Agent skill

Codex Host

by avelikiy in avelikiy/great_cto

Run the greatcto controlled Codex lifecycle with controller-owned writes, verifier evidence, human gates and optional artifact release.

MITAuto-check: notes

Install Codex Host

skills CLI
$ npx skills add avelikiy/great_cto --skill codex-host -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install avelikiy/great_cto codex-host --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codex-host .claude/skills/codex-host && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex-host
GitHub stars
103
Token cost
~789 tokens
SKILL.md length
309 words
Files
1
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Run the greatcto controlled Codex lifecycle with controller-owned writes, verifier evidence, human gates and optional artifact release.

  • SKILL.md covers Preflight, Start, Gates and recovery and Release boundary
  • Calls npx; needs GATE_TOKEN and RELEASE_TOKEN

What it does

Codex Host is an agent skill from avelikiy/great_cto. Run the greatcto controlled Codex lifecycle with controller-owned writes, verifier evidence, human gates and optional artifact release.

Its SKILL.md is about 790 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with GitHub. The repository describes itself as: You already have the agent. This is everything around it. greatcto runs Claude Code as a pipeline of 70 specialist agents — an independent model checks each stage before the next… The licence is MIT.

Example prompts

  • “/codex-host”

Requirements

  • Node.js
  • Docker
  • A credential in GATE_TOKEN
  • A credential in RELEASE_TOKEN
  • Pre-approved tools (allowed-tools): Read, Bash

What it can do on your machine

Read from SKILL.md and the folder at commit 5d6e760. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GATE_TOKEN
    • RELEASE_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex Host loads about 789 tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 309 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~789

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from avelikiy/great_cto at commit 5d6e760, republished under its MIT licence (© avelikiy). 309 words, ~789 tokens.

Download SKILL.mdSave it as .claude/skills/codex-host/SKILL.md (or your agent's skills folder).
name
codex-host
description
Run the great_cto controlled Codex lifecycle with controller-owned writes, verifier evidence, human gates and optional artifact release.
allowed-tools
Read, Bash
when_to_use
Use when the user asks Codex to run or inspect a full great_cto pipeline rather than only use an individual skill.
effort
high

Controlled Codex host

Use the version-pinned npm entrypoint below. A Codex plugin install loads skills and MCP configuration, but it does not add the great-cto npm binary to PATH. Do not imitate Claude Code hooks or manually chain roles: the controller reads shared/pipeline.toml, persists the cursor and owns every write and gate transition.

Preflight

sh
npx --yes great-cto@3.58.1 codex-host doctor
npx --yes great-cto@3.58.1 codex-host list --dir /absolute/project

doctor.state=blocked means do not start. Docker may be unavailable when no checks/release policy is requested; GitHub CLI may be unavailable when the local adapter is used. The run store must not be group/world accessible. For mixed-host runs, also require doctor.checks.claude.state=available.

Start

Policies must be operator-owned absolute files outside the worker project. Allowed paths are explicit controller write boundaries.

sh
npx --yes great-cto@3.58.1 codex-host start \
  --dir /absolute/project \
  --prompt "the requested outcome" \
  --allow src,tests,docs \
  --checks-policy /absolute/operator/checks.json \
  --release-policy /absolute/operator/release.json

Read the returned status, pending and release object. Never treat exit 2 as success: it means a gate, manual action or blocked evidence requires attention.

Since 3.47.0, independent graph roles can run on both hosts with --routes qa-engineer=claude-code,security-officer=codex on start. The controller dispatches only a symmetric join pair concurrently, checks both proposals for overlap, serializes writes and runs the existing verifier and human gates. The route map is fixed for the run. An interrupted wave must be inspected; never start replacement workers against an uncertain wave.

Gates and recovery

Show the operator the exact gate/release summary and wait for explicit approval. Then pass back the controller-issued token; never synthesize or persist one in a project file.

sh
npx --yes great-cto@3.58.1 codex-host approve RUN_UUID --token GATE_TOKEN
npx --yes great-cto@3.58.1 codex-host approve-release RUN_UUID --token RELEASE_TOKEN
npx --yes great-cto@3.58.1 codex-host resume RUN_UUID

Use recover only after inspecting the recorded reason. Recovery reuses the same candidate and refuses unknown partial writes. cancel revokes unexecuted approval but does not delete external audit evidence.

Release boundary

The local and GitHub Release adapters publish immutable artifacts and declare activation: none. They do not deploy traffic. Local rollback means selecting a previous directory; GitHub rollback is a newly gated superseding release. Production activation needs a separate adapter and approval contract.

Detailed policy schemas and limitations are in docs/HOST-CODEX.md.

© avelikiy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/codex-host of avelikiy/great_cto.

Open the folder on GitHubat commit 5d6e760

Compare with similar skills

Codex Host next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex Host compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex Host this skillavelikiy/great_cto103—~789Automated safety check: NotesMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Diagnosing Superpowers Sessionsobra/superpowers296k3 repos~1.7kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow83k5 repos~1.3kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    296k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    83k GitHub starsUsed in 5 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Last30days

    mvanhorn/last30days-skill

    Research what people actually say about any topic in the last 30 days.

    64k GitHub stars~7.8k tokensUpdated today
    Research & ScienceAuto-check: notes

More from avelikiy/great_cto

All 28 skills in this repo
  • AnyDesign Design Analyzer

    avelikiy/great_cto

    Analyzes a screenshot, website or Figma file and writes a `design.md` with its token system, component inventory and reconstruction notes, or an `element.md` for one element.

    103 GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Opportunity Solution Tree

    avelikiy/great_cto

    Builds an Opportunity Solution Tree that links one measurable outcome to customer opportunities, candidate solutions and experiments.

    103 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Rewrites a feature-list roadmap into outcome statements that name the customer segment, the result they get and the business impact, grouped into themes.

    103 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Exposed Secret Rotation

    avelikiy/great_cto

    Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session.

    103 GitHub stars~884 tokensUpdated yesterday
    Auto-check: notes
  • Cost Model

    avelikiy/great_cto

    Standardized cost-estimation framework for greatcto plans. An agent skill from avelikiy/great_cto.

    103 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Skeptical Triage

    avelikiy/great_cto

    Runs a three-round self-challenge plus an arbiter over high-stakes findings, so false positives from reviews, audits and flaky-test verdicts do not become blockers.

    103 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check: notes

Works with

Questions about Codex Host

What does Codex Host do?

Run the greatcto controlled Codex lifecycle with controller-owned writes, verifier evidence, human gates and optional artifact release. Codex Host is an agent skill from avelikiy/great_cto. Run the greatcto controlled Codex lifecycle with controller-owned writes, verifier evidence, human gates and optional artifact release.

How do I install Codex Host in Claude Code?

Run `npx skills add avelikiy/great_cto --skill codex-host -a claude-code`. Or copy the skill folder (skills/codex-host in avelikiy/great_cto) into .claude/skills/codex-host in your project. Claude Code loads it when a task matches its description.

How do I install Codex Host in Codex?

Run `npx skills add avelikiy/great_cto --skill codex-host -a codex`. Or copy the skill folder (skills/codex-host in avelikiy/great_cto) into .agents/skills/codex-host in your project. Codex loads it when a task matches its description.

Can I use Codex Host in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add avelikiy/great_cto --skill codex-host -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-host, .gemini/skills/codex-host, .github/skills/codex-host and .opencode/skills/codex-host in your project.

What does Codex Host need to run?

Going by SKILL.md and its folder, Codex Host needs the command-line tools its instructions call (npx) and credentials named GATE_TOKEN and RELEASE_TOKEN. Our summary lists: Node.js; Docker; A credential in GATE_TOKEN; A credential in RELEASE_TOKEN. Its frontmatter pre-approves these tools: Read, Bash.

Does Codex Host access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codex Host safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Codex Host use?

Codex Host is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex Host use?

About 789 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codex Host?

Skills that share tags, products or a category with Codex Host: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Diagnosing Superpowers Sessions (obra/superpowers, 296k stars), GitHub Deep Research (bytedance/deer-flow, 83k stars) and Greploop (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex Host?

avelikiy (a GitHub user) maintains it in avelikiy/great_cto, which has 103 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 7, 2026.

Source: avelikiy/great_cto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.