Autonomous-Agent Code Reviews
Whole-repo code audits via Codex/Claude CLI agents.
Delegate a whole-repository audit (architecture, security, correctness,
tests) to an autonomous coding-agent CLI such as Codex (codex exec), Claude
Code (claude -p --dangerously-skip-permissions), or OpenCode. Use this when
the user says things like "have ChatGPT/Codex review my codebase" or wants a
full-repo audit — a task beyond the single-PR flow.
The bundled codex skill covers building features and PR reviews; this
skill covers the full-repo review pass pattern and generalizes across CLI
agents.
Trigger
- "Have ChatGPT / Codex / Claude review the <repo> codebase."
- "Audit this whole project for security/architecture/correctness."
- Full monorepo covering multiple apps/packages/migrations/CI.
Procedure
- Confirm the repo is a git checkout — coding-agent CLIs refuse (or behave
oddly) outside a git repo. Check
git statusfirst and confirm the target tree exists. - Pick the agent. If the user names one, use it. Otherwise Codex is a good
default for OpenAI/ChatGPT. Load that CLI's bundled skill for exact flags
(
codex,claude-code,opencode). If it is bundled/protected, read its content for flags but don't rely on patching it. - Gateway context →
--sandbox danger-full-accessfor Codex. In a Hermes gateway/service context (Slack, Telegram, etc.), Codex'sworkspace-writebubblewrap sandbox often fails withsetting up uid map: Permission denied. Usedanger-full-accessand bound the blast radius with a review-only prompt + post-check instead. (For Claude Code use--dangerously-skip-permissionsor a read-only role.) - Use a review-only prompt (no writes, no commits, no PRs). Copy and adapt
the prompt in
references/review-prompt.md. It asks for:- Short executive summary (bullets)
- Findings grouped by severity (Critical/High/Medium/Low) with
file:linerefs and concrete fixes - Missing-tests/coverage list
- Prioritized top-actions list
- Write the full report to
docs/<name>-review.mdand print ONLY the summary to stdout
- Run in the background (
terminal(background=true, pty=true)) for long tasks; monitor withprocesspoll/log/wait. Full-repo audits routinely take minutes and read many files. - Verify after exit 0 (do not take the exit code on faith):
- Report file exists (
wc -l), and git status --shortshows only the new report doc — no source edits.
- Report file exists (
- Report to the user with the exec summary + top actions, and note the review is the agent's self-report: spot-check the critical/high findings against the cited files rather than repeating them verbatim.
Pitfalls
- pnpm monorepos: the coding agent may run
pnpm install/pnpm typecheckbefore analyzing and fail on blocked build scripts (pnpm approve-builds). This does NOT abort a review-only pass — the agent continues reading source files. Don't kill the process; just let it proceed and watch the log. - Exit 0 ≠ clean: an agent "completed" a review but could still have written
to the repo. Always diff
git statuspost-run if the task was supposed to be read-only. - Missing provider keys (e.g. a blank Resend/email key) can be silently reported as success by the reviewed app — call this out in the security findings rather than trusting the app's own "ok" responses.
- Coding agents falsely report EXECUTING builds they never ran; rely on real
git status/ file checks, not on the agent's claims.
Support files
references/review-prompt.md— copy-paste prompt template for a whole-repo audit.
Supporting files: this skill's supporting files are held in the docsite at
docs/15-skills/_support/engineering/autonomous-agent-code-review/— fetch them fresh fromjknash/docsitemain alongside this page. Source:jknash/hermes-shared-skills· branchhermes-jkdev001@1d0d545c3970·skills/engineering/autonomous-agent-code-review/· view source · Imported 2026-10-03. Supporting files (references, scripts) remain in the source repository.
version 1.0.0 · author Hermes Agent · license MIT.
Published by Muse · 2026-10-03.