Evolving The Data Model
TriliumNext/Trilium
A skill your agent uses when adding a DB migration or a new column/field to a Becca entity in Trilium ("add a migration", "new column on notes/attributes", "ALTER TABLE", "add a field to…
Independently validate the current analysis with a second model (OpenAI Codex).
$ npx skills add ai-analyst-lab/ai-analyst --skill codex-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ai-analyst-lab/ai-analyst codex-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/codex-review .claude/skills/codex-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codex-review" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/codex-review into .claude/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/codex-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ai-analyst-lab/ai-analyst --skill codex-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ai-analyst-lab/ai-analyst codex-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/codex-review .agents/skills/codex-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codex-review" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/codex-review into .agents/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ai-analyst-lab/ai-analyst --skill codex-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ai-analyst-lab/ai-analyst codex-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/codex-review .cursor/skills/codex-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codex-review" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/codex-review into .cursor/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ai-analyst-lab/ai-analyst.git --path .claude/skills/codex-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ai-analyst-lab/ai-analyst --skill codex-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ai-analyst-lab/ai-analyst codex-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/codex-review .gemini/skills/codex-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codex-review" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/codex-review into .gemini/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ai-analyst-lab/ai-analyst codex-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ai-analyst-lab/ai-analyst --skill codex-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/codex-review .github/skills/codex-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codex-review" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/codex-review into .github/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ai-analyst-lab/ai-analyst --skill codex-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ai-analyst-lab/ai-analyst codex-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ai-analyst-lab/ai-analyst.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/codex-review .opencode/skills/codex-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codex-review" agent skill from https://github.com/ai-analyst-lab/ai-analyst/tree/main/.claude/skills/codex-review into .opencode/skills/codex-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codex-reviewIndependently validate the current analysis with a second model (OpenAI Codex).
Codex Review is an agent skill from ai-analyst-lab/ai-analyst. Independently validate the current analysis with a second model (OpenAI Codex). Codex re-derives the same answer from the same data — blind to Claude's SQL and numbers — and the skill reports AGREE / DISAGREE / PARTIAL per finding. Use when the user types "/codex-review", or says "validate with codex", "codex review", "second opinion from codex", "have the other model check this", "independently verify this analysis", "does codex agree", "cross-check this with gpt/codex", or wants a different model to confirm a…
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Databases, covering SQL. It works with SQL. The repository describes itself as: AI Product Analyst — Claude Code-powered data analysis toolkit. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 52c0744. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
codexpython3npmclaudeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codex Review loads about 3k tokens when it runs. Until then it costs about 191 tokens; SKILL.md has 1,535 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ai-analyst-lab/ai-analyst at commit 52c0744, republished under its MIT licence (© ai-analyst-lab). 1,535 words, ~3,011 tokens.
.claude/skills/codex-review/SKILL.md (or your agent's skills folder).Have a second model (OpenAI Codex) independently re-derive the current analysis from the same data and compare it to Claude's original. Codex gets the question and the metric definitions, but never sees Claude's SQL, numbers, or conclusions — it writes its own queries and computes its own results. The skill then reconciles the two: AGREE, DISAGREE, or PARTIAL per finding. Two models agreeing from independent derivations is strong evidence the analysis is sound; a disagreement points to exactly where to look.
This pairs with /reliability (same model, run N times — tests stability). /codex-review
uses a different model once — it tests correctness by independent agreement.
/codex-review, "validate with codex", "codex review", "second opinion from
codex", "independently verify this", "does codex agree", "cross-check with the other model"/codex-review [finding or artifact path] — validate the most recent analysis by default,
or scope to a single finding/file if given.
Example: /codex-review after answering "What's our 30-day retention?"
⛔ HARD GATE — read before anything else
This skill is worthless unless a different model (Codex) does the validation. If Codex is not ready, you (Claude) MUST NOT perform the validation yourself. Claude re-checking Claude's analysis is circular — it produces a confident "validated ✓" that means nothing and actively misleads the student.
The rule: if Step 1's preflight returns a non-empty
missinglist, your ONLY job this turn is to help the student set up Codex. You may not proceed to Steps 2–7, and you may not substitute any other model, your own reasoning, a re-run of the SQL, or an "approximate" check. There is no fallback that uses Claude. Setup is the task when Codex is missing — completing it is the helpful outcome, not skipping ahead to a verdict.
Run the deterministic check:
python3 helpers/provenance/codex_validation.py --checkIt returns JSON: {"codex_cli", "plugin", "auth", "missing": [...]}. Route on missing:
missing → Codex is ready. Go to Step 2."codex_cli" present → the Codex CLI isn't installed. Tell the user to run:npm install -g @openai/codex"plugin" present → the Claude Code plugin isn't installed. Show these commands for
the user to paste (the skill cannot run them — they're interactive):/plugin marketplace add openai/codex-plugin-cc
/plugin install codex@openai-codex
/reload-plugins
/codex:setup"auth" present → Codex is installed but not authenticated. Tell the user to run:codex loginIf missing is non-empty, stop after giving the setup step and end the turn with "Once
that's done, re-run /codex-review and I'll have Codex check it." The next invocation re-runs
--check and proceeds only when missing is empty.
Restart gate. If the student just installed the plugin, also remind them the plugin's
tools aren't loaded until they run /reload-plugins — so the sequence is install →
/reload-plugins → re-run /codex-review. (auth is best-effort: if --check returns
auth: null with the CLI and plugin present, proceed — the live Codex run is the real gate
and will surface any login error.)
Keep this simple and one-step-at-a-time: name only the first missing piece, let the student fix it, then re-run the check. Setup may take two or three turns (CLI, then plugin + reload, then login); that is the expected, correct path — not a detour from the "real" work.
Identify, for the most recent analysis (or the scoped finding):
metrics/index.yaml), the analysis design spec, or the analysis itself..knowledge/active.yaml).If it's ambiguous what to validate (no recent finding, multiple candidates), ask the user which finding or artifact to check, and offer a path.
Create a timestamped run directory: working/codex_validation/<UTC-timestamp>-<question-slug>/.
Write brief.md in it containing ONLY what Codex needs to answer the same question the
same way, independently:
.knowledge/active.yaml, the active
dataset's .knowledge/datasets/{active}/schema.md and quirks.md; connect with
from helpers.data.connection_manager import ConnectionManager (or the local DuckDB/CSV
fallback in the dataset manifest's local_data if no warehouse is reachable).Do NOT put Claude's SQL, result numbers, or conclusion in brief.md. That blindness is
the whole point — it's what makes Codex's derivation independent.
Separately, stash Claude's original result in claude_original.md in the same run dir
(headline number(s), SQL, conclusion). This file is for the Step 5 comparison only — it is
not given to Codex.
Dispatch the codex:codex-rescue subagent (Agent tool) with brief.md and this output
contract:
Independently answer the analytics question in this brief against the active dataset. Connect to the data and write your own SQL — do not ask for or assume anyone else's queries or numbers. Use the metric definition exactly as given. Log your queries. Then report ONLY:
headline: <the single number you'd report>(one per finding if multiple)sql: <the query/queries you actually ran>measured: <numerator, denominator, grain, window, filters>conclusion: <one or two sentences>
Capture Codex's full response to codex_independent.md in the run dir.
(Fallback: if the subagent's output is unreliable or unavailable, run codex exec via Bash
with the same brief and output contract, and save the result to the same file.)
Put Codex's numbers next to Claude's (claude_original.md) and assign a verdict per finding:
Write a verdict.md (the human-readable comparison table) AND a verdict.json for
the deterministic audit log, shaped:
{"question": "<q>", "model": "codex", "findings": [{"name": "<finding>", "verdict": "AGREE|DISAGREE|PARTIAL"}, ...]}.
Append the run to the audit log:
python3 helpers/provenance/codex_validation.py --log <that run directory>It reads verdict.json, counts the verdicts deterministically, and appends one line to
.knowledge/codex-review/log.jsonl. The run dir now holds the full provenance:
brief.md, claude_original.md, codex_independent.md, verdict.md, verdict.json.
Frame it as independent multi-model validation, then show the comparison:
Finding | Claude | Codex | Verdict | Why table from verdict.md..knowledge/codex-review/log.jsonl).Then the honest framing:
On any DISAGREE, offer to re-run the relevant analysis step, define the metric via
/metric-spec, or log the lesson via /log-correction.
missing is non-empty,
stop at setup. Never validate with Claude, another model, your own reasoning, or a re-run of
the SQL. A Claude-checks-Claude result is circular and must never be presented as a
validation. This is the one rule that cannot be bent. (See the Hard Gate above.)brief.md. If you can't keep them out, the run isn't independent — say
so rather than presenting a false validation.codex_validation.py --log
reading verdict.json, never estimated in prose./reload-plugins.--check is clean.manifest.local_data) so it can still derive independently./metric-spec.auth: null from preflight → proceed; the live run surfaces any real login error.openai/codex-plugin-cc) is just the simple, supported path to an installed +
authenticated Codex CLI. The validation itself runs Codex against the data, not a code
diff — the plugin's /codex:review (diff review) is a different thing and isn't used here./reliability: that re-runs the same model to test stability; this runs a
different model once to test correctness by independent agreement.© ai-analyst-lab, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/codex-review of ai-analyst-lab/ai-analyst.
Open the folder on GitHubat commit 52c0744
Codex Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codex Review this skillai-analyst-lab/ai-analyst | 304 | — | ~3k | Automated safety check: Pass | MIT | |
| Evolving The Data ModelTriliumNext/Trilium | 38k | — | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Orchardcore Data MigrationOrchardCMS/OrchardCore | 8.2k | — | ~1.7k | Automated safety check: Pass | BSD-3-Clause | |
| SQL Optimization Patternsynulihao/AgentSkillOS | 617 | 11 repos | ~3.3k | Automated safety check: Pass | None | |
| SQL PortabilityHL7/sql-on-fhir | 150 | — | ~512 | Automated safety check: Pass | Custom licence | |
| StmoSAP/project-foxhound | 180 | 2 repos | ~1.8k | Automated safety check: Pass | GPL-3.0 |
TriliumNext/Trilium
A skill your agent uses when adding a DB migration or a new column/field to a Becca entity in Trilium ("add a migration", "new column on notes/attributes", "ALTER TABLE", "add a field to…
OrchardCMS/OrchardCore
Creates and updates OrchardCore data migrations (DataMigration classes with CreateAsync/UpdateFromX).
ynulihao/AgentSkillOS
Master SQL query optimization, indexing strategies, and EXPLAIN analysis to dramatically improve database performance and eliminate slow queries.
HL7/sql-on-fhir
Analyse whether a SQL query is portable across database implementations using sqlglot transpilation.
SAP/project-foxhound
Manage Redash queries and dashboards on Mozilla's STMO (sql.telemetry.mozilla.org) using stmo-cli.
kurealnum/dotfiles
A skill your agent uses when generating or regenerating Drizzle migration files, changing database schema tables or columns, resolving migration sequence conflicts after rebase, reviewing migration…
ai-analyst-lab/ai-analyst
Never present a metric or number in isolation; anchor every number to a comparison (prior period, benchmark, or another segment) or state that none is available.
ai-analyst-lab/ai-analyst
Retrieve proven SQL patterns, table cheatsheets, and join patterns from .knowledge/query-archaeology/ so past work gets reused.
ai-analyst-lab/ai-analyst
Save completed analyses to the knowledge system's analysis archive for future reference.
ai-analyst-lab/ai-analyst
Verify Google Workspace MCP authentication at the start of any session that needs Google APIs (Docs, Slides, Drive).
ai-analyst-lab/ai-analyst
Causal inference toolkit for when experiments are not possible: estimate treatment effects from observational data with assumption checks and mandatory caveats.
ai-analyst-lab/ai-analyst
Standardized workflow for uploading local chart PNGs to Google Drive and making them available for insertion into Google Docs and Slides.
Works with
Categories
Independently validate the current analysis with a second model (OpenAI Codex). Codex Review is an agent skill from ai-analyst-lab/ai-analyst. Independently validate the current analysis with a second model (OpenAI Codex).
Codex Review fits situations like: the user types /codex-review; says validate with codex; second opinion from codex; have the other model check this.
Run `npx skills add ai-analyst-lab/ai-analyst --skill codex-review -a claude-code`. Or copy the skill folder (.claude/skills/codex-review in ai-analyst-lab/ai-analyst) into .claude/skills/codex-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ai-analyst-lab/ai-analyst --skill codex-review -a codex`. Or copy the skill folder (.claude/skills/codex-review in ai-analyst-lab/ai-analyst) into .agents/skills/codex-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ai-analyst-lab/ai-analyst --skill codex-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-review, .gemini/skills/codex-review, .github/skills/codex-review and .opencode/skills/codex-review in your project.
Going by SKILL.md and its folder, Codex Review needs the command-line tools its instructions call (codex, python3, npm and claude). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Codex Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Codex Review: Evolving The Data Model (TriliumNext/Trilium, 38k stars), Orchardcore Data Migration (OrchardCMS/OrchardCore, 8.2k stars), SQL Optimization Patterns (ynulihao/AgentSkillOS, 617 stars) and SQL Portability (HL7/sql-on-fhir, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ai-analyst-lab (a GitHub organization) maintains it in ai-analyst-lab/ai-analyst, which has 304 GitHub stars. The repository holds 43 skills in this directory. The repository was last updated on September 30, 2026.
Source: ai-analyst-lab/ai-analyst on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.