Default structured reviews can return planning prose instead of findings when Claude prioritises interactive Plan Mode. This release keeps isolated reviews and the tool-free setup probe out of that workflow.
- Preserve no built-in tools, strict empty MCP, no Chrome, the configured Claude model and xhigh effort for reviews.
- Retain Plan Mode for explicitly enabled MCP reviews. Advice, prepared tasks and rescue keep their existing permission modes.
- Keep strict native result/session validation, fail-closed findings and the single formatting retry.
- Add planning-response and MCP-boundary regressions, with matching command documentation and release metadata.
Validation: 765 tests passed with two platform skips; metadata and smoke passed. Codex routing passed while accurately reporting unavailable authentication in its nested sandbox. An authenticated comparison used identical public input and changed only the permission-mode argument, returning valid native findings after the Plan Mode route failed twice. Actual configured-default xhigh Claude review was independently validated and its five findings adjudicated.
Maintainer verification used macOS, Claude Code 2.1.234 and the existing app-bundled Codex CLI 0.153.4. The older standalone Codex CLI 0.147.0 rejected the configured Codex model; no global upgrade or model override was required. Authenticated Windows/WSL coverage remains unverified. Real read-only runs preserved fixture contents and Git state. Denied-write regressions use isolated fake providers; no live write-capable smoke was run.
Delivered through protected PR #18. Required Node 20/22/24 checks passed on the reviewed head and merged commit. The release tag, clean main and reviewed source tree were verified together.
Post-install verification: a fresh normal Codex session resolved the installed v0.1.18 skill. Both $claude review and $claude adversarial-review identified the seeded ownership defect on their first attempts. Original native provider responses agree with status/result retrieval and stored authority. Both explicit rescue --resume --job-id continuations retained their original provider UUIDs. Fixture contents and Git state remained unchanged and owned processes exited. All ten installed files match the released commit. No desktop restart was required.