Agent skill

Codex Review

by ClickHouse in ClickHouse/ClickHouse

Run a local pre-push AI code review of the current branch with the OpenAI codex CLI, the same way ClickHouse CI does, and optionally iterate fix and re-review until clean.

Apache-2.0Auto-check: notesDatabases

Install Codex Review

skills CLI
$ npx skills add ClickHouse/ClickHouse --skill codex-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ClickHouse/ClickHouse codex-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ClickHouse/ClickHouse.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/codex-review .claude/skills/codex-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex-review
GitHub stars
50k
Token cost
~1.8k tokens
SKILL.md length
835 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a local pre-push AI code review of the current branch with the OpenAI codex CLI, the same way ClickHouse CI does, and optionally iterate fix and re-review until clean.

  • Works in 6 steps: Check codex → Model and effort (asked once, persisted) → Find the base commit → …
  • Asked to review the current branch before pushing
  • SKILL.md covers Arguments, 1. Check codex, 2. Model and effort (asked… and 3. Find the base commit, plus 3 more sections
  • Calls git, codex and npm; needs OPENAI_API_KEY

What it does

Codex Review is an agent skill from ClickHouse/ClickHouse. Run a local pre-push AI code review of the current branch with the OpenAI codex CLI, the same way ClickHouse CI does, and optionally iterate fix and re-review until clean. Use when asked to review the current branch before pushing, run "the codex review" / "the AI review" locally, or get an independent second opinion on a diff. Not for reviewing someone else's PR on GitHub (CI already does that).

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering Data warehousing. It works with ClickHouse and GitHub. The repository describes itself as: ClickHouse® is a real-time analytics database management system. The licence is Apache-2.0.

When your agent uses it

  • Asked to review the current branch before pushing
  • Run the codex review / the AI review locally
  • Get an independent second opinion on a diff

Example prompts

  • “the codex review”
  • “the AI review”
  • “/codex-review”

Requirements

  • Node.js
  • A credential in OPENAI_API_KEY
  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob, Edit, Write, AskUserQuestion

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Check codex
  2. Model and effort (asked once, persisted)
  3. Find the base commit
  4. Run the review
  5. Present the findings
  6. Fix and re-review (optional)

What it can do on your machine

Read from SKILL.md and the folder at commit c873902. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob
    • Edit
    • Write
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • codex
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex Review loads about 1.8k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 835 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob, Edit, Write, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ClickHouse/ClickHouse at commit c873902, republished under its Apache-2.0 licence (© ClickHouse). 835 words, ~1,833 tokens.

Download SKILL.mdSave it as .claude/skills/codex-review/SKILL.md (or your agent's skills folder).
name
codex-review
description
Run a local pre-push AI code review of the current branch with the OpenAI `codex` CLI, the same way ClickHouse CI does, and optionally iterate fix and re-review until clean. Use when asked to review the current branch before pushing, run "the codex review" / "the AI review" locally, or get an independent second opinion on a diff. Not for reviewing someone else's PR on GitHub (CI already does that).
allowed-tools
Bash, Read, Grep, Glob, Edit, Write, AskUserQuestion
argument-hint
[--fix] [--model]
disable-model-invocation
false

Local codex review

Run the same AI review CI runs (ci/jobs/copilot_review_job.py), but locally against the current branch, before pushing. The point is an independent model with a general prompt: a Claude subagent shares this session's context and blind spots. Spawn a real codex process, never a subagent.

Arguments

  • --fix: after the review, fix verified findings and re-review until clean (step 6) without asking.
  • --model: ask for the model and effort again even if they are already saved (step 2).

1. Check codex

bash
codex --version && codex login status
  • codex missing: stop and tell the user to install it (npm install -g @openai/codex).
  • Not logged in: stop and ask the user to authenticate themselves with any method codex supports (! codex login for the ChatGPT browser flow, or codex login --with-api-key / codex login --with-access-token in their own terminal), then re-run the skill. Never run codex login yourself, never set CODEX_HOME or OPENAI_API_KEY, and never ask the user to paste a key or token into the session. ClickHouse Inc. members can request access through the internal AI tools onboarding guide.

2. Model and effort (asked once, persisted)

The choice is stored in the user's global git config, so it survives across sessions and worktrees:

bash
MODEL=$(git config --global --get codex-review.model)
EFFORT=$(git config --global --get codex-review.effort)

If either is empty, or --model was passed, find the model CI uses:

bash
grep -oP 'f"-m \K[\w.-]+' ci/jobs/copilot_review_job.py | head -1

Ask with AskUserQuestion (one call, two questions):

  • Model: the CI model (Recommended), plus codex default (pass no -m; codex uses its own ~/.codex/config.toml). The user can type any other model name via "Other".
  • Effort: xhigh (Recommended, same as CI), high, medium.

Persist the answers (default for the codex default model):

bash
git config --global codex-review.model "<model>"
git config --global codex-review.effort "<effort>"

Tell the user which model/effort is used and that /codex-review --model changes it.

3. Find the base commit

Use the local remote-tracking refs only. Do not git fetch: the review must not change the user's refs.

Find the remote that points to the upstream repository, ClickHouse/ClickHouse or ClickHouse/ClickHouse-private (it may be called origin, upstream, blessed, private...):

bash
git remote -v | awk '$3 == "(fetch)" && tolower($2) ~ /[:\/]clickhouse\/clickhouse(-private)?(\.git)?$/ { print $1 }'
BASE_REF="<remote>/master"
git rev-parse --verify -q "$BASE_REF^{commit}"
  • Exactly one match: use it.
  • Several matches (a checkout with both the public and the private remote): use the one whose <remote>/master has the newer merge-base with HEAD; if they are equal, ask the user.
  • No such remote, or $BASE_REF does not exist: stop and ask the user which ref to diff against. Do not guess a local master (it is often stale or has local commits).
  • If the user named a different base (e.g. a release branch), use it instead.

Then compute and verify the merge-base:

bash
BASE=$(git merge-base "$BASE_REF" HEAD)
git log -1 --format='%h %cs %s' "$BASE"
git log --oneline "$BASE"..HEAD
git status --short
  • $BASE equals HEAD (no commits to review): stop and say so.
  • Show the user $BASE_REF, the merge-base (hash, date, subject) and the commit count before running.
  • Uncommitted changes are not part of git diff $BASE...HEAD. Mention them and ask whether to commit first; do not include them silently.
Show full SKILL.md (386 more words)Show less

4. Run the review

Keep the prompt as close to CI's as possible and general. Do NOT add invariant lists, "pay attention to X", focus files, a description of the fix, or anything that steers toward the solution you have in mind. Steering is exactly what makes the review miss things.

Local binaries are the one addition: if you built the branch in this session (or the user told you where a build of it is), tell codex the absolute path of the binary so it can reproduce scenarios instead of reasoning about them. Say only where it is and that it may be older than HEAD; do not say what to run. Leave BINARY_NOTE empty if you do not know of a build of this branch; do not search for one.

bash
mkdir -p tmp
N=$(( $(ls tmp/codex_review_*.log 2>/dev/null | wc -l) + 1 ))
BINARY_NOTE=""   # e.g. "A ClickHouse binary built from this branch is at /abs/build/programs/clickhouse (may be older than HEAD)."
PROMPT="Follow the Review Instructions in .claude/skills/review/SKILL.md.
Repo is checked out at the branch to review.

Review the changes on the current branch. Get the diff with 'git diff ${BASE}...HEAD' and read the
current code, not only the diff.
${BINARY_NOTE}
Write the review to stdout using the REQUESTED OUTPUT FORMAT from .claude/skills/review/SKILL.md.
Do not use gh and do not post anything."

MODEL_ARGS=(); [ "$MODEL" != default ] && MODEL_ARGS=(-m "$MODEL")
codex exec "${MODEL_ARGS[@]}" -c "model_reasoning_effort=$EFFORT" \
  -s workspace-write -c approval_policy=never --color never "$PROMPT" < /dev/null \
  > "tmp/codex_review_$N.log" 2>&1
  • Run from the repo root, in the background (it takes many minutes); you are notified when it exits.
  • No network access flag: unlike CI it must not use gh or post anything.
  • Read the final review from the end of the log (the part after the last codex marker).

5. Present the findings

For each finding: what it claims, file:line, and whether it holds. Verify every finding against the current code before calling it real; model reviews produce false positives. If a finding describes a concrete failing scenario (an input, a query, a sequence of operations), reproduce it first (run the query, write the failing test) and treat the finding as confirmed only if the reproduction fails; reading the code is not enough. Say which ones you confirmed, which you refuted (and why), and which you could not decide.

Then stop, unless --fix was passed: ask the user whether to fix the confirmed findings and re-review. A "Block" verdict is not a mandate to fix.

6. Fix and re-review (optional)

Only with --fix or the user's go-ahead:

  1. Fix the confirmed findings. Skip refuted ones.
  2. Commit the fixes (new commit, respecting the user's commit rules) so git diff $BASE...HEAD sees them.
  3. Re-run step 4 with a fresh codex exec and the same general prompt.
  4. Repeat until no correctness defects remain.
  5. Findings asking for tests or benchmark evidence are PR-level decisions: surface them to the user.

Report the outcome faithfully: which findings were real and fixed, which were refuted and why.

© ClickHouse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/codex-review of ClickHouse/ClickHouse.

Open the folder on GitHubat commit c873902

Compare with similar skills

Codex Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex Review this skillClickHouse/ClickHouse50k—~1.8kAutomated safety check: NotesApache-2.0
Datasources Provisioninggrafana/skills281—~2.8kAutomated safety check: PassApache-2.0
Clickhouse Logs Queriessupabase/supabase111k—~2.4kAutomated safety check: PassApache-2.0
Chdb SQLvemetric/vemetric3951 repos~1.2kAutomated safety check: PassApache-2.0
Clickhouse Architecture Advisorvemetric/vemetric3952 repos~791Automated safety check: PassApache-2.0
Observal AdminObserval/Observal4.3k—~774Automated safety check: PassApache-2.0

Similar skills

  • Official

    Generate a copy-paste Grafana data source provisioning file (YAML or Terraform) for any plugin from its standardized settings schema on the plugins CDN.

    281 GitHub stars~2.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Clickhouse Logs Queries

    supabase/supabase

    Official

    Write, review, and migrate Supabase logs queries against the ClickHouse-backed logs table (the logs.all.otel analytics endpoint).

    111k GitHub stars~2.4k tokensUpdated today
    DatabasesAuto-check passed
  • Chdb SQL

    vemetric/vemetric

    A skill your agent uses when the user wants to run SQL — especially analytical SQL — on local files (parquet/csv/json), URLs, S3 paths, or remote databases (Postgres, MySQL, MongoDB, ClickHouse…

    395 GitHub starsUsed in 1 repo~1.2k tokens
    DatabasesAuto-check passed
  • MUST USE when designing ClickHouse architectures, selecting between ingestion or modeling patterns, or translating best practices into workload-specific system designs.

    395 GitHub starsUsed in 2 repos~791 tokens
    DatabasesAuto-check passed
  • Observal Admin

    Observal/Observal

    Administers Observal users, settings, diagnostics, review queues, security events, audit logs, SAML, SCIM, the local Observal server, its upgrades and rollback, and its own PostgreSQL and ClickHouse…

    4.3k GitHub stars~774 tokensUpdated yesterday
    DatabasesAuto-check passed
  • ClickHouse RowBinary for Node.js

    ClickHouse/agent-skills

    Generates TypeScript or JavaScript readers and writers for ClickHouse's RowBinary formats over HTTP in Node.js, after checking that RowBinary suits the data.

    544 GitHub stars~1.3k tokensUpdated 10 days ago
    DatabasesAuto-check passed

More from ClickHouse/ClickHouse

All 24 skills in this repo
  • Keeper Stress Analysis

    ClickHouse/ClickHouse

    Analyze ClickHouse Keeper stress-test results from play.clickhouse.com / keeperstresstests data warehouse.

    50k GitHub stars~4.7k tokensUpdated today
    Auto-check passed
  • Perf Comparison

    ClickHouse/ClickHouse

    Evaluate ClickHouse performance test results from existing CI/dashboard data or local perf.py runs.

    50k GitHub stars~3.9k tokensUpdated today
    Auto-check: notes
  • Patch Release Check

    ClickHouse/ClickHouse

    Check whether ClickHouse's supported versions (last 3 majors + latest LTS) have recent stable patch releases, diagnose why the scheduled AutoReleases pipeline failed, and identify which releases…

    50k GitHub stars~4k tokensUpdated today
    Auto-check: notes
  • Alloc Profile

    ClickHouse/ClickHouse

    Analyze a jemalloc (or other) allocation profile in collapsed stack format.

    50k GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Bisect

    ClickHouse/ClickHouse

    Bisect a ClickHouse regression using pre-built master binaries from CI.

    50k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Clickhouse PR Description

    ClickHouse/ClickHouse

    Generate PR descriptions for ClickHouse/ClickHouse that match maintainer expectations.

    50k GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Categories

Questions about Codex Review

What does Codex Review do?

Run a local pre-push AI code review of the current branch with the OpenAI codex CLI, the same way ClickHouse CI does, and optionally iterate fix and re-review until clean. Codex Review is an agent skill from ClickHouse/ClickHouse. Run a local pre-push AI code review of the current branch with the OpenAI codex CLI, the same way ClickHouse CI does, and optionally iterate fix and re-review until clean.

When should I use Codex Review?

Codex Review fits situations like: asked to review the current branch before pushing; run the codex review / the AI review locally; get an independent second opinion on a diff.

How do I install Codex Review in Claude Code?

Run `npx skills add ClickHouse/ClickHouse --skill codex-review -a claude-code`. Or copy the skill folder (.claude/skills/codex-review in ClickHouse/ClickHouse) into .claude/skills/codex-review in your project. Claude Code loads it when a task matches its description.

How do I install Codex Review in Codex?

Run `npx skills add ClickHouse/ClickHouse --skill codex-review -a codex`. Or copy the skill folder (.claude/skills/codex-review in ClickHouse/ClickHouse) into .agents/skills/codex-review in your project. Codex loads it when a task matches its description.

Can I use Codex Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ClickHouse/ClickHouse --skill codex-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-review, .gemini/skills/codex-review, .github/skills/codex-review and .opencode/skills/codex-review in your project.

What does Codex Review need to run?

Going by SKILL.md and its folder, Codex Review needs the command-line tools its instructions call (git, codex and npm) and credentials named OPENAI_API_KEY. Our summary lists: Node.js; A credential in OPENAI_API_KEY. Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob, Edit, Write, AskUserQuestion.

Does Codex Review access the network?

SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codex Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Codex Review use?

Codex Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex Review use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codex Review?

Skills that share tags, products or a category with Codex Review: Datasources Provisioning (grafana/skills, 281 stars), Clickhouse Logs Queries (supabase/supabase, 111k stars), Chdb SQL (vemetric/vemetric, 395 stars) and Clickhouse Architecture Advisor (vemetric/vemetric, 395 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex Review?

ClickHouse (a GitHub organization) maintains it in ClickHouse/ClickHouse, which has 50,308 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 9, 2026.

Source: ClickHouse/ClickHouse on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.