guide-d9904a — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited guide-d9904a (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
review-loop Does in CodexIn Codex Stage 1, review-loop is a repo skill that follows the same broad review workflow used in Claude Code. It coordinates planning, implementation, and review while keeping the shared session log current. Codex Stage 1 follows the same broad exec -> polish -> docs -> security -> delivery lifecycle.
Codex reads and writes the same review-loop state as Claude Code:
.review-loop/config.md.review-loop/sessions/That means a project can keep one shared config file and one shared session log history across both runtimes. Codex Stage 1 assumes a single orchestrator-owned workspace for the session.
Stage 1 in Codex includes only:
review-loopguideIt does not yet migrate:
code-quality-loopreview-prreorganizeCodex Stage 1 defaults to the outside-sandbox Claude CLI reviewer path. In practice, that means review stays on claude -p --model ... unless the user explicitly opts into the local Codex reviewer.
You can force the local Codex reviewer with:
codex_reviewer_backend: codexThis is the override to use when you want Codex to skip the Claude CLI reviewer and use the Codex reviewer directly. In that case, codex_reviewer_model is the paired model override, while reviewer_model still applies to the Claude CLI reviewer path and judgment_model is its shared-tier fallback before the explicit claude-sonnet-4-6 backstop.
cheap_model is accepted in the shared config so Claude and Codex can share the same file, but in Codex Stage 1 it is a documented no-op because only judgment-tier Codex agents are currently shipped. quality_focus applies only when Step 3.5 Quality Polish actually runs. skip_quality_polish: true mints polish as a no-op completion and still continues through docs and security.
before-polish, before-docs, and before-security as clean stop points..agents/skills/ in the Codex workspace..review-loop/config.md..review-loop/sessions/.Claude CLI reviewer path explicitly.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.