---
title: Top Code Quality & Review Skills for Codex
slug: top-code-quality-review-skills-for-codex
type: category-agent-cut
category: code-quality-review
agent: codex
canonical: https://top-agent-skills.com/top-code-quality-review-skills-for-codex
verified: 11
unverified: 9
updated: 2026-09-29
---

# Top Code Quality & Review Skills for Codex

For code review in Codex CLI, install Trail of Bits' security skills and Anthropic's debug and tech-debt skills — Codex runs in the terminal with real repo access, which is exactly the setting where a severity-tagged review pass beats an inline suggestion. superpowers and tdd-skill add the before-the-code discipline if you want review pressure earlier than the diff.

## Verified on Codex CLI (11)

### 1. wordpress-agent-skills — score 67/100 (verified-org)

WordPress’s own answer to agents writing pre-Gutenberg code: blocks, block themes, plugins, the modern APIs.

- Best for: Stopping an agent generating outdated WordPress patterns — pre-block themes, missing block deprecations that cause "Invalid block" errors, plugin code that skips the security conventions.
- Not ideal for: Running or hosting a WordPress site. These teach how to build for WordPress; updates, backups and hosting are a host’s skill, not this set.
- Publisher: WordPress · GPL-2.0-or-later
- Verified on: claude-code, codex, cursor

```bash
npx skills add WordPress/agent-skills --skill wp-plugin-development --yes
```

Full entry: https://top-agent-skills.com/skill/wordpress-agent-skills (https://top-agent-skills.com/skill/wordpress-agent-skills.md)

### 2. superpowers — score 61/100 (community)

Structured multi-step development. Brainstorm → spec → plan → build → review → merge — TDD baked in.

- Best for: Long-running engineering tasks where you want each phase to handoff cleanly.
- Not ideal for: Quick one-shot tasks — the orchestration overhead is not worth it.
- Publisher: obra · MIT
- Verified on: claude-code, cursor, codex

```bash
npx skills add obra/superpowers
```

Full entry: https://top-agent-skills.com/skill/superpowers (https://top-agent-skills.com/skill/superpowers.md)

### 3. debug — score 51/100 (official-anthropic)

Disciplined debugging loop. Reproduce, isolate, diagnose, fix.

- Best for: When behavior diverges from expected and the cause is not obvious from a quick read.
- Publisher: Anthropic · MIT
- Verified on: claude-code, cursor, codex, antigravity

```bash
claude plugin install engineering
```

Full entry: https://top-agent-skills.com/skill/debug (https://top-agent-skills.com/skill/debug.md)

### 4. tech-debt — score 51/100 (official-anthropic)

Honest tech-debt audit with a prioritized cleanup backlog.

- Best for: Quarterly planning, post-incident review, or any moment the team agrees something has to give.
- Publisher: Anthropic · MIT
- Verified on: claude-code, cursor, codex, antigravity

```bash
claude plugin install engineering
```

Full entry: https://top-agent-skills.com/skill/tech-debt (https://top-agent-skills.com/skill/tech-debt.md)

### 5. vercel-web-design-guidelines — score 49/100 (verified-org)

100+ accessibility and UX rules from Vercel, applied as a structural audit on your UI code.

- Best for: Pre-PR audits, accessibility compliance, design system enforcement.
- Publisher: Vercel · MIT
- Verified on: claude-code, cursor, codex

```bash
npx skills add github.com/vercel-labs/agent-skills --skill web-design-guidelines
```

Full entry: https://top-agent-skills.com/skill/vercel-web-design-guidelines (https://top-agent-skills.com/skill/vercel-web-design-guidelines.md)

### 6. vercel-react-best-practices — score 49/100 (verified-org)

57 React/Next.js performance rules, applied as a structural review on your code.

Full entry: https://top-agent-skills.com/skill/vercel-react-best-practices (https://top-agent-skills.com/skill/vercel-react-best-practices.md)

### 7. trail-of-bits — score 49/100 (verified-org)

Security audits run by a real security firm. CodeQL + Semgrep + audit workflows.

Full entry: https://top-agent-skills.com/skill/trail-of-bits (https://top-agent-skills.com/skill/trail-of-bits.md)

### 8. prisma-orm — score 49/100 (verified-org)

Prisma migrations and queries by the book. Index-aware, migration-safe, type-correct.

Full entry: https://top-agent-skills.com/skill/prisma-orm (https://top-agent-skills.com/skill/prisma-orm.md)

### 9. next-js-app-router — score 49/100 (verified-org)

Next.js App Router by the book. Server components, streaming, parallel routes.

Full entry: https://top-agent-skills.com/skill/next-js-app-router (https://top-agent-skills.com/skill/next-js-app-router.md)

### 10. sentry-error-handling — score 48/100 (verified-org)

Sentry the right way. Source maps, releases, breadcrumbs, performance, structured tags.

Full entry: https://top-agent-skills.com/skill/sentry-error-handling (https://top-agent-skills.com/skill/sentry-error-handling.md)

### 11. tdd-skill — score 46/100 (community)

TDD with red/green/refactor as a concrete TypeScript walkthrough.

Full entry: https://top-agent-skills.com/skill/tdd-skill (https://top-agent-skills.com/skill/tdd-skill.md)

## In Code Quality & Review but NOT verified on Codex CLI (9)

These may well work — the SKILL.md format is shared. They are listed as unverified because this site lists an agent only where the install was run or the publisher documents a path for it.

- composition-patterns — Boolean prop hell → compound components. Cleaner React component APIs by construction. (https://top-agent-skills.com/skill/composition-patterns)
- simplify — Review for reuse, quality, efficiency. Catches over-abstraction and dead code before merge. (https://top-agent-skills.com/skill/simplify)
- code-review-plugin — Structured PR reviews with severity-tagged findings — bugs, security, perf, style. (https://top-agent-skills.com/skill/code-review-plugin)
- semgrep — Semgrep's own scanning skill: run the industry-standard SAST engine across 30+ languages, and author custom rules for your codebase's patterns. (https://top-agent-skills.com/skill/semgrep-scan)
- code-security — A vendor-maintained rule corpus for secure code review — one reference file per vulnerability class, from SQL injection to Terraform misconfiguration. (https://top-agent-skills.com/skill/semgrep-code-security)
- code-review-security — OWASP-published review, SCA, secrets and threat-modelling skills — the most citable provenance available for security review vocabulary. (https://top-agent-skills.com/skill/owasp-security-skills)
- security-review — Pre-merge security sweep on the current branch's diff. (https://top-agent-skills.com/skill/security-review)
- code-review — The canonical Anthropic code review. Effort levels from quick to ultra. (https://top-agent-skills.com/skill/code-review-builtin)
- review — PR review with inline GitHub comments via gh. (https://top-agent-skills.com/skill/review-pr)

## Common question

**How does Codex load a skill compared with Claude Code?**

Codex adopted the SKILL.md format directly, so the same folder works, but the install path differs: Codex takes the repo-plus-path form (codex skills add github.com/owner/repo/skills/name) rather than a --skill flag. The frontmatter and the three-tier loading behaviour are the same.

---

_Top Agent Skills. Machine-readable twin of https://top-agent-skills.com/top-code-quality-review-skills-for-codex._
