What Prompts Are Used for Adversarial Reviews Versus Regular Reviews in Codex?
The OpenAI Codex plugin utilizes two distinct system prompt templates—adversarial-review.md for aggressive security scrutiny and stop-review-gate.md for balanced constructive feedback—to differentiate between stress-testing and standard code review workflows.
Managing code quality in AI-assisted development requires different review intensities depending on risk tolerance. In the openai/codex-plugin-cc repository, the Codex CLI supports both standard constructive feedback and aggressive adversarial testing through dedicated prompt templates stored as Markdown files. Understanding the distinction between these Codex adversarial review prompts and their regular counterparts is essential for implementing effective, context-appropriate code review automation.
Prompt File Locations and Architecture
The plugin stores both review modalities as separate Markdown files within the prompts directory, allowing the system to inject the appropriate system instructions at runtime.
Adversarial Review Prompt (adversarial-review.md)
Located at plugins/codex/prompts/adversarial-review.md, this file contains the system-level instruction that instructs the model to adopt an explicitly adversarial stance. According to the source implementation, this prompt directs Codex to deliberately probe for hidden bugs, security vulnerabilities, and edge-case failures that standard reviews might overlook. The command implementation in plugins/codex/commands/adversarial-review.md loads this specific template when the adversarial-review command is invoked.
Regular Review Prompt (stop-review-gate.md)
Located at plugins/codex/prompts/stop-review-gate.md, this file provides the default review instruction that encourages a balanced, constructive assessment. This prompt asks the model to highlight code improvements, identify possible bugs, and suggest clean-up opportunities without employing an aggressive or confrontational tone. The standard review command implementation in plugins/codex/commands/review.md references this template for normal review operations.
How Prompts Are Loaded and Executed
The actual prompt injection mechanism is handled by the utility module at plugins/codex/scripts/lib/prompts.mjs, which reads the selected Markdown file and formats it for the target model (Codex or Claude). When a review command executes, the following sequence occurs:
- The command handler (
revieworadversarial-review) identifies the target prompt file path. - The
prompts.mjsutility loads the Markdown content fromplugins/codex/prompts/. - The formatted system prompt is injected into the request payload sent to the underlying language model.
This architecture ensures that switching between review modes requires only changing the file path reference, with no hard-coded prompt strings within the command logic itself.
Functional Comparison: Adversarial vs Regular Review
The distinction between these two Codex review prompts centers on intent and tone:
-
Adversarial Review (
adversarial-review.md): Optimized for security audits and stress testing. The prompt instructs the model to assume a critical, skeptical posture specifically searching for zero-day vulnerabilities, logic bombs, and obscure failure modes. This mode is ideal for pre-release security gates or when reviewing code from untrusted sources. -
Regular Review (
stop-review-gate.md): Optimized for daily development workflows. The prompt encourages teaching and collaborative improvement, focusing on maintainability, style consistency, and obvious defect detection while maintaining a supportive tone suitable for team environments.
Practical Usage Examples
To invoke these different review modes programmatically, use the codexClient interface with the appropriate command specifier:
// Trigger a standard constructive review
await codexClient.runCommand('review', {
files: ['src/utils/helpers.js'],
repoState: currentContext,
// Additional options...
});
// Trigger an adversarial security-focused review
await codexClient.runCommand('adversarial-review', {
files: ['src/utils/helpers.js'],
repoState: currentContext,
// Same options; internal routing switches the prompt file
});
In both cases, the underlying system passes the same file list and repository context, but the command router selects either stop-review-gate.md or adversarial-review.md via the prompts utility module.
Summary
- Dual Prompt System: The
openai/codex-plugin-ccrepository maintains separate Markdown prompts atplugins/codex/prompts/adversarial-review.mdandplugins/codex/prompts/stop-review-gate.mdfor adversarial versus regular reviews. - Loading Mechanism: The
plugins/codex/scripts/lib/prompts.mjsmodule handles runtime prompt injection for both modalities. - Command Integration:
plugins/codex/commands/review.mduses the regular prompt, whileplugins/codex/commands/adversarial-review.mduses the adversarial variant. - Operational Difference: Adversarial mode targets security flaws and edge cases with critical intensity; regular mode focuses on constructive improvements and standard bug detection.
Frequently Asked Questions
What is the main difference between adversarial and regular review prompts in Codex?
The adversarial review prompt (adversarial-review.md) instructs the model to adopt a hostile, skeptical stance specifically hunting for security vulnerabilities and hidden edge-case failures, while the regular review prompt (stop-review-gate.md) encourages balanced, constructive feedback suitable for iterative team development.
Where are the review prompt files located in the codex-plugin-cc repository?
Both prompt files reside in the plugins/codex/prompts/ directory: adversarial-review.md for adversarial reviews and stop-review-gate.md for regular reviews, as implemented in the openai/codex-plugin-cc source tree.
How does Codex programmatically switch between adversarial and regular review modes?
The system switches modes by changing the command invocation from codexClient.runCommand('review', ...) to codexClient.runCommand('adversarial-review', ...), which internally routes to different command handlers in plugins/codex/commands/review.md and plugins/codex/commands/adversarial-review.md, each loading their respective prompt files via plugins/codex/scripts/lib/prompts.mjs.
Can developers customize the adversarial review prompt behavior?
Yes, because the prompts are stored as plain Markdown files (adversarial-review.md and stop-review-gate.md) in the plugins/codex/prompts/ directory, developers can modify the system instructions directly to adjust the aggressiveness level or specific security focus areas, and the prompts.mjs loader will ingest the updated content on the next command execution.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →