai Docs

    aafqaq/codex-lb-enhanced

    A skill your agent uses when the user asks how to build with OpenAI products or APIs and needs up-to-date official documentation with citations (for example: Codex, Responses API, Chat Completions…

    102 GitHub starsUsed in 3 repos~861 tokens
    Auto-check passed
  • Openspec Context Docs

    aafqaq/codex-lb-enhanced

    OpenSpec context documentation policy: keep requirements in spec.md and capture narrative context in context/overview/rationale docs under openspec/specs.

    102 GitHub stars~505 tokensUpdated 2 days ago
    Auto-check passed
  • Project Conventions

    aafqaq/codex-lb-enhanced

    Project code conventions reference. An agent skill from aafqaq/codex-lb-enhanced.

    102 GitHub stars~203 tokensUpdated 2 days ago
    Auto-check passed

Questions about Codex Review Loop

What does Codex Review Loop do?

Adversarial PR code review using Codex CLI. An agent skill from aafqaq/codex-lb-enhanced. Codex Review Loop is an agent skill from aafqaq/codex-lb-enhanced. Adversarial PR code review using Codex CLI.

When should I use Codex Review Loop?

Codex Review Loop fits situations like: devOps & Cloud work in your project.

How do I install Codex Review Loop in Claude Code?

Run `npx skills add aafqaq/codex-lb-enhanced --skill codex-review-loop -a claude-code`. Or copy the skill folder (.agents/skills/codex-review-loop in aafqaq/codex-lb-enhanced) into .claude/skills/codex-review-loop in your project. Claude Code loads it when a task matches its description.

How do I install Codex Review Loop in Codex?

Run `npx skills add aafqaq/codex-lb-enhanced --skill codex-review-loop -a codex`. Or copy the skill folder (.agents/skills/codex-review-loop in aafqaq/codex-lb-enhanced) into .agents/skills/codex-review-loop in your project. Codex loads it when a task matches its description.

Can I use Codex Review Loop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aafqaq/codex-lb-enhanced --skill codex-review-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-review-loop, .gemini/skills/codex-review-loop, .github/skills/codex-review-loop and .opencode/skills/codex-review-loop in your project.

What does Codex Review Loop need to run?

Going by SKILL.md and its folder, Codex Review Loop needs a shell for the scripts in its folder and the command-line tools its instructions call (bash, gh, codex, uvx, uv and npm). Our summary lists: Node.js; A Bash shell.

Does Codex Review Loop access the network?

SKILL.md contains no URLs. Its commands use gh, uvx, uv and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codex Review Loop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Codex Review Loop use?

Codex Review Loop is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex Review Loop use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Codex Review Loop?

Skills that share tags, products or a category with Codex Review Loop: Debug (sbusso/claudeclaw, 194 stars), AI Server (Opentrons/opentrons, 521 stars), Kopiur Design (home-operations/kopiur, 113 stars) and GitHub Actions Pat (bifrost-proxy/bifrost, 160 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex Review Loop?

aafqaq (a GitHub user) maintains it in aafqaq/codex-lb-enhanced, which has 102 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 5, 2026.

Source: aafqaq/codex-lb-enhanced on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.