# What Prompts Are Used for Adversarial Reviews Versus Regular Reviews in Codex?

> Explore the distinct prompts used for adversarial vs regular reviews in OpenAI Codex. Understand how adversarial-review.md and stop-review-gate.md differentiate security scrutiny and constructive feedback.

- Repository: [OpenAI/codex-plugin-cc](https://github.com/openai/codex-plugin-cc)
- Tags: deep-dive
- Published: 2026-08-02

---

**The OpenAI Codex plugin utilizes two distinct system prompt templates—[`adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/adversarial-review.md) for aggressive security scrutiny and [`stop-review-gate.md`](https://github.com/openai/codex-plugin-cc/blob/main/stop-review-gate.md) for balanced constructive feedback—to differentiate between stress-testing and standard code review workflows.**

Managing code quality in AI-assisted development requires different review intensities depending on risk tolerance. In the `openai/codex-plugin-cc` repository, the Codex CLI supports both standard constructive feedback and aggressive adversarial testing through dedicated prompt templates stored as Markdown files. Understanding the distinction between these **Codex adversarial review prompts** and their regular counterparts is essential for implementing effective, context-appropriate code review automation.

## Prompt File Locations and Architecture

The plugin stores both review modalities as separate Markdown files within the prompts directory, allowing the system to inject the appropriate system instructions at runtime.

### Adversarial Review Prompt ([`adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/adversarial-review.md))

Located at [`plugins/codex/prompts/adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/prompts/adversarial-review.md), this file contains the **system-level instruction** that instructs the model to adopt an explicitly adversarial stance. According to the source implementation, this prompt directs Codex to deliberately probe for hidden bugs, security vulnerabilities, and edge-case failures that standard reviews might overlook. The command implementation in [`plugins/codex/commands/adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/adversarial-review.md) loads this specific template when the `adversarial-review` command is invoked.

### Regular Review Prompt ([`stop-review-gate.md`](https://github.com/openai/codex-plugin-cc/blob/main/stop-review-gate.md))

Located at [`plugins/codex/prompts/stop-review-gate.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/prompts/stop-review-gate.md), this file provides the default review instruction that encourages a balanced, constructive assessment. This prompt asks the model to highlight code improvements, identify possible bugs, and suggest clean-up opportunities without employing an aggressive or confrontational tone. The standard `review` command implementation in [`plugins/codex/commands/review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/review.md) references this template for normal review operations.

## How Prompts Are Loaded and Executed

The actual prompt injection mechanism is handled by the utility module at `plugins/codex/scripts/lib/prompts.mjs`, which reads the selected Markdown file and formats it for the target model (Codex or Claude). When a review command executes, the following sequence occurs:

1. The command handler (`review` or `adversarial-review`) identifies the target prompt file path.
2. The `prompts.mjs` utility loads the Markdown content from `plugins/codex/prompts/`.
3. The formatted system prompt is injected into the request payload sent to the underlying language model.

This architecture ensures that switching between review modes requires only changing the file path reference, with no hard-coded prompt strings within the command logic itself.

## Functional Comparison: Adversarial vs Regular Review

The distinction between these two **Codex review prompts** centers on intent and tone:

- **Adversarial Review** ([`adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/adversarial-review.md)): Optimized for security audits and stress testing. The prompt instructs the model to assume a critical, skeptical posture specifically searching for zero-day vulnerabilities, logic bombs, and obscure failure modes. This mode is ideal for pre-release security gates or when reviewing code from untrusted sources.

- **Regular Review** ([`stop-review-gate.md`](https://github.com/openai/codex-plugin-cc/blob/main/stop-review-gate.md)): Optimized for daily development workflows. The prompt encourages teaching and collaborative improvement, focusing on maintainability, style consistency, and obvious defect detection while maintaining a supportive tone suitable for team environments.

## Practical Usage Examples

To invoke these different review modes programmatically, use the `codexClient` interface with the appropriate command specifier:

```javascript
// Trigger a standard constructive review
await codexClient.runCommand('review', {
  files: ['src/utils/helpers.js'],
  repoState: currentContext,
  // Additional options...
});

// Trigger an adversarial security-focused review
await codexClient.runCommand('adversarial-review', {
  files: ['src/utils/helpers.js'],
  repoState: currentContext,
  // Same options; internal routing switches the prompt file
});

```

In both cases, the underlying system passes the same file list and repository context, but the command router selects either [`stop-review-gate.md`](https://github.com/openai/codex-plugin-cc/blob/main/stop-review-gate.md) or [`adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/adversarial-review.md) via the prompts utility module.

## Summary

- **Dual Prompt System**: The `openai/codex-plugin-cc` repository maintains separate Markdown prompts at [`plugins/codex/prompts/adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/prompts/adversarial-review.md) and [`plugins/codex/prompts/stop-review-gate.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/prompts/stop-review-gate.md) for adversarial versus regular reviews.
- **Loading Mechanism**: The `plugins/codex/scripts/lib/prompts.mjs` module handles runtime prompt injection for both modalities.
- **Command Integration**: [`plugins/codex/commands/review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/review.md) uses the regular prompt, while [`plugins/codex/commands/adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/adversarial-review.md) uses the adversarial variant.
- **Operational Difference**: Adversarial mode targets security flaws and edge cases with critical intensity; regular mode focuses on constructive improvements and standard bug detection.

## Frequently Asked Questions

### What is the main difference between adversarial and regular review prompts in Codex?

The **adversarial review prompt** ([`adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/adversarial-review.md)) instructs the model to adopt a hostile, skeptical stance specifically hunting for security vulnerabilities and hidden edge-case failures, while the **regular review prompt** ([`stop-review-gate.md`](https://github.com/openai/codex-plugin-cc/blob/main/stop-review-gate.md)) encourages balanced, constructive feedback suitable for iterative team development.

### Where are the review prompt files located in the codex-plugin-cc repository?

Both prompt files reside in the `plugins/codex/prompts/` directory: [`adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/adversarial-review.md) for adversarial reviews and [`stop-review-gate.md`](https://github.com/openai/codex-plugin-cc/blob/main/stop-review-gate.md) for regular reviews, as implemented in the `openai/codex-plugin-cc` source tree.

### How does Codex programmatically switch between adversarial and regular review modes?

The system switches modes by changing the command invocation from `codexClient.runCommand('review', ...)` to `codexClient.runCommand('adversarial-review', ...)`, which internally routes to different command handlers in [`plugins/codex/commands/review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/review.md) and [`plugins/codex/commands/adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/plugins/codex/commands/adversarial-review.md), each loading their respective prompt files via `plugins/codex/scripts/lib/prompts.mjs`.

### Can developers customize the adversarial review prompt behavior?

Yes, because the prompts are stored as plain Markdown files ([`adversarial-review.md`](https://github.com/openai/codex-plugin-cc/blob/main/adversarial-review.md) and [`stop-review-gate.md`](https://github.com/openai/codex-plugin-cc/blob/main/stop-review-gate.md)) in the `plugins/codex/prompts/` directory, developers can modify the system instructions directly to adjust the aggressiveness level or specific security focus areas, and the `prompts.mjs` loader will ingest the updated content on the next command execution.