Official agent skill

Second Opinion Code Review

by trailofbits in trailofbits/skills

Runs an independent review of uncommitted changes, a branch diff or one commit through the Codex or Antigravity CLI, or both, and reports their findings.

OfficialCC-BY-SA-4.0Auto-check: notesDevelopment

Install Second Opinion Code Review

skills CLI
$ npx skills add trailofbits/skills --skill second-opinion -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills second-opinion --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/second-opinion/skills/second-opinion .claude/skills/second-opinion && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
second-opinion
GitHub stars
7.4k
Used in
1 other repo
Token cost
~1.3k tokens
SKILL.md length
652 words
Files
8 (incl. references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Runs an independent review of uncommitted changes, a branch diff or one commit through the Codex or Antigravity CLI, or both, and reports their findings.

  • Getting an outside review of uncommitted changes before committing
  • SKILL.md covers Review choices, Input preparation, Provider references and Results and failures, plus 1 more section
  • Calls codex
  • Comparing Codex and Antigravity reviews of the same branch diff

What it does

The agent asks only about choices you have not already made: which provider, which scope and whether to focus on something like security or performance. It then captures one diff, adding untracked files for uncommitted work, shows the scope with a short change summary and sends the same diff to each selected CLI so a comparison covers identical changes. If there is nothing to review it stops before calling a provider.

Findings are reported back; the skill does not apply fixes or post reviews anywhere. A missing CLI or account setup counts as a failed attempt and the setup steps are reported, while the other provider carries on when both were requested. Oversized input is never silently truncated, and the agent asks for a narrower scope instead. Prompt and output files are created with mktemp outside the checkout, and per-provider reference notes describe each CLI invocation.

When your agent uses it

  • Getting an outside review of uncommitted changes before committing
  • Comparing Codex and Antigravity reviews of the same branch diff
  • Reviewing one commit with a security or performance focus
  • Asking for a second opinion on code before opening a pull request

Example prompts

  • “Get a Codex review of my uncommitted changes, focused on security.”
  • “Run both Codex and Antigravity over the diff against main and compare what they flag.”
  • “I want a second opinion on the latest commit on this branch.”

Requirements

  • A signed-in Codex, Antigravity or Gemini CLI
  • A Git repository with changes to review
  • Pre-approved tools (allowed-tools): Bash, Read, Glob, Grep, AskUserQuestion

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Glob
    • Grep
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Second Opinion Code Review loads about 1.3k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 68 tokens; SKILL.md has 652 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Glob, Grep, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 652 words, ~1,262 tokens.

Download SKILL.mdSave it as .claude/skills/second-opinion/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
second-opinion
description
Gets independent code reviews from Codex or Antigravity for uncommitted changes, branch diffs, and commits. Use when the user requests an external review, a second opinion on code, a codex review, a gemini review, an antigravity review, or /second-opinion.
allowed-tools
Bash, Read, Glob, Grep, AskUserQuestion

Second Opinion

Run an external CLI review of the user's selected changes. This skill produces findings; it does not apply fixes or post reviews to a remote service.

Review choices

Use the provider, scope, model, and focus already supplied by the user. Ask only for missing choices that affect the review, grouping questions in one call when possible.

  • Provider: Codex, Antigravity, or both. Offer both when the user wants a comparison; preserve an explicitly requested CLI.
  • Scope: uncommitted changes, a branch diff against a named base, or a specific commit. Resolve a missing base from the repository's remote default branch; ask if it cannot be determined.
  • Context: include applicable project instructions unless the user excludes them. Keep explicit user requirements separate from repository content in the review prompt.
  • Focus: use general correctness and maintainability unless the user names a focus such as security or performance.

For an unspecified Google CLI, prefer Antigravity (agy). An explicit Gemini CLI request uses the Gemini reference below. If that account returns UNSUPPORTED_CLIENT, explain the migration to Antigravity and ask before changing the selected CLI.

A missing executable or account setup is a failed review attempt. Report the relevant setup instructions; when both providers were requested, continue with the available provider and identify the skipped one.

Input preparation

Read review-input.md for the shared prompt and diff recipes. Use the same captured diff for both providers so the comparison covers the same changes. Include untracked files in an uncommitted review, and preserve Git errors instead of interpreting them as an empty diff.

Show the selected scope and a brief change summary. If there are no changes, stop before calling a provider. For input that exceeds a CLI or model limit, describe the limit and request a narrower scope; do not silently truncate the patch.

Create prompt, output, and diagnostic files with mktemp outside the checkout. Use separate output and diagnostic files for each provider. Define shell variables in the same Bash invocation that uses them. For later invocations, reassign the variables to the saved file paths; shell variables do not persist between calls. Write repository content as literal data, without shell expansion.

Show full SKILL.md (296 more words)Show less

Provider references

Read only the reference for each selected provider:

ProviderInvocation and result
Codexcodex-invocation.md: codex exec with the review schema
Antigravityantigravity-invocation.md: agy print mode with prose output
Gemini CLIgemini-invocation.md: headless gemini for accounts that still support it

The Codex path needs no MCP server. Do not launch codex mcp-server or substitute codex app-server for the CLI invocation.

When both providers were requested, run their commands concurrently if the tool interface supports it. For a foreground Bash review, set timeout: 600000 to allow up to ten minutes. Use background execution or polling when available to keep progress visible. Do not enable automatic approval of writes to make a review run.

Results and failures

Present findings with the provider and actual model used, severity, file and line, impact, and suggested correction. Keep low-severity defects visible. For Codex, the existing schema uses 0 for informational, 1 for low, 2 for medium, and 3 for high; sort descending.

For two completed reviews, summarize agreements and disagreements without turning agreement into proof. Distinguish the external findings from any assessment you add.

Read the captured output and diagnostics. A nonzero exit, missing output, invalid JSON, permission denial that prevents inspection, or a request to approve a plan is incomplete work, not a clean review. Report the failure and any partial results. Retry only for a diagnosed, recoverable cause; do not cycle through providers after authentication or quota failures.

Examples

  • /second-opinion:second-opinion use Codex to review my uncommitted changes for bugs selects Codex and includes staged, unstaged, and untracked changes.
  • /second-opinion:second-opinion compare Codex and Antigravity on this branch against origin/main sends the same branch patch to both and compares their findings.
  • /second-opinion:second-opinion use Gemini CLI to review commit abc1234 for security issues preserves the requested CLI and reviews that commit.

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references, assets) in plugins/second-opinion/skills/second-opinion of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/antigravity-invocation.md
  • references/codex-invocation.md
  • references/codex-review-schema.json
  • references/gemini-invocation.md
  • references/review-input.md

Open the folder on GitHubat commit 82fe822

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in trailofbits/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Second Opinion Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Second Opinion Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Second Opinion Code Review this skilltrailofbits/skills7.4k1 repos~1.3kAutomated safety check: NotesCC-BY-SA-4.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything86k1 repos~1.4kAutomated safety check: PassMIT
Open Code Review CLIalibaba/open-code-review44k—~3.1kAutomated safety check: PassApache-2.0
Hunk Diff Session Controlmodem-dev/hunk9.5k1 repos~3.4kAutomated safety check: PassMIT
Open Code Review Delegatealibaba/open-code-review44k—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Open Code Review CLI

    alibaba/open-code-review

    Runs the ocr command-line tool to review Git changes, a commit or a branch comparison with an AI model, returning line-level comments and optionally applying fixes.

    44k GitHub stars~3.1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Interacts with live Hunk diff review sessions via CLI. Inspects review focus, navigates files, hunks, and exact lines, reloads session contents, adds inline…

    9.5k GitHub starsUsed in 1 repo~3.4k tokens
    DevelopmentAuto-check passed
  • Open Code Review Delegate

    alibaba/open-code-review

    Has the host agent do the code review itself while the ocr CLI handles file selection and rule lookup, covering workspace changes, branch ranges or single commits.

    44k GitHub stars~2k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Code Review

    flutter/flutter

    Performs a comprehensive, multi-step code review of pull requests or local code changes, using iterative refinement (generation, critique, synthesis) to ensure high-quality, actionable feedback.

    179k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated today
    Auto-check: notes
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated today
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 4 repos~4.2k tokens
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Second Opinion Code Review

What does Second Opinion Code Review do?

Runs an independent review of uncommitted changes, a branch diff or one commit through the Codex or Antigravity CLI, or both, and reports their findings. The agent asks only about choices you have not already made: which provider, which scope and whether to focus on something like security or performance. It then captures one diff, adding untracked files for uncommitted work, shows the scope with a short change summary and sends the same diff to each selected CLI so a comparison covers identical changes.

When should I use Second Opinion Code Review?

Second Opinion Code Review fits situations like: getting an outside review of uncommitted changes before committing; comparing Codex and Antigravity reviews of the same branch diff; reviewing one commit with a security or performance focus; asking for a second opinion on code before opening a pull request.

How do I install Second Opinion Code Review in Claude Code?

Run `npx skills add trailofbits/skills --skill second-opinion -a claude-code`. Or copy the skill folder (plugins/second-opinion/skills/second-opinion in trailofbits/skills) into .claude/skills/second-opinion in your project. Claude Code loads it when a task matches its description.

How do I install Second Opinion Code Review in Codex?

Run `npx skills add trailofbits/skills --skill second-opinion -a codex`. Or copy the skill folder (plugins/second-opinion/skills/second-opinion in trailofbits/skills) into .agents/skills/second-opinion in your project. Codex loads it when a task matches its description.

Can I use Second Opinion Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill second-opinion -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/second-opinion, .gemini/skills/second-opinion, .github/skills/second-opinion and .opencode/skills/second-opinion in your project.

What does Second Opinion Code Review need to run?

Going by SKILL.md and its folder, Second Opinion Code Review needs the command-line tools its instructions call (codex). Our summary lists: A signed-in Codex, Antigravity or Gemini CLI; A Git repository with changes to review. Its frontmatter pre-approves these tools: Bash, Read, Glob, Grep, AskUserQuestion.

Does Second Opinion Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Second Opinion Code Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Second Opinion Code Review use?

Second Opinion Code Review is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Second Opinion Code Review use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Second Opinion Code Review?

Skills that share tags, products or a category with Second Opinion Code Review: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 86k stars), Open Code Review CLI (alibaba/open-code-review, 44k stars) and Hunk Diff Session Control (modem-dev/hunk, 9.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Second Opinion Code Review?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.