codex-review — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited codex-review (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Run an independent code review via the OpenAI Codex CLI (codex review). The value is a second opinion from a different model family than the one that wrote the code — Codex catches things Claude misses due to author bias.
Complements brains-trust (generic multi-model opinions). This skill is specialised: git-aware, uses a tuned review prompt, saves structured output.
Do NOT use for:
brains-trust instead which codexIf missing: tell the user to install it (brew install codex on macOS, or see https://github.com/openai/codex) and stop. Do not continue.
codex review call will fail clearly if not logged in. If that happens, instruct the user to run codex login and stop.Pick the scope flag based on what the user asked for:
| User intent | Flag |
|---|---|
| "codex review" / "review the app" / "full review" / default | no flag (reviews whole app at current HEAD) |
| "review my changes" / "review what I just did" / "review uncommitted" | --uncommitted |
| "review this branch vs main" / "review the PR" | --base main (or the branch they name) |
| "review commit abc123" | --commit abc123 |
Default is whole-app review. A bare "codex review" with no qualifier means review the entire codebase at HEAD — not just uncommitted changes. Only use --uncommitted if the user specifically refers to their recent/uncommitted work.
If ambiguous, ask once. Don't guess on commits or branches.
The canonical review prompt lives in prompt.md next to this skill. Pipe it via stdin to avoid shell escaping:
mkdir -p .jez/reviews
TS=$(date +%Y-%m-%d-%H%M)
OUT=".jez/reviews/codex-${TS}.md"
SKILL_DIR="$(dirname "$0")" # or use the skill's absolute path
# Example: uncommitted changes
cat "${SKILL_DIR}/prompt.md" | codex review --uncommitted - 2>&1 | tee "$OUT"Other scopes:
# Vs base branch
cat prompt.md | codex review --base main - 2>&1 | tee "$OUT"
# Specific commit
cat prompt.md | codex review --commit abc123 - 2>&1 | tee "$OUT"
# Current HEAD (no scope flag)
cat prompt.md | codex review - 2>&1 | tee "$OUT"codex review can take several minutes on a large diff. Let it run.
After Codex finishes:
Report saved to .jez/reviews/codex-<timestamp>.mdauth.ts:42?"prompt.md file is deliberately neutral — Codex reviews the code, not Claude's narrative about the code. Independence is the whole point..claude/ (protected directory).The skill is working if:
codex binary.jez/reviews/ with a sensible timestamp~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.