# Native Review vs Adversarial Review in the Codex Plugin: Key Differences Explained

> Understand the key differences between native review and adversarial review in the Codex plugin. Learn how each method audits code for quality and identifies risks.

- Repository: [OpenAI/codex-plugin-cc](https://github.com/openai/codex-plugin-cc)
- Tags: deep-dive
- Published: 2026-07-29

---

**Native review provides a neutral, quality-focused code audit, while adversarial review adopts a skeptical, challenge-based stance to surface hidden failure modes and design risks through steerable prompt engineering.**

The `openai/codex-plugin-cc` repository provides two distinct review commands that invoke the same underlying Codex engine but differ significantly in purpose, framing, and flexibility. Understanding the difference between native review and adversarial review in the Codex plugin allows you to select the appropriate level of scrutiny for your code changes.

## Core Purpose and Review Philosophy

The fundamental distinction lies in the **intent** of the review.

**Native Review** (`/codex:review`) delivers a straightforward, read-only analysis focused on correctness, style issues, and general code quality. According to the command definition in [`plugins/codex/commands/review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/review.md), it operates from a supportive, factual stance designed to catch bugs and improve maintainability without questioning underlying design assumptions.

**Adversarial Review** (`/codex:adversarial-review`) conducts a deliberate challenge of the implementation. As defined in [`plugins/codex/commands/adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/adversarial-review.md), this mode attempts to "break confidence in the change" by actively seeking disproof. It examines design-level risks, hidden assumptions, and edge-case failures that might survive a standard review.

## Prompt Architecture and Framing

Both commands ultimately invoke `plugins/codex/scripts/codex-companion.mjs`, but they load different prompt templates that dictate the model's reasoning style.

The **native review** uses a built-in neutral prompt that frames the task as a standard code audit. The **adversarial review** explicitly loads [`plugins/codex/prompts/adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/prompts/adversarial-review.md), which contains structured sections including `<operating_stance>`, `<attack_surface>`, `<review_method>`, and `<finding_bar>`. These sections force the model to adopt a skeptical stance and produce material findings only, refusing to give credit for good intent unless the implementation can be rigorously defended.

## Steerability and Focus Text

A critical functional difference is the ability to steer the review focus.

**Native review** is **not steerable**. It accepts standard flags like `--wait`, `--background`, and `--base <ref>`, but rejects any additional focus text. The command executes a predetermined review pattern regardless of specific concerns.

**Adversarial review** is fully **steerable**. After the standard flags, you can append free-form **focus text** to direct the challenge toward specific risk areas. This flexibility makes the adversarial mode particularly valuable for pressure-testing critical components before shipping.

## Source Code Implementation

Despite their different behaviors, both commands share identical target-selection logic. They examine git status, branch diffs, and optional `--base` references to determine the review scope.

As implemented in [`plugins/codex/commands/review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/review.md), the native command calls:

```bash
codex-companion.mjs review ...

```

As defined in [`plugins/codex/commands/adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/adversarial-review.md), the adversarial command calls:

```bash
codex-companion.mjs adversarial-review ...

```

The only distinction is the sub-command word passed to the companion script, which selects the appropriate prompt template and enables the focus text parsing logic for adversarial mode.

## Practical Usage Examples

Run a **native review** for standard quality checks:

```bash

# Background review of current changes

/codex:review --background

# Review branch diff against main

/codex:review --base main

# Foreground review that blocks until completion

/codex:review --wait

```

Execute an **adversarial review** with custom focus text to challenge specific assumptions:

```bash

# Challenge retry logic for network partition handling

/codex:adversarial-review "challenge whether the retry logic handles network partitions"

# Question caching strategy with base reference

/codex:adversarial-review --base main "question the caching strategy for consistency"

# Background adversarial scan for race conditions

/codex:adversarial-review --background "look for race conditions in the new worker pool"

```

## When to Use Each Review Mode

Choose **native review** when you need a quick, high-quality audit of syntax, style, and obvious bugs. It provides fast feedback without the overhead of defensive justification.

Select **adversarial review** when shipping critical infrastructure, refactoring core systems, or when you need to pressure-test design assumptions before production. The steerable focus text allows domain experts to direct the model toward specific vulnerability classes or architectural concerns.

## Summary

- **Native review** (`/codex:review`) provides neutral, quality-focused audits using a built-in prompt and does not accept custom focus text.
- **Adversarial review** (`/codex:adversarial-review`) conducts skeptical, challenge-based reviews using the prompt template at [`plugins/codex/prompts/adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/prompts/adversarial-review.md).
- Both commands invoke `plugins/codex/scripts/codex-companion.mjs` with identical target-selection logic but different sub-commands (`review` vs `adversarial-review`).
- Only adversarial review supports **steerability** via optional focus text appended after flags.
- Native reviews target bugs and style; adversarial reviews target design flaws, hidden assumptions, and failure modes.

## Frequently Asked Questions

### Can I add custom focus text to a native review?

No. The native review command defined in [`plugins/codex/commands/review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/review.md) strictly parses only the flags `--wait`, `--background`, and `--base <ref>`. Attempting to append focus text will result in an error. Only the adversarial review command accepts additional free-form text to steer the review.

### Do both review modes analyze the same set of files?

Yes. Both commands share identical target-selection logic implemented in the companion script. They examine git status, diff ranges, and the optional `--base` reference to determine the file scope. Switching between review modes changes the analytical lens, not the files being reviewed.

### What prompt sections enforce the adversarial stance?

The adversarial review relies on [`plugins/codex/prompts/adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/prompts/adversarial-review.md), which includes explicit XML-tagged sections: `<operating_stance>`, `<attack_surface>`, `<review_method>`, and `<finding_bar>`. These sections instruct the model to adopt a skeptical posture and require material findings that could break confidence in the change.

### Is there a performance difference between native and adversarial reviews?

Both commands execute through the same `codex-companion.mjs` entry point and share identical execution paths for target selection and background/foreground handling. Any performance variation stems from the complexity of the prompt processing rather than architectural differences in the plugin implementation.