Review, GitHub and PR workflows
Local reviews, desktop diff feedback, hosted GitHub review, CI and Passion8 boundaries.
Choose the review's execution location before deciding whether Codex should also fix findings: local read-only review, desktop diff feedback or hosted GitHub/CI review.
#Review modes
| Mode | Entry | Use | Passion8 |
|---|---|---|---|
| Local CLI | /review | Find concrete risks before committing | Can use local provider configuration |
| Desktop Review pane | App Review | Inspect diffs, comment, stage or revert | Supported local threads can use Passion8 |
| GitHub review | @codex review or automatic review | Team review on a PR | Official hosted capability |
| CI review | codex exec or GitHub Action | Automated PR/release checks | Depends on runner credentials and configuration |
Hosted GitHub, Slack and Linear tasks do not automatically inherit your local provider. Configure local CLI, local app/IDE or your own CI explicitly for https://passion8.cc/v1.
#Local /review
/reviewChoose a scope:
| Scope | Meaning |
|---|---|
| Base branch | Compare with main, master or another base before a PR |
| Uncommitted changes | Inspect staged, unstaged and relevant untracked changes |
| Commit | Review a particular commit |
| Custom instructions | Focus on security, performance, accessibility or migrations |
An optional review model override:
review_model = "gpt-6-sol"Use a model actually available on your route. For read-only review:
codex --sandbox read-only --ask-for-approval on-request#Desktop Review pane
A practical diff/comment loop:
- Open the PR branch or local changes.
- Open Review.
- Choose uncommitted changes, branch diff or the last turn's changes.
- Leave comments on specific lines.
- Ask Codex to address those comments only.
- Inspect the updated diff before staging, committing or pushing.
If the app needs GitHub PR comments, install and authenticate GitHub CLI where required:
gh auth login#GitHub PR review
With the official integration enabled:
@codex reviewThe service reviews the PR diff and applicable repository instructions. Focus guidance on concrete correctness, security and regression risks rather than stylistic noise.
Example AGENTS.md guidance:
## Review guidelines
- Treat authentication bypass as P0.
- Treat missing migration rollback instructions as P1.
- Do not flag copy edits unless they change product behavior.Request a follow-up fix when supported:
@codex fix the P1 issueIf nothing happens:
| Check | Action |
|---|---|
| Review enabled | Enable the repository in official review settings |
| Cloud setup | Check the required hosted environment/workspace setup |
| Trigger | Use the documented PR comment syntax |
| Access | Confirm the integration can read the repository and diff |
| Instructions | Keep review guidance specific and relevant |
#CI and GitHub Action
A lightweight local-runner review:
codex exec --sandbox read-only "Review this PR diff and return only P0/P1 risks."The official Action can manage installation, proxy setup and output:
name: Codex review
on:
pull_request:
types: [opened, synchronize, reopened]
jobs:
codex:
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0
persist-credentials: false
- uses: openai/codex-action@v1
with:
openai-api-key: ${{ secrets.OPENAI_API_KEY }}
prompt: Review this pull request. Report only correctness, security, data loss, and missing-test risks.
sandbox: read-onlyThis official-provider example is not a verified Passion8 Action configuration.
| Concern | Recommendation |
|---|---|
| Trigger source | Trusted users or events requiring approval |
| Prompt input | Treat PR text, commit messages and HTML comments as untrusted |
| Secrets | Use the CI secret store, never repository literals |
| Permissions | Start with contents: read; add PR write only when needed |
| Sandbox | Read-only for review; workspace-write only for authorized fixes |
#Before opening a PR
- Review completed with no unresolved critical findings.
- Relevant tests and lint ran; failures are explained.
- Review instructions are current.
- Large changes are divided into reviewable commits or PRs.
- A person inspected the proposed fix.
- Untrusted input cannot override the CI task's intended scope.
#Continue reading
#Official references
Support
Need help?
For setup, billing, or model issues, email us. Check the status page for uptime.
WeChat / QQ support is available at the bottom right.

