Agent skill

Codex Guard

by Akimiya-z in Akimiya-z/codex-guard

Pre-submit hygiene check for AI-agent-authored pull requests.

MITAuto-check passedDevelopment

Install Codex Guard

skills CLI
$ npx skills add Akimiya-z/codex-guard --skill codex-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Akimiya-z/codex-guard codex-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Akimiya-z/codex-guard.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codex-guard .claude/skills/codex-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex-guard
GitHub stars
136
Token cost
~564 tokens
SKILL.md length
270 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Pre-submit hygiene check for AI-agent-authored pull requests.

  • Works in 5 steps: Find the CLI → Run the checks → Fix everything the CLI lists → …
  • You are about to open
  • SKILL.md covers 1. Find the CLI, 2. Run the checks, 3. Fix everything the CLI lists and 4. Exceptions, plus 1 more section
  • Calls node and npx

What it does

Codex Guard is an agent skill from Akimiya-z/codex-guard. Pre-submit hygiene check for AI-agent-authored pull requests. Use this skill whenever you are about to open or update a pull request: it runs the codex-guard CLI locally, verifies the diff contains no leftover TODO/FIXME/XXX markers and no hardcoded secrets, checks that commit subjects follow conventional commits, and blocks submission until the checks pass or exceptions are documented in the PR description.

Its SKILL.md is about 560 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests, Commit messages and Secrets management. The repository describes itself as: Quality gate for AI/Codex-generated pull requests: blocks TODO leftovers, leaked secrets, sloppy commits and red CI before they reach main. The licence is MIT.

When your agent uses it

  • You are about to open
  • Update a pull request: it runs the codex-guard CLI locally
  • Verifies the diff contains no leftover TODO/FIXME/XXX markers and no hardcoded secrets
  • Checks that commit subjects follow conventional commits

Example prompts

  • “/codex-guard”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Find the CLI
  2. Run the checks
  3. Fix everything the CLI lists
  4. Exceptions
  5. Then submit

What it can do on your machine

Read from SKILL.md and the folder at commit 87e138c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex Guard loads about 564 tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 270 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~564

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Akimiya-z/codex-guard at commit 87e138c, republished under its MIT licence (© Akimiya-z). 270 words, ~564 tokens.

Download SKILL.mdSave it as .claude/skills/codex-guard/SKILL.md (or your agent's skills folder).
name
codex-guard
description
Pre-submit hygiene check for AI-agent-authored pull requests. Use this skill whenever you are about to open or update a pull request: it runs the codex-guard CLI locally, verifies the diff contains no leftover TODO/FIXME/XXX markers and no hardcoded secrets, checks that commit subjects follow conventional commits, and blocks submission until the checks pass or exceptions are documented in the PR description.

codex-guard — self-check before you open a PR

You are about to open or update a pull request. Before submitting, run the same hygiene checks that the codex-guard GitHub Action enforces in CI — locally, on the working tree.

1. Find the CLI

  • If this repository ships the codex-guard source, run it directly: node src/cli.js
  • Otherwise, use npx (works once the package is published): npx -y codex-guard

2. Run the checks

  • Scan uncommitted changes: node src/cli.js --git --commits
  • Or scan a specific range: node src/cli.js --git origin/main --commits
  • Exit code 0 means no blocking findings; 1 means blocking findings were found; 2 is a usage error.

3. Fix everything the CLI lists

  • TODO / FIXME / XXX / HACK / WIP markers: remove them, or convert them to tracked issues and remove the code comments. Never leave "I'll handle this later" comments in a PR you submit.
  • Hardcoded secrets (AWS/GitHub/OpenAI/Stripe keys, connection strings, passwords): remove them, rotate any that were shared, and use the repository's secret storage. A redacted match in the report still means the secret is in the diff — treat it as real.
  • Non-conventional commit subjects (WIP, fix stuff, empty subjects): rewrite with conventional commits (feat, fix, docs, chore, ...).

4. Exceptions

If you deliberately keep something the CLI flags (for example a task-list checkbox), state it explicitly in the PR description so a human reviewer can confirm it is intentional. Do not silently resubmit a failing diff.

5. Then submit

Only open or update the PR after the checks exit 0 (or the exception is documented in the description). This keeps the CI-side gate green and the human review focused on real design questions.

© Akimiya-z, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/codex-guard of Akimiya-z/codex-guard.

Open the folder on GitHubat commit 87e138c

Compare with similar skills

Codex Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex Guard this skillAkimiya-z/codex-guard136—~564Automated safety check: PassMIT
PR Finalize Reviewmicrosoft/garnet12k—~3.1kAutomated safety check: PassMIT
Git Workflow and Versioningaddyosmani/agent-skills104k2 repos~3.5kAutomated safety check: NotesMIT
React Router Pull Request Creatorremix-run/react-router57k—~2.5kAutomated safety check: PassMIT
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Citus Merge Loopcitusdata/citus13k—~2.5kAutomated safety check: PassAGPL-3.0

Similar skills

  • PR Finalize Review

    microsoft/garnet

    Official

    Checks that a pull request's title and description match its implementation and reviews the code for Garnet best practices, reporting findings without posting them.

    12k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Git Workflow and Versioning

    addyosmani/agent-skills

    Sets git habits for every change: short-lived branches, atomic commits with descriptive messages, clean pull requests, plus versioning, tagging and changelogs for releases.

    104k GitHub starsUsed in 2 repos~3.5k tokens
    DevelopmentAuto-check: notes
  • React Router Pull Request Creator

    remix-run/react-router

    Packages finished React Router work into a draft pull request: branch, commit, push, a written PR body and the right GitHub labels.

    57k GitHub stars~2.5k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Citus Merge Loop

    citusdata/citus

    Take a list of citusdata/citus PR links or numbers and merge each one independently: sync it with its base branch, fix a red check-style job with make reindent, retry other red checks a bounded…

    13k GitHub stars~2.5k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Emoji Commit Conventions

    baptisteArno/typebot.io

    Sets the repository's convention for commit messages and pull request titles: one emoji prefix for the main intent, a concise title and clean follow-up commits.

    11k GitHub stars~424 tokensUpdated 3 days ago
    DevelopmentAuto-check passed

Categories

Questions about Codex Guard

What does Codex Guard do?

Pre-submit hygiene check for AI-agent-authored pull requests. Codex Guard is an agent skill from Akimiya-z/codex-guard. Pre-submit hygiene check for AI-agent-authored pull requests.

When should I use Codex Guard?

Codex Guard fits situations like: you are about to open; update a pull request: it runs the codex-guard CLI locally; verifies the diff contains no leftover TODO/FIXME/XXX markers and no hardcoded secrets; checks that commit subjects follow conventional commits.

How do I install Codex Guard in Claude Code?

Run `npx skills add Akimiya-z/codex-guard --skill codex-guard -a claude-code`. Or copy the skill folder (skills/codex-guard in Akimiya-z/codex-guard) into .claude/skills/codex-guard in your project. Claude Code loads it when a task matches its description.

How do I install Codex Guard in Codex?

Run `npx skills add Akimiya-z/codex-guard --skill codex-guard -a codex`. Or copy the skill folder (skills/codex-guard in Akimiya-z/codex-guard) into .agents/skills/codex-guard in your project. Codex loads it when a task matches its description.

Can I use Codex Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Akimiya-z/codex-guard --skill codex-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-guard, .gemini/skills/codex-guard, .github/skills/codex-guard and .opencode/skills/codex-guard in your project.

What does Codex Guard need to run?

Going by SKILL.md and its folder, Codex Guard needs the command-line tools its instructions call (node and npx). Our summary lists: Node.js.

Does Codex Guard access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codex Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codex Guard use?

Codex Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex Guard use?

About 564 tokens (SKILL.md is roughly 2.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codex Guard?

Skills that share tags, products or a category with Codex Guard: PR Finalize Review (microsoft/garnet, 12k stars), Git Workflow and Versioning (addyosmani/agent-skills, 104k stars), React Router Pull Request Creator (remix-run/react-router, 57k stars) and Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex Guard?

Akimiya-z (a GitHub user) maintains it in Akimiya-z/codex-guard, which has 136 GitHub stars. The repository was last updated on October 1, 2026.

Source: Akimiya-z/codex-guard on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.