Agent skill

Codex Review

by alinaqi in alinaqi/maggy

OpenAI Codex CLI code review with GPT-5.2-Codex, CI/CD integration

MITAuto-check passedDevOps & Cloud

Install Codex Review

skills CLI
$ npx skills add alinaqi/maggy --skill codex-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alinaqi/maggy codex-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alinaqi/maggy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codex-review .claude/skills/codex-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex-review
GitHub stars
707
Token cost
~3k tokens
SKILL.md length
369 words
Files
1
Skills in repo
71
Repo updated
First seen
Licence
MIT

At a glance

OpenAI Codex CLI code review with GPT-5.2-Codex, CI/CD integration

  • Tasks that involve CI/CD
  • SKILL.md covers Why Codex for Code Review?, Installation, Interactive Code Review and Headless Mode (Automation), plus 7 more sections
  • Calls codex, brew and nvm; needs OPENAI_API_KEY
  • Tasks that involve Code review

What it does

Codex Review is an agent skill from alinaqi/maggy. OpenAI Codex CLI code review with GPT-5.2-Codex, CI/CD integration

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering CI/CD and Code review. It works with OpenAI and GitHub. The repository describes itself as: What started as an opinionated Claude Code setup kit is now an autonomous AI engineering command center. The licence is MIT.

When your agent uses it

  • Tasks that involve CI/CD
  • Tasks that involve Code review

Example prompts

  • “/codex-review”

Requirements

  • Python 3
  • Node.js
  • A credential in OPENAI_API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 72a456e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • codex
    • brew
    • nvm
    • npm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.openai.com
    • github.com
    • cookbook.openai.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex Review loads about 3k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 369 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alinaqi/maggy at commit 72a456e, republished under its MIT licence (© alinaqi). 369 words, ~3,011 tokens.

Download SKILL.mdSave it as .claude/skills/codex-review/SKILL.md (or your agent's skills folder).
name
codex-review
description
OpenAI Codex CLI code review with GPT-5.2-Codex, CI/CD integration
when-to-use
When user requests Codex-powered code review or multi-engine review
user-invocable
true
effort
medium

OpenAI Codex Code Review Skill

Use OpenAI's Codex CLI for specialized code review with GPT-5.2-Codex - trained specifically for detecting bugs, security flaws, and code quality issues.

Sources: Codex CLI | GitHub | Code Review Cookbook


Why Codex for Code Review?

FeatureBenefit
GPT-5.2-CodexSpecialized training for code review
88% detection rateBugs, security flaws, style issues (LiveCodeBench)
Structured outputJSON schema for consistent findings
GitHub native@codex review in PR comments
Headless modeCI/CD automation without TUI

Installation

Prerequisites
bash
# Check Node.js version (requires 22+)
node --version

# Install Node.js 22 if needed
# macOS
brew install node@22

# Or via nvm
nvm install 22
nvm use 22
Install Codex CLI
bash
# Via npm (recommended)
npm install -g @openai/codex

# Via Homebrew (macOS)
brew install --cask codex

# Verify installation
codex --version
Authentication

Option 1: ChatGPT Subscription (Plus, Pro, Team, Edu, Enterprise)

bash
codex
# Follow prompts to sign in with ChatGPT account

Option 2: OpenAI API Key

bash
# Set environment variable
export OPENAI_API_KEY=sk-proj-...

# Or add to shell profile
echo 'export OPENAI_API_KEY=sk-proj-...' >> ~/.zshrc

# Run Codex
codex
Shell Completions (Optional)
bash
# Bash
codex completion bash >> ~/.bashrc

# Zsh
codex completion zsh >> ~/.zshrc

# Fish
codex completion fish > ~/.config/fish/completions/codex.fish

Interactive Code Review

Launch Review Mode
bash
# Start Codex
codex

# In the TUI, type:
/review
Review Presets
PresetUse Case
Review against base branchBefore opening PR - diffs against upstream
Review uncommitted changesBefore committing - staged + unstaged + untracked
Review a commitAnalyze specific SHA from history
Custom instructionse.g., "Focus on security vulnerabilities"
Example Session
$ codex
> /review

Select review type:
❯ Review against a base branch
  Review uncommitted changes
  Review a commit
  Custom review instructions

Select base branch: main

Reviewing changes...

┌─────────────────────────────────────────────────────────────┐
│ CODE REVIEW FINDINGS                                        │
├─────────────────────────────────────────────────────────────┤
│ 🔴 CRITICAL: SQL Injection vulnerability                    │
│    File: src/api/users.ts:45                                │
│    Issue: User input directly interpolated in query         │
│    Fix: Use parameterized queries                           │
├─────────────────────────────────────────────────────────────┤
│ 🟠 HIGH: Missing authentication check                       │
│    File: src/api/admin.ts:23                                │
│    Issue: Admin endpoint accessible without auth            │
│    Fix: Add requireAuth middleware                          │
├─────────────────────────────────────────────────────────────┤
│ 🟡 MEDIUM: Inefficient database query                       │
│    File: src/services/orders.ts:89                          │
│    Issue: N+1 query pattern in loop                         │
│    Fix: Use batch query or JOIN                             │
└─────────────────────────────────────────────────────────────┘

Headless Mode (Automation)

Basic Usage
bash
# Simple review
codex exec "review the code for bugs and security issues"

# Review with JSON output
codex exec --json "review uncommitted changes" > review.json

# Save final message to file
codex exec --output-last-message review.txt "review the diff against main"
Full Automation (CI/CD)
bash
# Full auto mode (use only in isolated runners!)
codex exec \
  --full-auto \
  --json \
  --output-last-message findings.txt \
  --sandbox read-only \
  -m gpt-5.2-codex \
  "Review this code for bugs, security issues, and performance problems"
Structured Output with Schema
bash
# Define output schema
cat > review-schema.json << 'EOF'
{
  "type": "object",
  "properties": {
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "severity": { "enum": ["critical", "high", "medium", "low"] },
          "title": { "type": "string" },
          "file": { "type": "string" },
          "line": { "type": "integer" },
          "description": { "type": "string" },
          "suggestion": { "type": "string" }
        },
        "required": ["severity", "title", "file", "description"]
      }
    },
    "summary": { "type": "string" },
    "approved": { "type": "boolean" }
  },
  "required": ["findings", "summary", "approved"]
}
EOF

# Run with schema validation
codex exec \
  --output-schema review-schema.json \
  --output-last-message review.json \
  "Review the staged changes and output findings"

GitHub Integration

Option 1: PR Comment Trigger

In any pull request, add a comment:

@codex review

Codex will respond with a standard GitHub code review.

Option 2: GitHub Action
yaml
# .github/workflows/codex-review.yml
name: Codex Code Review

on:
  pull_request:
    types: [opened, synchronize]

jobs:
  review:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      pull-requests: write

    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - name: Codex Review
        uses: openai/codex-action@main
        with:
          openai_api_key: ${{ secrets.OPENAI_API_KEY }}
          model: gpt-5.2-codex
          safety_strategy: drop-sudo
Option 3: Manual Headless in CI
yaml
# .github/workflows/codex-review.yml
name: Codex Code Review

on:
  pull_request:

jobs:
  review:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0

      - uses: actions/setup-node@v4
        with:
          node-version: '22'

      - name: Install Codex CLI
        run: npm install -g @openai/codex

      - name: Run Review
        env:
          OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
        run: |
          # Get diff
          git diff origin/${{ github.base_ref }}...HEAD > diff.txt

          # Run Codex review
          codex exec \
            --full-auto \
            --sandbox read-only \
            --output-last-message review.md \
            "Review this git diff for bugs, security issues, and code quality: $(cat diff.txt)"

      - name: Post Review Comment
        uses: actions/github-script@v7
        with:
          script: |
            const fs = require('fs');
            const review = fs.readFileSync('review.md', 'utf8');
            github.rest.issues.createComment({
              owner: context.repo.owner,
              repo: context.repo.repo,
              issue_number: context.issue.number,
              body: `## 🤖 Codex Code Review\n\n${review}`
            });

GitLab CI/CD

yaml
# .gitlab-ci.yml
codex-review:
  image: node:22
  stage: review
  script:
    - npm install -g @openai/codex
    - |
      codex exec \
        --full-auto \
        --sandbox read-only \
        --output-last-message review.md \
        "Review the merge request changes for bugs and security issues"
    - cat review.md
  artifacts:
    paths:
      - review.md
  rules:
    - if: $CI_PIPELINE_SOURCE == "merge_request_event"

Jenkins Pipeline

groovy
pipeline {
    agent any

    environment {
        OPENAI_API_KEY = credentials('openai-api-key')
    }

    stages {
        stage('Install Codex') {
            steps {
                sh 'npm install -g @openai/codex'
            }
        }

        stage('Code Review') {
            steps {
                sh '''
                    codex exec \
                      --full-auto \
                      --sandbox read-only \
                      --output-last-message review.md \
                      "Review the code changes for bugs and security issues"
                '''
            }
        }

        stage('Publish Results') {
            steps {
                archiveArtifacts artifacts: 'review.md'
                script {
                    def review = readFile('review.md')
                    echo "Code Review Results:\n${review}"
                }
            }
        }
    }
}

Configuration

Config File
toml
# ~/.codex/config.toml

[model]
default = "gpt-5.2-codex"  # Best for code review

[sandbox]
default = "read-only"  # Safe for reviews

[review]
# Custom review instructions applied to all reviews
instructions = """
Focus on:
1. Security vulnerabilities (OWASP Top 10)
2. Performance issues (N+1 queries, memory leaks)
3. Error handling gaps
4. Type safety issues
"""
Per-Project Config
toml
# .codex/config.toml (in project root)

[review]
instructions = """
This is a Python FastAPI project. Focus on:
- Async/await correctness
- Pydantic model validation
- SQL injection via SQLAlchemy
- Authentication/authorization gaps
"""

CLI Quick Reference

bash
# Interactive
codex                          # Start TUI
/review                        # Open review presets

# Headless
codex exec "prompt"            # Non-interactive execution
codex exec --json "prompt"     # JSON output
codex exec --full-auto "prompt"  # No approval prompts

# Key Flags
--output-last-message FILE     # Save response to file
--output-schema FILE           # Validate against JSON schema
--sandbox read-only            # Restrict file access
-m gpt-5.2-codex              # Use best review model
--json                         # Machine-readable output

# Resume
codex exec resume SESSION_ID   # Continue previous session

Show full SKILL.md (168 more words)Show less

Comparison: Claude vs Codex Review

AspectClaude (Built-in)Codex CLI
SetupNone (already in Claude Code)Install CLI + auth
ModelClaudeGPT-5.2-Codex (specialized)
ContextFull conversation contextFresh context per review
IntegrationNativeGitHub, GitLab, Jenkins
OutputMarkdownJSON schema support
Best forQuick reviews, in-flowCI/CD, critical PRs

Security Considerations

CI/CD Safety
yaml
# Always use these flags in CI/CD:
--sandbox read-only           # Prevent file modifications
--safety-strategy drop-sudo   # Revoke elevated permissions
API Key Protection
yaml
# GitHub Actions - use secrets
env:
  OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}

# Never hardcode keys
# Never echo keys in logs
Public Repositories

For public repos, use drop-sudo safety strategy to prevent Codex from reading its own API key during execution.


Troubleshooting

IssueSolution
codex: command not foundRun npm install -g @openai/codex
Node.js version errorUpgrade to Node.js 22+
Authentication failedRe-run codex and sign in again
API key invalidCheck OPENAI_API_KEY env var
Timeout in CIAdd --timeout 300 flag
Rate limitedReduce frequency or upgrade plan

Anti-Patterns

  • Using --dangerously-bypass-approvals-and-sandbox casually - Only in isolated CI runners
  • Exposing API keys in logs - Use secrets management
  • Skipping sandbox in CI - Always use --sandbox read-only
  • Ignoring findings - Review and address or document exceptions
  • Running on every commit - Use on PRs only to save costs

© alinaqi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/codex-review of alinaqi/maggy.

Open the folder on GitHubat commit 72a456e

Compare with similar skills

Codex Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex Review this skillalinaqi/maggy707—~3kAutomated safety check: PassMIT
GitHub Actions Patbifrost-proxy/bifrost160—~2kAutomated safety check: PassMIT
Renovate Actions PR Reviewbacknotprop/plannotator9.3k—~640Automated safety check: PassApache-2.0
Openai Gh Fix CItrailofbits/skills-curated513—~955Automated safety check: NotesCC-BY-SA-4.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Agentic GitHub Actions Auditortrailofbits/skills7.5k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • GitHub Actions Pat

    bifrost-proxy/bifrost

    用 Personal Access Token 通过 GitHub REST API 分析 Actions CI 的失败 run/job/step、拉取日志、轮询运行状态、做 PR code review,并驱动 fix → push → watch → iterate 的闭环。Token 只从 GITHUBTOKEN 环境变量读取,不落盘、不回显。适合在 bifrost remote /…

    160 GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Renovate Actions PR Review

    backnotprop/plannotator

    Reviews Renovate pull requests that bump GitHub Actions by checking pinned SHAs against upstream tags, scanning changelogs and confirming workflows stay compatible.

    9.3k GitHub stars~640 tokensUpdated today
    DevelopmentAuto-check passed
  • Openai Gh Fix CI

    trailofbits/skills-curated

    Official

    A skill your agent uses when a user asks to debug or fix failing GitHub PR checks that run in GitHub Actions; use gh to inspect checks and logs, summarize failure context, draft a fix plan, and…

    513 GitHub stars~955 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check: notes
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.5k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • GitHub Automation

    ruvnet/ruflo

    GitHub workflow automation, PR management, issue tracking, and code review coordination.

    74k GitHub starsUsed in 2 repos~368 tokens
    DevelopmentAuto-check passed

More from alinaqi/maggy

All 71 skills in this repo
  • Aeo Optimization

    alinaqi/maggy

    AI Engine Optimization - semantic triples, page templates, content clusters for AI citations

    707 GitHub stars~3.7k tokensUpdated 16 days ago
    Auto-check passed
  • Agent Teams

    alinaqi/maggy

    Claude Code Agent Teams - default team-based development with strict TDD pipeline enforcement

    707 GitHub stars~5k tokensUpdated 16 days ago
    Auto-check: notes
  • AI Models

    alinaqi/maggy

    Latest AI models reference - Claude, OpenAI, Gemini, Eleven Labs, Replicate

    707 GitHub stars~4.1k tokensUpdated 16 days ago
    Auto-check passed
  • Android Java

    alinaqi/maggy

    Android Java development with MVVM, ViewBinding, and Espresso testing

    707 GitHub stars~3.9k tokensUpdated 16 days ago
    Auto-check: notes
  • Android Kotlin

    alinaqi/maggy

    Android Kotlin development with Coroutines, Jetpack Compose, Hilt, and MockK testing

    707 GitHub stars~3k tokensUpdated 16 days ago
    Auto-check passed
  • Autonomous Testing

    alinaqi/maggy

    AI-driven testing agent that auto-discovers, generates, executes, evaluates, and fixes tests for any project type

    707 GitHub stars~1.1k tokensUpdated 16 days ago
    Auto-check passed

Works with

Questions about Codex Review

What does Codex Review do?

OpenAI Codex CLI code review with GPT-5.2-Codex, CI/CD integration. Codex Review is an agent skill from alinaqi/maggy.

When should I use Codex Review?

Codex Review fits situations like: tasks that involve CI/CD; tasks that involve Code review.

How do I install Codex Review in Claude Code?

Run `npx skills add alinaqi/maggy --skill codex-review -a claude-code`. Or copy the skill folder (skills/codex-review in alinaqi/maggy) into .claude/skills/codex-review in your project. Claude Code loads it when a task matches its description.

How do I install Codex Review in Codex?

Run `npx skills add alinaqi/maggy --skill codex-review -a codex`. Or copy the skill folder (skills/codex-review in alinaqi/maggy) into .agents/skills/codex-review in your project. Codex loads it when a task matches its description.

Can I use Codex Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alinaqi/maggy --skill codex-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-review, .gemini/skills/codex-review, .github/skills/codex-review and .opencode/skills/codex-review in your project.

What does Codex Review need to run?

Going by SKILL.md and its folder, Codex Review needs the command-line tools its instructions call (codex, brew, nvm, npm and node) and credentials named OPENAI_API_KEY. Our summary lists: Python 3; Node.js; A credential in OPENAI_API_KEY.

Does Codex Review access the network?

SKILL.md names 3 domains. As links in the text: developers.openai.com, github.com and cookbook.openai.com. This is read from the text; nothing was executed.

Is Codex Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codex Review use?

Codex Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex Review use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codex Review?

Skills that share tags, products or a category with Codex Review: GitHub Actions Pat (bifrost-proxy/bifrost, 160 stars), Renovate Actions PR Review (backnotprop/plannotator, 9.3k stars), Openai Gh Fix CI (trailofbits/skills-curated, 513 stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex Review?

alinaqi (a GitHub user) maintains it in alinaqi/maggy, which has 707 GitHub stars. The repository holds 71 skills in this directory. The repository was last updated on September 24, 2026.

Source: alinaqi/maggy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.