Agent Plugins Marketplace
← All plugins

auto-review

v0.3.1

Auto-review hook for Codex PermissionRequest events. A static deny-bucket blocks universally destructive commands instantly; everything else is decided by a bounded-turn LLM agent loop using the official Z.ai Python SDK (`from zai import ZaiClient`) and native function tools (a single `review` tool with an `action` enum: allow / deny / probe).

Codex

By dzungtrLicense: UNLICENSED1 GitHub starsUpdated 1 hour ago

Directory evidence

Runtimes
Codex
Parsed components
0 skill or MCP entries
Source updated
Sep 28, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install auto-review for Codex

Installs for the current user
codex plugin marketplace add dzungtr/harness6
codex plugin marketplace upgrade harness6
codex plugin add auto-review@harness6

Paste and run these commands in a terminal with Codex. They add and refresh the harness6 catalog, then install this plugin.

Compatibility: the page URL and API slug “auto-review-2” remain stable.

  • Codex: auto-review-2@agent-plugin-marketplace → auto-review@harness6

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/dzungtr/harness6

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/auto-review/.

Plugin files

plugins/auto-review/
└── .codex-plugin/plugin.json

Plugin manifests1

plugins/auto-review/.codex-plugin/plugin.json
{
  "name": "auto-review",
  "version": "0.3.1",
  "description": "Auto-review hook for Codex PermissionRequest events. A static deny-bucket blocks universally destructive commands instantly; everything else is decided by a bounded-turn LLM agent loop using the official Z.ai Python SDK (`from zai import ZaiClient`) and native function tools (a single `review` tool with an `action` enum: allow / deny / probe).",
  "author": {
    "name": "dzungtr",
    "url": "https://github.com/dzungtr"
  },
  "homepage": "https://github.com/dzungtr/harness6",
  "repository": "https://github.com/dzungtr/harness6",
  "license": "UNLICENSED",
  "keywords": [
    "codex",
    "permission",
    "auto-review",
    "hook",
    "safety"
  ],
  "interface": {
    "displayName": "Auto Review",
    "shortDescription": "Z.ai-SDK-driven LLM auto-review hook for Codex PermissionRequest (allow / deny / probe via action enum)",
    "longDescription": "Auto Review intercepts Codex PermissionRequest events on Bash and apply_patch tool calls. Universally destructive commands (rm -rf on /|~|$HOME, force-push to main/master, git reset --hard, git clean -fd/-fx, chmod -R 777 /, dd/mkfs on block devices, fork bombs, curl/wget | bash) are denied instantly by a regex deny-bucket. Everything else is decided by a bounded-turn LLM agent loop (max 8 turns, 60s wall-clock, 20s per request) that uses the official Z.ai Python SDK (`zai-sdk`) to drive `client.chat.completions.create(...)` with a single `review` tool whose `action` enum is `allow` / `deny` / `probe`. The configured AUTO_REVIEW_BASE_URL is passed through the SDK, so the hook works with any OpenAI-compatible provider (Z.ai, OpenRouter, Ollama, vLLM). On uncertainty or infra failure the hook declines and Codex shows its normal approval prompt.",
    "developerName": "dzungtr",
    "category": "Developer Tools",
    "capabilities": [
      "Read"
    ],
    "defaultPrompt": [
      "What does the auto-review plugin block?",
      "How do I extend the deny-bucket with my own rules?"
    ],
    "websiteURL": "https://github.com/dzungtr/harness6"
  }
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[auto-review on Agent Plugins Marketplace](https://pluginsmp.com/plugins/auto-review-2)