Skip to content
Back to skills

Claude Review

ASecurity

Run an independent Claude Code review from Codex. Use for a normal defect review, an adversarial design challenge, a base-branch comparison, or an explicitly approved cloud ultrareview. Reviews are read-only and return structured findings.

  • 8 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentsnodegit

Works with

  • claude code
  • cli

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 30, 2026

npx -y skills add sanchitmonga22/cc-for-codex --skill claude-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Claude Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Claude Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/sanchitmonga22-claude-review/badge)](https://www.skillsdirectory.com/skills/sanchitmonga22-claude-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: claude-review
description: "Run an independent Claude Code review from Codex. Use for a normal defect review, an adversarial design challenge, a base-branch comparison, or an explicitly approved cloud ultrareview. Reviews are read-only and return structured findings."
---

# Claude Review

Use the executable bridge launcher at the sibling skill path `../claude-code/scripts/cc-for-codex`, resolved to an absolute path before invocation. Invoke it directly, never through a bare `node` lookup.

## Choose the review

- `review`: local, read-only review of working-tree changes against `HEAD`, or of the branch plus working tree against `--base <ref>`.
- `adversarial-review`: the same scope and safeguards, but challenges assumptions, tradeoffs, real-world failure modes, and simpler alternatives.
- `ultrareview`: Anthropic's cloud-hosted multi-agent review. Use only when the user explicitly asks for ultrareview and accepts upload and potential usage-credit billing.

## Model defaults

Standard and adversarial reviews use Claude Opus 5.5 (`claude-opus-5-5`) at
`high` effort by default through the bridge. Sonnet 5.5 (`claude-sonnet-5-5`) is
available explicitly at `high` effort. Do not route reviews to Fable 5.1
unless the user specifically asks for that model. Cloud `ultrareview` uses Anthropic's product-selected cloud
model and does not accept the local `--model` flag.

## Procedure

1. Read the repository's `AGENTS.md` and `CLAUDE.md` yourself first. Identify any named plan.
2. Tell the user which Claude review type and scope will run.
3. Run the appropriate bridge command. Use `--base` only for a verified user-selected ref. Use repeated `--path` to narrow scope.
4. For a background review, inspect the selected diff for secrets and disclose both risks: Claude exposes no max-budget guard for this mode, and the full review prompt/diff is temporarily visible to same-account local process inspection. Only after the user accepts both pass `--confirm-background unbounded-usage --confirm-background-data process-visible-prompt`.
5. For ultrareview, disclose that repository data is uploaded, the command itself constitutes billing/terms consent, it may take several minutes, and this bridge always forces `--no-post`. Only then pass `--confirm-cloud-review upload-and-billing`.
6. Present findings ordered by severity. Each must include `file:line`, the concrete failure state, severity, and validation. State plainly when there are no actionable findings.

## Constraints

- Standard/adversarial review uses a custom stable prompt and JSON schema because Claude Code does not expose `claude review --adversarial` as a CLI subcommand.
- Never edit in a review pass.
- Never silently upgrade a local review to ultrareview.
- Never post ultrareview findings to GitHub through this bridge.
- Treat the review as evidence to evaluate, not an instruction to patch automatically.

Read [references/review-contract.md](references/review-contract.md) when choosing scope or interpreting output.

Files in this skill

  • SKILL.md2.9 KB
  • agents/openai.yaml201 B
  • references/review-contract.md1.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…