Native Review vs Adversarial Review in the Codex Plugin: Key Differences Explained
Native review provides a neutral, quality-focused code audit, while adversarial review adopts a skeptical, challenge-based stance to surface hidden failure modes and design risks through steerable prompt engineering.
The openai/codex-plugin-cc repository provides two distinct review commands that invoke the same underlying Codex engine but differ significantly in purpose, framing, and flexibility. Understanding the difference between native review and adversarial review in the Codex plugin allows you to select the appropriate level of scrutiny for your code changes.
Core Purpose and Review Philosophy
The fundamental distinction lies in the intent of the review.
Native Review (/codex:review) delivers a straightforward, read-only analysis focused on correctness, style issues, and general code quality. According to the command definition in plugins/codex/commands/review.md, it operates from a supportive, factual stance designed to catch bugs and improve maintainability without questioning underlying design assumptions.
Adversarial Review (/codex:adversarial-review) conducts a deliberate challenge of the implementation. As defined in plugins/codex/commands/adversarial-review.md, this mode attempts to "break confidence in the change" by actively seeking disproof. It examines design-level risks, hidden assumptions, and edge-case failures that might survive a standard review.
Prompt Architecture and Framing
Both commands ultimately invoke plugins/codex/scripts/codex-companion.mjs, but they load different prompt templates that dictate the model's reasoning style.
The native review uses a built-in neutral prompt that frames the task as a standard code audit. The adversarial review explicitly loads plugins/codex/prompts/adversarial-review.md, which contains structured sections including <operating_stance>, <attack_surface>, <review_method>, and <finding_bar>. These sections force the model to adopt a skeptical stance and produce material findings only, refusing to give credit for good intent unless the implementation can be rigorously defended.
Steerability and Focus Text
A critical functional difference is the ability to steer the review focus.
Native review is not steerable. It accepts standard flags like --wait, --background, and --base <ref>, but rejects any additional focus text. The command executes a predetermined review pattern regardless of specific concerns.
Adversarial review is fully steerable. After the standard flags, you can append free-form focus text to direct the challenge toward specific risk areas. This flexibility makes the adversarial mode particularly valuable for pressure-testing critical components before shipping.
Source Code Implementation
Despite their different behaviors, both commands share identical target-selection logic. They examine git status, branch diffs, and optional --base references to determine the review scope.
As implemented in plugins/codex/commands/review.md, the native command calls:
codex-companion.mjs review ...
As defined in plugins/codex/commands/adversarial-review.md, the adversarial command calls:
codex-companion.mjs adversarial-review ...
The only distinction is the sub-command word passed to the companion script, which selects the appropriate prompt template and enables the focus text parsing logic for adversarial mode.
Practical Usage Examples
Run a native review for standard quality checks:
# Background review of current changes
/codex:review --background
# Review branch diff against main
/codex:review --base main
# Foreground review that blocks until completion
/codex:review --wait
Execute an adversarial review with custom focus text to challenge specific assumptions:
# Challenge retry logic for network partition handling
/codex:adversarial-review "challenge whether the retry logic handles network partitions"
# Question caching strategy with base reference
/codex:adversarial-review --base main "question the caching strategy for consistency"
# Background adversarial scan for race conditions
/codex:adversarial-review --background "look for race conditions in the new worker pool"
When to Use Each Review Mode
Choose native review when you need a quick, high-quality audit of syntax, style, and obvious bugs. It provides fast feedback without the overhead of defensive justification.
Select adversarial review when shipping critical infrastructure, refactoring core systems, or when you need to pressure-test design assumptions before production. The steerable focus text allows domain experts to direct the model toward specific vulnerability classes or architectural concerns.
Summary
- Native review (
/codex:review) provides neutral, quality-focused audits using a built-in prompt and does not accept custom focus text. - Adversarial review (
/codex:adversarial-review) conducts skeptical, challenge-based reviews using the prompt template atplugins/codex/prompts/adversarial-review.md. - Both commands invoke
plugins/codex/scripts/codex-companion.mjswith identical target-selection logic but different sub-commands (reviewvsadversarial-review). - Only adversarial review supports steerability via optional focus text appended after flags.
- Native reviews target bugs and style; adversarial reviews target design flaws, hidden assumptions, and failure modes.
Frequently Asked Questions
Can I add custom focus text to a native review?
No. The native review command defined in plugins/codex/commands/review.md strictly parses only the flags --wait, --background, and --base <ref>. Attempting to append focus text will result in an error. Only the adversarial review command accepts additional free-form text to steer the review.
Do both review modes analyze the same set of files?
Yes. Both commands share identical target-selection logic implemented in the companion script. They examine git status, diff ranges, and the optional --base reference to determine the file scope. Switching between review modes changes the analytical lens, not the files being reviewed.
What prompt sections enforce the adversarial stance?
The adversarial review relies on plugins/codex/prompts/adversarial-review.md, which includes explicit XML-tagged sections: <operating_stance>, <attack_surface>, <review_method>, and <finding_bar>. These sections instruct the model to adopt a skeptical posture and require material findings that could break confidence in the change.
Is there a performance difference between native and adversarial reviews?
Both commands execute through the same codex-companion.mjs entry point and share identical execution paths for target selection and background/foreground handling. Any performance variation stems from the complexity of the prompt processing rather than architectural differences in the plugin implementation.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →