Agent skill

Codex PR Review

by Mentra-Community in Mentra-Community/MentraOS

Run an independent local Codex (gpt-6.1-sol, medium) review of a GitHub pull request and relay its verdict.

Apache-2.0Auto-check passedDevelopment

Install Codex PR Review

skills CLI
$ npx skills add Mentra-Community/MentraOS --skill codex-pr-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Mentra-Community/MentraOS codex-pr-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Mentra-Community/MentraOS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/codex-pr-review .claude/skills/codex-pr-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex-pr-review
GitHub stars
2.4k
Token cost
~3.1k tokens
SKILL.md length
1,483 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run an independent local Codex (gpt-6.1-sol, medium) review of a GitHub pull request and relay its verdict.

  • Every PR an agent opens
  • SKILL.md covers What the script does, Configuration, Tests and Extra prompt file, plus 1 more section
  • Calls codex, git and gh; needs MENTRA_RELEASE_COORDINATOR_KEY
  • Whenever the user asks to review a PR with Codex

What it does

Codex PR Review is an agent skill from Mentra-Community/MentraOS. Run an independent local Codex (gpt-6.1-sol, medium) review of a GitHub pull request and relay its verdict. Use for every PR an agent opens or updates, and whenever the user asks to review a PR "with Codex". The review is posted on the PR as approve / request-changes; it never edits, commits or merges.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests. It works with GitHub. The repository describes itself as: MentraOS is the leading smart glasses OS. See live captions, stream your view, talk to AI, and capture photos hands-free on compatible glasses. The licence is Apache-2.0.

When your agent uses it

  • Every PR an agent opens
  • Whenever the user asks to review a PR with Codex

Example prompts

  • “with Codex”
  • “/codex-pr-review”

Requirements

  • Node.js
  • A credential in MENTRA_RELEASE_COORDINATOR_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit bc626e0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • codex
    • git
    • gh
    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.chatgpt.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • MENTRA_RELEASE_COORDINATOR_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex PR Review loads about 3.1k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 1,483 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Mentra-Community/MentraOS at commit bc626e0, republished under its Apache-2.0 licence (© Mentra-Community). 1,483 words, ~3,069 tokens.

Download SKILL.mdSave it as .claude/skills/codex-pr-review/SKILL.md (or your agent's skills folder).
name
codex-pr-review
description
Run an independent local Codex (gpt-6.1-sol, medium) review of a GitHub pull request and relay its verdict. Use for every PR an agent opens or updates, and whenever the user asks to review a PR "with Codex". The review is posted on the PR as approve / request-changes; it never edits, commits or merges.

Local Codex PR review

One command does everything. Run it in the background and wait for it; do not re-verify the Codex binary, the scripts, the token minter or the gh login first. The script fails loudly if anything is missing.

bash
nohup scripts/codex-review/codex-pr-review.sh <repo-dir> <pr-number> [extra-prompt-file] > <log> 2>&1 &

Then wait on the log (until grep -q 'codex-pr-review: done\|FAILED' <log>; do sleep 15; done) and keep working. Every exit path prints exactly one of those markers, including preflight failures. A run normally takes 5-20 minutes. The watchdog kills an attempt, with every process it spawned, after 8 minutes without an event from the Codex process, or 30 minutes total, and retries once unless the verdict was already posted. Never launch a bare codex exec for a review.

What the script does

  • Fetches the PR head into the sibling worktree <repo-dir>-pr-<n>, so the main checkout is never touched. If GitHub has not advertised the PR's Git pull ref yet, it fetches the exact head from the PR API and rechecks that head before starting the review. It never substitutes a moving branch tip. The tool marks worktrees it created with a <repo-dir>-pr-<n>.codex-review-owned sentinel; on reruns it resets and cleans only those (ignored files such as node_modules are kept) and refuses a path at that location it did not create. A per-PR lock refuses a second concurrent run; a lock whose owner is dead is reclaimed through a short-lived <lock>.reclaim mutex, so two reclaimers cannot clobber each other. Cancelling the script (Ctrl-C, SIGTERM) stops the runner and every process of the attempt before the lock is released; the runner pid is kept in the lock so a runner that outlives a hard-killed wrapper still counts as live. A worktree created by an earlier version of the script has no sentinel: add the file by hand (any content) or remove the worktree with git worktree remove.
  • Chooses the posting account. GitHub refuses a formal review from the PR author, so a PR authored by the logged-in gh user posts through a mentra-release-coordinator GitHub App token minted by mentra-release-coordinator-token.mjs; anyone else's PR posts from the logged-in account. Override with GH_ACCOUNT=app|own.
  • Writes the standard prompt: read the diff against the base, read every existing comment (bots included) and judge each on its merits, favour low complexity and a coherent design over patchy fixes, no edits or pushes, and finish with gh pr review <n> --approve or --request-changes whose body starts with Reviewed by local Codex (gpt-6.1-sol, medium). and lists what was checked. If GitHub refuses the formal review it falls back to --comment with Approve. or Request changes. as the first line.
  • Always adds an "Is this change needed?" step: Codex must judge whether the change is needed or desirable for the project at all (real problem, existing or planned alternative, surface area and maintenance cost versus benefit, smaller change possible) and let that weigh in the verdict, not only implementation quality.
  • Runs codex-review.sh (watchdog + one retry) and prints Codex's final message. The runner starts codex exec --json by default, or the small stdio app-server adapter for a configured desktop project. Both use their own server event stream as the heartbeat, so other Codex sessions on the machine can never be mistaken for this one; every process of the attempt carries a unique CODEX_REVIEW_ATTEMPT marker so it can be terminated even if Codex exits first. Success means a review carrying the marker was found on the head commit after the run started, checked through the GitHub API by review-receipt.sh; the runner performs the same check before any retry so a verdict posted just before a crash is never duplicated. Artifacts: $CODEX_REVIEW_HOME/<repo>-pr-<n>-<timestamp>/{prompt.txt,last-message.txt,runner.log,events-<attempt>.jsonl} (default ~/.codex-reviews).

Configuration

Use a desktop Review project

On the host that runs reviews, create a folder and add it as a local Codex project named Review. Save its absolute path once:

bash
mkdir -p "$HOME/dev/Codex-Reviews" "${CODEX_REVIEW_HOME:-$HOME/.codex-reviews}"
printf '%s\n' "$HOME/dev/Codex-Reviews" > "${CODEX_REVIEW_HOME:-$HOME/.codex-reviews}/project-directory"

Future skill invocations use codex app-server --stdio and the documented initialize → thread/start → turn/start protocol, with that folder as the saved session's starting directory. The server creates a persistent interactive session and the adapter gives it a <repo> #<PR> · review title. This matters: codex exec has a separate session source that default history lists exclude; changing its cwd alone does not establish desktop visibility. --thread-source is an analytics label and does not change that history source.

The reviewer receives the separate PR worktree path for all code inspection and tests; worktree ownership, locks, watchdogs and verdict checks still apply. Existing sessions are not moved. This is configured per host: a Mini review needs the folder registered as a project on the Mini's connection. Do not use --ephemeral or a separate CODEX_HOME, which would hide sessions from the usual desktop account.

For durable project assignment, initialize the same host's codex app-server --stdio and call its documented project/list method. Follow pagination and match the project's roots[].path to the exact configured directory. Save that returned ID in $CODEX_REVIEW_HOME/project-id (default ~/.codex-reviews/project-id) or set CODEX_REVIEW_PROJECT_ID. Desktop-tool list_projects IDs can use a different namespace: do not copy those IDs into this configuration. The adapter passes the app-server ID as thread/start.projectId and verifies the response. It never reads or edits Codex's database. Without an ID, grouping depends on the registered folder; verify visibility on the next actual review rather than creating a duplicate review as a probe.

Override the saved path with CODEX_REVIEW_PROJECT_DIR=/absolute/path, or set it to an empty string for one invocation to start in the PR worktree instead. Without a saved path or override, the existing exec behavior is unchanged. A configured missing directory is an error, so reviews cannot silently appear somewhere else. An explicit directory override ignores the saved project ID; also pass CODEX_REVIEW_PROJECT_ID if that different folder needs a durable assignment. Project reviews require Node.js and a Codex version supporting the app-server protocol. Incompatible protocol, failed/interrupted turns and missing final text fail the attempt; they never produce a successful review merely from progress.

Show full SKILL.md (513 more words)Show less

Protocol reference: Codex App Server, including its sourceKinds history filter. The adapter uses the server's normal session source; it does not relabel existing sessions or spoof a source.

VariableDefaultPurpose
CODEX_BINcodexCodex CLI binary. Point it at a specific install if the shim on PATH does not support exec.
CODEX_REVIEW_MODEL / CODEX_REVIEW_EFFORTgpt-6.1-sol / mediumModel and reasoning effort.
CODEX_REVIEW_HOME~/.codex-reviewsWhere prompts, final messages and runner logs are kept.
CODEX_REVIEW_PROJECT_DIRSaved project-directory file, otherwise PR worktreeStarting directory for future sessions; register that folder in Codex to group reviews.
CODEX_REVIEW_PROJECT_IDSaved project-id file, otherwise unsetOptional durable project assignment for the configured project on this host.
MENTRA_RELEASE_COORDINATOR_KEY~/.config/mentra-release-coordinator/private-key.pemApp private key (0600) for posting on your own PRs.
GH_ACCOUNTautoapp or own, see above.
STALL_SECONDS / MAX_SECONDS / ATTEMPTS / POLL_SECONDS480 / 1800 / 2 / 5Watchdog limits and poll interval.
LOCK_STALE_SECONDS60Age after which a lock directory without a pid file is reclaimed.

The App must be installed on the target repository or the mint fails with HTTP 422 and the run falls back to a comment review from the logged-in account.

With an already configured GitHub App installation credential, set GH_ACCOUNT=own to retain that credential. An explicit account skips the user-only /user lookup; it does not grant additional access or change the review receipt requirements. The usual self-review comment fallback still applies. Controllers can inspect scripts/codex-review/codex-pr-review.sh --capabilities before admitting this mode.

Tests

bun test scripts/codex-review runs the lifecycle suite with fake gh and codex binaries: markers on every exit path, worktree ownership, lock behaviour, receipt-before-retry, and stall handling. Project transport tests cover the real JSON protocol, completion ordering, final-text validation, cancellation and detached-child cleanup. They do not claim a live desktop sidebar check. CI runs them on changes under scripts/codex-review/.

Extra prompt file

Only when the review needs context Codex cannot get from the PR itself (a design decision made in chat, a known-flaky test to ignore). Do not use it to steer the verdict on a specific comment; let Codex weigh comments itself.

After the run

  • Relay the verdict and Codex's list to the user. Do not merge.
  • If the PR is the agent's own and the verdict is request-changes: read the bot comments too, fix real defects with a coherent design change, say which comments were ignored and why, push, and rerun the script on the new head.
  • If the PR belongs to someone else, report only; do not rework unless asked.
  • On codex-pr-review: FAILED, read runner.log, report the failure, and do not claim a review was posted.
  • Remove completed review worktrees first, before finished fixer worktrees, once the canonical outcome and needed reproduction material are preserved outside the checkout. Wait for the wrapper, runner and their children to exit; keep a checkout still needed by active or saved review follow-up.
  • Before removal, check process use, incoming dependency symlinks and Git common-directory consumers. Preserve source commits/refs, review receipts, logs, evidence and shared dependencies. Use git worktree remove, never --force; if the checkout is still needed or removal refuses, keep it and report why. Store shared dependencies outside disposable review worktrees.

© Mentra-Community, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/codex-pr-review of Mentra-Community/MentraOS.

Open the folder on GitHubat commit bc626e0

Compare with similar skills

Codex PR Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex PR Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex PR Review this skillMentra-Community/MentraOS2.4k—~3.1kAutomated safety check: PassApache-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Pull Request Title and Body Writeropeninterpreter/openinterpreter69k2 repos~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Pull Request Title and Body Writer

    openinterpreter/openinterpreter

    Rewrites the title and body of one or more pull requests with gh, leading with why the change was made, then what changed, and describing only the net result.

    69k GitHub starsUsed in 2 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Runs a loop on a GitHub pull request: fetch review state, triage comments into actions, implement them and resolve threads, repeating until nothing actionable is left.

    48k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed

More from Mentra-Community/MentraOS

All 11 skills in this repo
  • Investigate Routine Failure

    Mentra-Community/MentraOS

    Investigate a Mentra routine failure from an Admin testRun URL or run/request ID, fetch authenticated results and verified artifacts with the existing incident-report token, trace the exact routine…

    2.4k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Mentra Update Live Firmware

    Mentra-Community/MentraOS

    Update MentraOS firmwarelive.json from the published BES and MTK feeds and prepare a PR, preserving production MTK upgrade paths.

    2.4k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • CI Triage

    Mentra-Community/MentraOS

    Triage failing GitHub PR checks: list failures with gh, fetch capped Actions logs, skip non-Actions checks, and summarize root cause.

    2.4k GitHub stars~582 tokensUpdated today
    Auto-check passed
  • Manage Cloud Env

    Mentra-Community/MentraOS

    Add or change backend deployment environment variables through Doppler shared configs and native Porter syncs.

    2.4k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Fix Nightly Failures

    Mentra-Community/MentraOS

    Diagnose an ongoing or finished Mentra nightly suite, group demonstrated shared failures, implement fixes, and carry PRs through independent Codex review and merge.

    2.4k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Sync Miniapp

    Mentra-Community/MentraOS

    Prepare an external Mentra miniapp for bundling into mobile/assets/miniapps (version bump, pack, zip install, regenerate bundledMiniapps).

    2.4k GitHub stars~430 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Codex PR Review

What does Codex PR Review do?

Run an independent local Codex (gpt-6.1-sol, medium) review of a GitHub pull request and relay its verdict. Codex PR Review is an agent skill from Mentra-Community/MentraOS.1-sol, medium) review of a GitHub pull request and relay its verdict.

When should I use Codex PR Review?

Codex PR Review fits situations like: every PR an agent opens; whenever the user asks to review a PR with Codex.

How do I install Codex PR Review in Claude Code?

Run `npx skills add Mentra-Community/MentraOS --skill codex-pr-review -a claude-code`. Or copy the skill folder (.agents/skills/codex-pr-review in Mentra-Community/MentraOS) into .claude/skills/codex-pr-review in your project. Claude Code loads it when a task matches its description.

How do I install Codex PR Review in Codex?

Run `npx skills add Mentra-Community/MentraOS --skill codex-pr-review -a codex`. Or copy the skill folder (.agents/skills/codex-pr-review in Mentra-Community/MentraOS) into .agents/skills/codex-pr-review in your project. Codex loads it when a task matches its description.

Can I use Codex PR Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Mentra-Community/MentraOS --skill codex-pr-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-pr-review, .gemini/skills/codex-pr-review, .github/skills/codex-pr-review and .opencode/skills/codex-pr-review in your project.

What does Codex PR Review need to run?

Going by SKILL.md and its folder, Codex PR Review needs the command-line tools its instructions call (codex, git, gh and bun) and credentials named MENTRA_RELEASE_COORDINATOR_KEY. Our summary lists: Node.js; A credential in MENTRA_RELEASE_COORDINATOR_KEY.

Does Codex PR Review access the network?

SKILL.md names 1 domain. As links in the text: learn.chatgpt.com. This is read from the text; nothing was executed.

Is Codex PR Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codex PR Review use?

Codex PR Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex PR Review use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codex PR Review?

Skills that share tags, products or a category with Codex PR Review: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars) and Create Pull Request (cline/cline, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex PR Review?

Mentra-Community (a GitHub organization) maintains it in Mentra-Community/MentraOS, which has 2,381 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 10, 2026.

Source: Mentra-Community/MentraOS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.