# Codex Review, GitHub and PR workflows

> Codex: Local reviews, desktop diff feedback, hosted GitHub review, CI and Passion8 boundaries.

URL: https://docs.passion8.cc/en/docs/codex/review-github
Language: en
Publisher: Passion8

Choose the review's execution location before deciding whether Codex should also fix findings: local read-only review, desktop diff feedback or hosted GitHub/CI review.

## Review modes

| Mode | Entry | Use | Passion8 |
| --- | --- | --- | --- |
| Local CLI | /review | Find concrete risks before committing | Can use local provider configuration |
| Desktop Review pane | App Review | Inspect diffs, comment, stage or revert | Supported local threads can use Passion8 |
| GitHub review | @codex review or automatic review | Team review on a PR | Official hosted capability |
| CI review | codex exec or GitHub Action | Automated PR/release checks | Depends on runner credentials and configuration |




Hosted GitHub, Slack and Linear tasks do not automatically inherit your local provider. Configure local CLI, local app/IDE or your own CI explicitly for https://passion8.cc/v1.




## Local /review

```text
/review
```

Choose a scope:

| Scope | Meaning |
| --- | --- |
| Base branch | Compare with main, master or another base before a PR |
| Uncommitted changes | Inspect staged, unstaged and relevant untracked changes |
| Commit | Review a particular commit |
| Custom instructions | Focus on security, performance, accessibility or migrations |

An optional review model override:

```toml
review_model = "gpt-6-sol"
```

Use a model actually available on your route. For read-only review:

```bash
codex --sandbox read-only --ask-for-approval on-request
```

## Desktop Review pane

A practical diff/comment loop:

1. Open the PR branch or local changes.
2. Open Review.
3. Choose uncommitted changes, branch diff or the last turn's changes.
4. Leave comments on specific lines.
5. Ask Codex to address those comments only.
6. Inspect the updated diff before staging, committing or pushing.

If the app needs GitHub PR comments, install and authenticate GitHub CLI where required:

```bash
gh auth login
```

## GitHub PR review

With the official integration enabled:

```md
@codex review
```

The service reviews the PR diff and applicable repository instructions. Focus guidance on concrete correctness, security and regression risks rather than stylistic noise.

Example AGENTS.md guidance:

```md
## Review guidelines
- Treat authentication bypass as P0.
- Treat missing migration rollback instructions as P1.
- Do not flag copy edits unless they change product behavior.
```

Request a follow-up fix when supported:

```md
@codex fix the P1 issue
```

If nothing happens:

| Check | Action |
| --- | --- |
| Review enabled | Enable the repository in official review settings |
| Cloud setup | Check the required hosted environment/workspace setup |
| Trigger | Use the documented PR comment syntax |
| Access | Confirm the integration can read the repository and diff |
| Instructions | Keep review guidance specific and relevant |

## CI and GitHub Action

A lightweight local-runner review:

```bash
codex exec --sandbox read-only "Review this PR diff and return only P0/P1 risks."
```

The official Action can manage installation, proxy setup and output:

```yaml
name: Codex review
on:
  pull_request:
    types: [opened, synchronize, reopened]
jobs:
  codex:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      pull-requests: write
    steps:
      - uses: actions/checkout@v5
        with:
          fetch-depth: 0
          persist-credentials: false
      - uses: openai/codex-action@v1
        with:
          openai-api-key: ${{ secrets.OPENAI_API_KEY }}
          prompt: Review this pull request. Report only correctness, security, data loss, and missing-test risks.
          sandbox: read-only
```

This official-provider example is not a verified Passion8 Action configuration.

| Concern | Recommendation |
| --- | --- |
| Trigger source | Trusted users or events requiring approval |
| Prompt input | Treat PR text, commit messages and HTML comments as untrusted |
| Secrets | Use the CI secret store, never repository literals |
| Permissions | Start with contents: read; add PR write only when needed |
| Sandbox | Read-only for review; workspace-write only for authorized fixes |

## Before opening a PR

- Review completed with no unresolved critical findings.
- Relevant tests and lint ran; failures are explained.
- Review instructions are current.
- Large changes are divided into reviewable commits or PRs.
- A person inspected the proposed fix.
- Untrusted input cannot override the CI task's intended scope.

## Continue reading



- [CI and SDK](https://docs.passion8.cc/en/docs/codex/noninteractive-ci-sdk): exec, GitHub Action and automation credentials.
- [Subagents and worktrees](https://docs.passion8.cc/en/docs/codex/subagents-worktrees): Independent reviews of security, tests and maintainability.
- [AGENTS.md](https://docs.passion8.cc/en/docs/codex/memory): Persist repository review instructions.



## Official references

- [Codex manual: Review](https://developers.openai.com/codex/codex-manual.md)
- [Codex manual: GitHub review](https://developers.openai.com/codex/codex-manual.md)
- [Codex manual: GitHub Action](https://developers.openai.com/codex/codex-manual.md)
