Codex Review
alinaqi/maggy
OpenAI Codex CLI code review with GPT-5.2-Codex, CI/CD integration
AI-powered code review for diffs and individual files using LLM analysis
$ npx skills add initializ/forge --skill code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install initializ/forge code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/initializ/forge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/forge-skills/local/embedded/code-review .claude/skills/code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "code-review" agent skill from https://github.com/initializ/forge/tree/main/forge-skills/local/embedded/code-review into .claude/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/initializ/forge/tree/main/forge-skills/local/embedded/code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add initializ/forge --skill code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install initializ/forge code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/initializ/forge.git skills-src && mkdir -p .agents/skills && cp -r skills-src/forge-skills/local/embedded/code-review .agents/skills/code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "code-review" agent skill from https://github.com/initializ/forge/tree/main/forge-skills/local/embedded/code-review into .agents/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add initializ/forge --skill code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install initializ/forge code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/initializ/forge.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/forge-skills/local/embedded/code-review .cursor/skills/code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "code-review" agent skill from https://github.com/initializ/forge/tree/main/forge-skills/local/embedded/code-review into .cursor/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/initializ/forge.git --path forge-skills/local/embedded/code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add initializ/forge --skill code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install initializ/forge code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/initializ/forge.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/forge-skills/local/embedded/code-review .gemini/skills/code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/initializ/forge/tree/main/forge-skills/local/embedded/code-review into .gemini/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install initializ/forge code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add initializ/forge --skill code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/initializ/forge.git skills-src && mkdir -p .github/skills && cp -r skills-src/forge-skills/local/embedded/code-review .github/skills/code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/initializ/forge/tree/main/forge-skills/local/embedded/code-review into .github/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add initializ/forge --skill code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install initializ/forge code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/initializ/forge.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/forge-skills/local/embedded/code-review .opencode/skills/code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "code-review" agent skill from https://github.com/initializ/forge/tree/main/forge-skills/local/embedded/code-review into .opencode/skills/code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
code-reviewAI-powered code review for diffs and individual files using LLM analysis
Code Review is an agent skill from initializ/forge. AI-powered code review for diffs and individual files using LLM analysis
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `scripts/code-review-diff.sh` and `scripts/code-review-file.sh`).
It sits in Development, covering Code review. It works with OpenAI, GitHub and Anthropic API. The repository describes itself as: Forge is the open-source runtime for Anthropic's Agent Skills standard — built for the agent that runs next to a service, in your environment, on infrastructure you already… The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 3c608d8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comapi.openai.comapi.together.aiFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ANTHROPIC_API_KEYOPENAI_API_KEYGH_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Code Review loads about 3k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 1,291 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from initializ/forge at commit 3c608d8, republished under its Apache-2.0 licence (© initializ). 1,291 words, ~3,003 tokens.
.claude/skills/code-review/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.AI-powered code review that analyzes diffs and individual files for bugs, security issues, style violations, and improvement opportunities. Supports both local git diffs and GitHub pull requests.
Set at least one LLM API key:
# Option A: Anthropic
export ANTHROPIC_API_KEY="sk-ant-..."
# Option B: OpenAI or any OpenAI-compatible provider (Together, OpenRouter, Groq, ...)
export OPENAI_API_KEY="sk-..."
export OPENAI_BASE_URL="https://api.together.ai/v1" # only when not using openai.com
# Optional: override the model (defaults: claude-sonnet-4-20250514 / gpt-4o)
export REVIEW_MODEL="moonshotai/Kimi-K2.6"
# Optional: force a specific provider when both keys are set
export REVIEW_PROVIDER="openai" # or "anthropic"Provider selection (auto-detected when REVIEW_PROVIDER is unset):
REVIEW_PROVIDER is set, it wins.REVIEW_MODEL starts with claude- or anthropic/, use Anthropic.This precedence fixes the common deployment where both ANTHROPIC_API_KEY and OPENAI_API_KEY live in .forge/secrets.enc (one is stale or for a different skill). Pre-fix the skill always preferred Anthropic and returned 401 against the stale key.
For GitHub PR review, also set:
export GH_TOKEN="ghp_..."The token needs read-only access:
| Scope (classic PAT) | Fine-grained permission | Why |
|---|---|---|
repo (or public_repo for public repos) | Contents: Read | Fetch PR diff and file contents |
This skill only reads diffs — it never posts comments, applies labels, or merges. For write operations, see the code-review-github skill.
| Variable | Required | Description |
|---|---|---|
| ANTHROPIC_API_KEY | one-of | Anthropic API key |
| OPENAI_API_KEY | one-of | OpenAI or OpenAI-compatible (Together, OpenRouter, Groq, ...) API key |
| REVIEW_PROVIDER | no | Explicit provider override: anthropic or openai. When unset, auto-detected from REVIEW_MODEL prefix, then by which key is set. Prefers openai when both keys exist and no model hint disambiguates |
| REVIEW_MODEL | no | Override LLM model name. Default: claude-sonnet-4-20250514 (anthropic) / gpt-5.4 (openai) |
| REVIEW_MAX_DIFF_BYTES | no | Max diff size before truncation (default: 100000) |
| GH_TOKEN | no | GitHub token for PR diffs — read-only access is sufficient |
| FORGE_REVIEW_STANDARDS_DIR | no | Path to .forge-review/standards/ directory for custom rules |
| OPENAI_BASE_URL | no | Base URL for OpenAI-compatible providers (default: https://api.openai.com/v1). Always uses /chat/completions — see OPENAI_USE_RESPONSES_API for the proprietary Responses API |
| OPENAI_USE_RESPONSES_API | no | Set to 1 to use OpenAI's proprietary /responses endpoint (Codex/OAuth flow). Default off. Only relevant when OPENAI_BASE_URL points at api.openai.com |
Review a code diff for bugs, security issues, and improvements. Accepts either a GitHub PR URL or a local git base ref.
Default behavior: When the user says "review my local changes" or "review changes in <path>" WITHOUT specifying a base branch, default to base_ref: "HEAD". This reviews uncommitted and untracked files — the user's work-in-progress. Do NOT ask the user for a base ref in this case. Only use main/develop as base_ref when the user explicitly says "against main" or "against develop".
Input:
| Parameter | Type | Required | Description |
|---|---|---|---|
| pr_url | string | no | GitHub PR URL (e.g., https://github.com/owner/repo/pull/123) |
| base_ref | string | no | Git ref to compare from. Default: HEAD (uncommitted changes). Use main only if user says "against main" |
| repo_path | string | no | Absolute path to the local git repository. Required when using base_ref |
| focus | string | no | Review focus: bugs, security, style, all. Default: all |
| extra_context | string | no | Additional context or instructions for the reviewer |
One of pr_url or base_ref is required. When using base_ref, repo_path must point to the user's local repository (scripts run in the agent's directory, not the user's project).
Output: JSON object with structured review findings.
User says → tool input mapping:
| User request | Tool input |
|---|---|
| "Review code changes against main in ~/myproject" | {"base_ref": "main", "repo_path": "~/myproject"} |
| "Review my changes since develop in /opt/app" | {"base_ref": "develop", "repo_path": "/opt/app"} |
| "Review the last 3 commits in ~/myproject for security issues" | {"base_ref": "HEAD~3", "repo_path": "~/myproject", "focus": "security"} |
| "Review changes on the feature/auth branch in ~/myproject" | {"base_ref": "main", "repo_path": "~/myproject"} |
| "Review my local changes in ~/myproject" | {"base_ref": "HEAD", "repo_path": "~/myproject"} |
| "Review my uncommitted changes in ~/myproject" | {"base_ref": "HEAD", "repo_path": "~/myproject"} |
| "Review this PR https://github.com/org/repo/pull/42" | {"pr_url": "https://github.com/org/repo/pull/42"} |
| "Security audit on PR 99 in org/repo" | {"pr_url": "https://github.com/org/repo/pull/99", "focus": "security"} |
Important:
repo_path exactly as the user provides it. The script handles ~ expansion internally — do NOT try to resolve ~ yourself (you do not know the user's home directory). For example, if the user says ~/myproject, pass "repo_path": "~/myproject".repo_path is required because the script runs in the agent's working directory, not the user's project directory.base_ref is the starting point to compare FROM. It is NOT the branch being reviewed — it is the base that changes are measured against. The diff includes both committed and uncommitted (working tree) changes relative to base_ref.base_ref can be a branch name (main, develop), a commit SHA, or a relative ref (HEAD~3). The script uses git merge-base to find the fork point, so only changes on the current branch are reviewed.HEAD~N to narrow the review scope to the most recent N commits. For example, HEAD~5 reviews only the last 5 commits.main (or the repo's default branch) as base_ref — NOT the branch name itself.HEAD as base_ref to show only unstaged/staged changes.Before calling code_review_diff with a base_ref, the agent MUST run cli_execute to check the diff scope:
cd <repo_path> && git log --oneline <base_ref>..HEAD | head -20This shows how many commits will be reviewed. If there are more than ~5 commits:
<base_ref> and HEAD. This includes: [list first few commit subjects]."HEAD~3."code_review_diff after the user confirms the scope.This prevents reviewing unrelated changes from older commits or merged PRs on long-lived branches.
The agent selects this tool when it detects:
{
"summary": "Brief overall assessment",
"risk_level": "low|medium|high|critical",
"findings": [
{
"file": "path/to/file.go",
"line": 42,
"severity": "error|warning|info|nitpick",
"category": "bug|security|style|performance|maintainability",
"title": "Short finding title",
"description": "Detailed explanation of the issue",
"suggestion": "Suggested fix or improvement"
}
],
"stats": {
"files_reviewed": 5,
"total_findings": 3,
"by_severity": {"error": 1, "warning": 1, "nitpick": 1}
}
}focus: security for security-focused auditsbase_ref: main to review all uncommitted changes against mainREVIEW_MAX_DIFF_BYTES (default 100KB)FORGE_REVIEW_STANDARDS_DIR to apply org-specific coding standardsDeep review of a single file with full context (not just diff). Useful for thorough analysis of critical files.
Input:
| Parameter | Type | Required | Description |
|---|---|---|---|
| file_path | string | yes | Path to the file to review (relative to repo root, or absolute path) |
| repo_path | string | no | Absolute path to the local repository. Required for local file review (scripts run in the agent's directory, not the user's project) |
| pr_url | string | no | If set, fetches the file from the PR head branch |
| focus | string | no | Review focus: bugs, security, style, all. Default: all |
| extra_context | string | no | Additional context or instructions for the reviewer |
Output: Same JSON structure as code_review_diff.
User says → tool input mapping:
| User request | Tool input |
|---|---|
| "Review the file src/server.go in ~/myproject" | {"file_path": "src/server.go", "repo_path": "~/myproject"} |
| "Security audit on cmd/main.go in /opt/app" | {"file_path": "cmd/main.go", "repo_path": "/opt/app", "focus": "security"} |
| "Review auth.py from PR #42 in org/repo" | {"file_path": "auth.py", "pr_url": "https://github.com/org/repo/pull/42"} |
Important: For local file review, repo_path is required. file_path is relative to the repo root. Resolve ~ to the absolute home directory path.
The agent selects this tool when it detects:
code_review_diff for comprehensive PR review: diff-level first, then deep-dive on flagged filesegress_domains)© initializ, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts) in forge-skills/local/embedded/code-review of initializ/forge.
Open the folder on GitHubat commit 3c608d8
Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Code Review this skillinitializ/forge | 223 | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Codex Reviewalinaqi/maggy | 707 | — | ~3k | Automated safety check: Pass | MIT | |
| PR Babysitteropeninterpreter/openinterpreter | 69k | 3 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Get API Docs with chubandrewyng/context-hub | 14k | 2 repos | ~775 | Automated safety check: Pass | MIT | |
| Open Code Review CLIalibaba/open-code-review | 44k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| GitHub Review Iterationprisma/orm | 48k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 |
alinaqi/maggy
OpenAI Codex CLI code review with GPT-5.2-Codex, CI/CD integration
openinterpreter/openinterpreter
Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.
andrewyng/context-hub
Fetches current documentation for third-party APIs and SDKs with the chub CLI before the agent writes code against them, instead of relying on remembered API shapes.
alibaba/open-code-review
Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.
prisma/orm
Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.
microsoft/garnet
Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.
initializ/forge
Turn a task description and repository into a structured implementation plan (files to create, files to modify, tests to add, risks).
initializ/forge
Scaffold and iterate on standalone Preact + HTM applications with zero build dependencies
initializ/forge
General-purpose coding agent that reads, writes, and edits code, and searches codebases.
initializ/forge
Scaffold and iterate on Vite + React applications. An agent skill from initializ/forge.
initializ/forge
Estimate Kubernetes infrastructure costs by querying cluster node, pod, PVC/PV, and LoadBalancer data, applying cloud pricing models, and producing cost attribution reports with storage and…
initializ/forge
Analyze Kubernetes workload metrics and produce policy-constrained CPU/memory rightsizing recommendations with optional patch generation and rollback-safe apply.
Works with
Categories
AI-powered code review for diffs and individual files using LLM analysis. Code Review is an agent skill from initializ/forge.
Code Review fits situations like: tasks that involve Code review.
Run `npx skills add initializ/forge --skill code-review -a claude-code`. Or copy the skill folder (forge-skills/local/embedded/code-review in initializ/forge) into .claude/skills/code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add initializ/forge --skill code-review -a codex`. Or copy the skill folder (forge-skills/local/embedded/code-review in initializ/forge) into .agents/skills/code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add initializ/forge --skill code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-review, .gemini/skills/code-review, .github/skills/code-review and .opencode/skills/code-review in your project.
Going by SKILL.md and its folder, Code Review needs a shell for the scripts in its folder, the command-line tools its instructions call (git) and credentials named ANTHROPIC_API_KEY, OPENAI_API_KEY and GH_TOKEN. Our summary lists: A Bash shell; A credential in ANTHROPIC_API_KEY; A credential in OPENAI_API_KEY.
SKILL.md names 3 domains. In commands or code: github.com, api.openai.com and api.together.ai; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Code Review: Codex Review (alinaqi/maggy, 707 stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Get API Docs with chub (andrewyng/context-hub, 14k stars) and Open Code Review CLI (alibaba/open-code-review, 44k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
initializ (a GitHub organization) maintains it in initializ/forge, which has 223 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 1, 2026.
Source: initializ/forge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.