Agent skill

Codex PR Review Loop

by victorGPT in victorGPT/vibeusage

A skill your agent uses when managing Codex review iterations for a PR and you must enforce preflight risk-layer checks and post-merge learning capture.

MITAuto-check passedDevelopment

Install Codex PR Review Loop

skills CLI
$ npx skills add victorGPT/vibeusage --skill codex-pr-review-loop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install victorGPT/vibeusage codex-pr-review-loop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/victorGPT/vibeusage.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/skills/codex-pr-review-loop .claude/skills/codex-pr-review-loop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex-pr-review-loop
GitHub stars
131
Token cost
~1.3k tokens
SKILL.md length
617 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when managing Codex review iterations for a PR and you must enforce preflight risk-layer checks and post-merge learning capture.

  • Works in 8 steps: Identify PR → Poll review threads, PR issue comments,… → Wait for updates (repeat until update) → …
  • Managing Codex review iterations for a PR and you must enforce preflight risk-layer checks and post-merge learning capture
  • SKILL.md covers Overview, Workflow (Preflight + Loop +…, Guardrails and Common Mistakes, plus 2 more sections
  • Calls gh, codex and git

What it does

Codex PR Review Loop is an agent skill from victorGPT/vibeusage. Use when managing Codex review iterations for a PR and you must enforce preflight risk-layer checks and post-merge learning capture.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests. The licence is MIT.

When your agent uses it

  • Managing Codex review iterations for a PR and you must enforce preflight risk-layer checks and post-merge learning capture
  • Tasks that involve Pull requests

Example prompts

  • “/codex-pr-review-loop”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Identify PR
  2. Poll review threads, PR issue comments, and PR body reactions
  3. Wait for updates (repeat until update)
  4. Decide
  5. Fix bugs or requested changes
  6. Reply and wait
  7. Merge and sync
  8. Post-merge learning capture (when Codex churn occurred)

What it can do on your machine

Read from SKILL.md and the folder at commit 4891a58. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • codex
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex PR Review Loop loads about 1.3k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 617 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from victorGPT/vibeusage at commit 4891a58, republished under its MIT licence (© victorGPT). 617 words, ~1,319 tokens.

Download SKILL.mdSave it as .claude/skills/codex-pr-review-loop/SKILL.md (or your agent's skills folder).
name
codex-pr-review-loop
description
Use when managing Codex review iterations for a PR and you must enforce preflight risk-layer checks and post-merge learning capture.

Codex PR Review Loop

Overview

Run a 5-minute polling loop for PR review threads, but enforce a preflight Codex Context gate and capture post-merge learning when Codex churn occurs.

Workflow (Preflight + Loop + Post-Merge)

Preconditions
  1. If the user asks for preflight, run Step -1 before PR submission.
  2. If PR already exists, proceed to Step 0.
  3. gh is authenticated.
  4. You are allowed to push/merge as part of this explicit user-requested workflow.
Step -1: Pre-PR Codex Readiness (only when requested)
  • Open .github/PULL_REQUEST_TEMPLATE.md.
  • If any Risk Layer Trigger applies, fill the Risk Layer Addendum (rules/invariants, boundary matrix >= 3, evidence).
  • Ensure Codex Context lists delta, invariants, edge cases, tests, and known gaps.
  • Run the minimal regression tests that cover the boundary matrix.
  • Stop and ask the user to create the PR if it does not exist yet.
Step 0: Identify PR
  • Prefer current branch PR: gh pr view --json number.
  • If ambiguous, ask for PR number.
Step 1: Poll review threads, PR issue comments, and PR body reactions

Run:

GH_OWNER=<owner>
GH_REPO=<repo>
PR_NUMBER=<number>

gh api graphql -f owner="$GH_OWNER" -f name="$GH_REPO" -F number=$PR_NUMBER -f query='query($owner:String!,$name:String!,$number:Int!){repository(owner:$owner,name:$name){pullRequest(number:$number){reactionGroups{content users{totalCount}} reviewThreads(first:100){nodes{isResolved path line originalLine comments(first:50){nodes{author{login} body createdAt reactions(content: THUMBS_UP){totalCount}}}}} comments(first:100){nodes{author{login} body createdAt reactions(content: THUMBS_UP){totalCount}}}}}}}'
Step 2: Wait for updates (repeat until update)
  • Do not proceed unless review threads, PR issue comments, or PR body reactions have new updates since the last poll (new comments, new threads, updated timestamps, or reaction count changes).
  • If no updates are found, wait 5 minutes and poll again. Continue doing this automatically until updates appear.
Step 3: Decide
  • If any review thread comment OR PR issue comment contains Codex Review: Didn't find any major issues (exact phrase) OR a thumbs-up signal:
    • thumbs-up signal = comment body includes 👍 or :+1: OR reactions(content: THUMBS_UP).totalCount > 0 OR PR body reactionGroups has content: THUMBS_UP with users.totalCount > 0
    • You may merge to remote main, then pull locally. Proceed to Step 6.
  • Else: treat updated review thread feedback as actionable. Proceed to Step 4.
Step 4: Fix bugs or requested changes
  • Apply fixes in code.
  • Add/adjust tests for regressions.
  • Run relevant verification commands.
  • Commit changes locally.
  • Push to update the PR.
Step 5: Reply and wait
  • Post a separate PR issue comment (not a thread reply) with exactly @codex review.
    • Use: gh pr comment <PR_NUMBER> --body "@codex review"
  • After replying, immediately return to Step 2 (wait 5 minutes, poll again until updates appear).
Show full SKILL.md (252 more words)Show less
Step 6: Merge and sync
  • Merge PR to main on remote (e.g., gh pr merge --merge or project-required strategy).
  • Pull latest main locally.
Step 7: Post-merge learning capture (when Codex churn occurred)
  • If the PR required multiple @codex review cycles or post-merge fixes:
    • Run a retrospective using pr-review-cycle-retro on this PR.
    • Update docs/retrospective/ entries if this repo uses them.
    • If a new cause category appears, update the churn skill taxonomy.

Guardrails

  • Do not merge until review thread content, PR issue comments, or PR body reactions explicitly include: Codex Review: Didn't find any major issues or a thumbs-up signal (see Step 3).
  • Do not take any action (fix/respond/merge) unless review threads have new updates since the last poll.
  • If no updates are found, you MUST keep waiting in 5-minute increments until updates appear.
  • Do not request @codex review if a Risk Layer Trigger applies but the Addendum is incomplete.
  • Always run tests appropriate to the change before pushing.
  • Follow repo rules (e.g., no git push unless this skill is explicitly requested).
  • If merging/pushing requires confirmation in the current environment, ask for explicit confirmation.

Common Mistakes

  • Triggering @codex review without filling Risk Layer Addendum when required.
  • Treating Codex churn as a tooling issue instead of a stage/contract issue.

Rationalization Table

ExcuseReality
"Preflight is optional"If Risk Layer Trigger applies, the addendum is mandatory.
"Codex asked again, so we can skip context"Missing context amplifies churn.

Red Flags - STOP

  • Risk Layer Trigger checked but Addendum is missing.
  • Multiple @codex reviews without any delta summary.

© victorGPT, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/skills/codex-pr-review-loop of victorGPT/vibeusage.

Open the folder on GitHubat commit 4891a58

Compare with similar skills

Codex PR Review Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex PR Review Loop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex PR Review Loop this skillvictorGPT/vibeusage131—~1.3kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Check PRonyx-dot-app/onyx32k2 repos~2.3kAutomated safety check: PassMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
PR Design DocOpenHands/OpenHands90k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Check PR

    onyx-dot-app/onyx

    Checks a GitHub, GitLab, or Perforce (p4) pull request (or merge request, or shelved changelist) for unresolved review comments, failing status checks, and incomplete PR descriptions.

    32k GitHub starsUsed in 2 repos~2.3k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • PR Design Doc

    OpenHands/OpenHands

    For a non-trivial pull request, write a self-contained HTML design doc under the temporary .pr/ directory and link a visibility-appropriate preview in the PR description, so maintainers grasp the…

    90k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from victorGPT/vibeusage

  • Frontend UI Functional

    victorGPT/vibeusage

    A skill your agent uses when building or refactoring functional React/Vite/Tailwind UI pages, templates, or component libraries that need consistent structure, tokenized styling, accessibility…

    131 GitHub stars~939 tokensUpdated 2 mo ago
    Auto-check passed
  • Backend Mvp Guardrails

    victorGPT/vibeusage

    A skill your agent uses when designing or reviewing a backend MVP with tight budget, evolving schema, and reliance on third-party backends where idempotency, replay, and responsibility attribution…

    131 GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed
  • PR Review Cycle Retro

    victorGPT/vibeusage

    A skill your agent uses when a team sees repeated @codex review cycles or Codex Cloud feedback churn and needs root-cause attribution by development stage.

    131 GitHub stars~1.4k tokensUpdated 2 mo ago
    Auto-check passed
  • Vibeusage Design

    victorGPT/vibeusage

    A skill your agent uses to generate well-branded interfaces and assets for VibeUsage, either for production or throwaway prototypes/mocks/etc.

    131 GitHub stars~566 tokensUpdated 2 mo ago
    Auto-check passed
  • Vibeusage Agent Readiness

    victorGPT/vibeusage

    Use VibeUsage to track AI coding agent token usage, inspect model and project usage, and find scoped API documentation.

    131 GitHub stars~252 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Codex PR Review Loop

What does Codex PR Review Loop do?

A skill your agent uses when managing Codex review iterations for a PR and you must enforce preflight risk-layer checks and post-merge learning capture. Codex PR Review Loop is an agent skill from victorGPT/vibeusage. Use when managing Codex review iterations for a PR and you must enforce preflight risk-layer checks and post-merge learning capture.

When should I use Codex PR Review Loop?

Codex PR Review Loop fits situations like: managing Codex review iterations for a PR and you must enforce preflight risk-layer checks and post-merge learning capture; tasks that involve Pull requests.

How do I install Codex PR Review Loop in Claude Code?

Run `npx skills add victorGPT/vibeusage --skill codex-pr-review-loop -a claude-code`. Or copy the skill folder (docs/skills/codex-pr-review-loop in victorGPT/vibeusage) into .claude/skills/codex-pr-review-loop in your project. Claude Code loads it when a task matches its description.

How do I install Codex PR Review Loop in Codex?

Run `npx skills add victorGPT/vibeusage --skill codex-pr-review-loop -a codex`. Or copy the skill folder (docs/skills/codex-pr-review-loop in victorGPT/vibeusage) into .agents/skills/codex-pr-review-loop in your project. Codex loads it when a task matches its description.

Can I use Codex PR Review Loop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add victorGPT/vibeusage --skill codex-pr-review-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-pr-review-loop, .gemini/skills/codex-pr-review-loop, .github/skills/codex-pr-review-loop and .opencode/skills/codex-pr-review-loop in your project.

What does Codex PR Review Loop need to run?

Going by SKILL.md and its folder, Codex PR Review Loop needs the command-line tools its instructions call (gh, codex and git).

Does Codex PR Review Loop access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codex PR Review Loop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codex PR Review Loop use?

Codex PR Review Loop is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex PR Review Loop use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codex PR Review Loop?

Skills that share tags, products or a category with Codex PR Review Loop: Finishing a Development Branch (obra/superpowers, 296k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars), Check PR (onyx-dot-app/onyx, 32k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex PR Review Loop?

victorGPT (a GitHub user) maintains it in victorGPT/vibeusage, which has 131 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on July 31, 2026.

Source: victorGPT/vibeusage on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.