Local Codex Review (pre-push)
Runs the exact same review Codex performs in CI (.github/workflows/codex-pr-review.yml),
but locally and scoped to work you have not pushed yet — so you catch what CI would flag
before the PR exists. Use this before git push on a non-trivial change.
Correspondence with CI — identical:
- Policy:
REVIEW.md(severity triage, public-surface checklist, AGENTS.md compliance, test coverage). - Reasoning effort:
model_reasoning_effort="xhigh". - Output: markdown starting with
## Codex Review, findings tagged P0 / P1 / P2 with file:line.
Differences from CI — local-only:
- Model is
gpt-6-astra; CI stays ongpt-5.6-sol. Not an oversight to reconcile:gpt-6-astrais confirmed on the ChatGPT authcodex loginuses locally, while CI authenticates withOPENAI_API_KEY(codex-pr-review.ymlprefers it overCODEX_AUTH_JSON) and that tier is unverified for the model. Move CI once API access is confirmed, or once CI switches toCODEX_AUTH_JSON. - Scope is the current branch vs
mainat the merge-base, including uncommitted changes (CI reviews a pushed PR diff). - Sandbox is
read-only(CI usesdanger-full-accesson an ephemeral runner). Codex reads the diff and files but cannot modify your working tree. - Fresh context is inherent:
codex execis a separate cold process, so it does not anchor on the current chat session — the same reasonlocal-reviewinsists on a subagent.
Prerequisites
codexCLI >= 0.153.4 installed and authed viacodex login(anOPENAI_API_KEYin the environment takes priority and may not reachgpt-6-astra— see the model note above). Older CLIs reject the model with "requires a newer version of Codex";run.shchecks the version up front. Upgrade withnpm install --global @openai/codex@0.153.4(may needsudofor a global install). This matches the pin in.github/workflows/codex-pr-review.yml— the CLI version is the same on both sides, only the model differs.git fetchthe base ref if it's stale, so the merge-base is accurate.
Run
bash .agents/skills/local-review-codex/run.sh # review vs main (default)
bash .agents/skills/local-review-codex/run.sh <base> # review vs a different base ref
Invoke with bash (or run the executable directly) — the script needs Bash for
set -o pipefail; sh is Dash on Debian/Ubuntu and would fail. If main isn't a
local branch (e.g. a fresh single-branch checkout), the runner falls back to
origin/main automatically.
The script computes BASE_SHA = git merge-base HEAD <base>, feeds Codex REVIEW.md plus a
diff context pointing at git diff <BASE_SHA> (which folds in uncommitted edits), and prints
the review. It writes only temp files — nothing lands in the working tree.
Relaying the result
Print the Codex output verbatim. Do not re-summarize or filter it — the value of a cold Codex pass is surfacing what the current session would rationalize away. Then decide with the user whether to address findings before pushing.
For a Claude-native review instead, use local-review (branch-diff-reviewer subagent). This
skill is the Codex counterpart; run both for independent perspectives.