The Codex reviewer in review.md captured the review by redirecting codex
exec's stdout to the review file. On Windows, codex writes process-teardown
output to stdout after the final agent message, so that noise was appended
to a non-empty file and slipped past the `[ ! -s ]` empty-output guard as a
silently polluted review (consumed by severity extraction and the
plan-review-convergence gate).
Capture the final message via codex's own `-o/--output-last-message <FILE>`
and discard stdout. The #1115 contract is preserved (stderr to .err,
capability-gated $CODEX_BYPASS_FLAG, --ephemeral, --skip-git-repo-check) and
the empty-output fallback still fires when codex leaves no/empty output.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>