# Codex Review

> Review staged changes with Codex by piping `git diff --cached` to `codex exec` and asking for P1-P4 labeled findings. Use when the user asks for a Codex-specific review on staged work ("codex review", "review with codex"). Do NOT auto-invoke for generic "review this" requests — those belong to the built-in `/review` skill.

- Skill: `lil-lon/codex-review` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add lil-lon/codex-review`
- Raw SKILL.md: https://api.skillmd.com/api/skills/lil-lon/codex-review/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: lil-lon (https://skillmd.com/u/lil-lon)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/lil-lon/codex-review

---


Run the review script that lives next to this SKILL.md, from the user's
current working directory (so `git diff --cached` operates on their
repo):

```
bash "$CLAUDE_CONFIG_DIR/skills/codex-review/review.sh"
```

The script aborts with exit 1 when no staged changes exist — surface
that message and stop.

Print the script's stdout verbatim. Do not paraphrase, trim, or add a
summary on top.

## Handling findings

- **P1 findings must always be fixed.** Never commit when codex reports
  a P1.
- **P2 findings** should be fixed, unless they have been previously
  discussed in this conversation and explicitly accepted as a policy
  trade-off. Treat an accepted P2 as resolved.
- **The iteration loop terminates** when codex no longer reports any
  P1, AND each remaining P2 has been either fixed or accepted as a
  known trade-off in this conversation.
- P3/P4 findings are non-blocking; surface them but proceed.

## Sandbox

The Claude Code sandbox blocks `codex exec` from accessing its session,
so run this script unsandboxed. It is safe because the script itself
passes `--sandbox read-only` to `codex exec`.

TODO: narrow the `sandbox.excludedCommands` glob in `settings.json` so
that this wrapper script is matched and the explicit unsandbox flag is
no longer needed.

