Agent skill

Codexhost Update Impact Audit

by BytePioneer-AI in BytePioneer-AI/codex-host

Diagnose whether a Codex Desktop update changed codexhost Composer/CDP bindings, private Renderer DOM or React state, Host bridges, routing, the Codex usage submission gate, or injected UI.

LGPL-3.0Auto-check passedFrontend & Design

Install Codexhost Update Impact Audit

skills CLI
$ npx skills add BytePioneer-AI/codex-host --skill codexhost-update-impact-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BytePioneer-AI/codex-host codexhost-update-impact-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BytePioneer-AI/codex-host.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/codexhost-update-impact-audit .claude/skills/codexhost-update-impact-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codexhost-update-impact-audit
GitHub stars
2.8k
Token cost
~3.5k tokens
SKILL.md length
1,713 words
Files
2
Skills in repo
9
Repo updated
First seen
Licence
LGPL-3.0

At a glance

Diagnose whether a Codex Desktop update changed codexhost Composer/CDP bindings, private Renderer DOM or React state, Host bridges, routing, the Codex usage submission gate, or injected UI.

  • Works in 6 steps: Establish the comparison chain → Diff semantic contracts → Trace codexhost ownership paths → …
  • Tasks that involve State management
  • SKILL.md covers Guardrails, 1. Establish the comparison…, 2. Diff semantic contracts and 3. Trace codexhost ownership…, plus 4 more sections
  • Calls npm and git

What it does

Codexhost Update Impact Audit is an agent skill from BytePioneer-AI/codex-host. Diagnose whether a Codex Desktop update changed codexhost Composer/CDP bindings, private Renderer DOM or React state, Host bridges, routing, the Codex usage submission gate, or injected UI. Use after an installed Codex update or when compatibility regresses and the affected surface is unknown.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Frontend & Design, covering State management. The repository describes itself as: Run Pi and Claude Code directly in Codex Desktop. 在 Codex Desktop 中直接运行 Pi 和 Claude Code。 The licence is LGPL-3.0.

When your agent uses it

  • Tasks that involve State management

Example prompts

  • “/codexhost-update-impact-audit”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Establish the comparison chain
  2. Diff semantic contracts
  3. Trace codexhost ownership paths
  4. Probe the real Renderer
  5. Rank hypotheses and validate narrowly
  6. Report verdict first

What it can do on your machine

Read from SKILL.md and the folder at commit 08c7d65. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codexhost Update Impact Audit loads about 3.5k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 1,713 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BytePioneer-AI/codex-host at commit 08c7d65, republished under its LGPL-3.0 licence (© BytePioneer-AI). 1,713 words, ~3,523 tokens.

Download SKILL.mdSave it as .claude/skills/codexhost-update-impact-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
codexhost-update-impact-audit
description
Diagnose whether a Codex Desktop update changed codexhost Composer/CDP bindings, private Renderer DOM or React state, Host bridges, routing, the Codex usage submission gate, or injected UI. Use after an installed Codex update or when compatibility regresses and the affected surface is unknown.

codexhost update impact audit

Audit before changing codexhost. Produce a verdict backed by bundle and live-Renderer evidence. Apply a fix only when the user explicitly requests one.

可先运行 npm run audit:codex-desktop 辅助检测;该命令不能替代下面的语义对比、ownership 追踪、真实 Renderer 探测和必要的行为验证,后续步骤仍须继续执行。

Guardrails

  • Read the repository AGENTS.md and record git status; preserve unrelated dirty-worktree changes.
  • Treat Codex Desktop private DOM, React state, and main-process services as versioned contracts.
  • Use semantic attributes, API shape, ownership, and observed relationships as contracts. Bundle hashes, asset names, minified identifiers, localized labels, private CSS classes, credentials, prompts, and full payloads are evidence only.
  • Start with a read-only inspection of an existing codexhost-controlled Desktop. Use a controlled launch or mutate Renderer state only when the required boundary cannot otherwise be verified.
  • Store only sanitized evidence under ignored .codexhost/update-impact/. Never persist Thread IDs, request IDs, prompts, transcripts, tokens, credentials, URL query/hash values, or full DOM snapshots.
  • Do not change production code during an audit. Do not claim a live or routing result unless that exact check ran.

1. Establish the comparison chain

Record the installed executable, Desktop version/build, Chromium version, and app.asar hash. Determine these distinct versions when possible:

  • reviewed baseline: the last version whose audit passed;
  • direct predecessor: the version immediately before the installed build;
  • current: the installed build under review.

Use the reviewed baseline for the compatibility decision. Use a direct predecessor only to localize the newest change. Never silently substitute a much older bundle for either role.

Search, in order, for prior evidence under .codexhost/update-impact/, Sparkle installation caches, compatibility fixtures, and other complete local installations. The official Sparkle appcast may establish release order and download locations, but downloading a full application is optional and must not block the audit when live evidence and a reviewed baseline are available.

Unpack each available app.asar into a temporary directory. After the audit, retain a minimal sanitized baseline at:

text
.codexhost/update-impact/<version>/
  manifest.json
  app-initial.js
  app-initial.css
  composer-utility-bar.js
  marker-inventory.json
  live-renderer.json

manifest.json should identify version/build, Chromium version, executable path, hashes, audit time, verdict, and which checks actually ran. Do not retain a full application or archive merely for the next comparison.

Completion criterion: the report names the reviewed baseline, direct predecessor if known, and current version without conflating them.

2. Diff semantic contracts

Compare relevant app-initial, composer-utility-bar, and relocated owning chunks. Hash and filename changes are not impact. Classify each observed difference as:

  • unchanged contract;
  • source relocation or chunk split;
  • styling-only change;
  • DOM relationship change;
  • React/API-shape change;
  • removed or ambiguous contract.

Inventory contracts by surface:

SurfacePrimary evidence
Composer identitydata-codex-composer-root, data-above-composer-portal, data-above-composer-conversation-id
Modeldata-codex-intelligence-trigger, data-composer-navigation-target="reasoning", owning Fiber props
Permissiondata-composer-navigation-target="permissions", permissionsHostId, permission-state Fiber props
Request/prewarmexecutionTargetHostId, permissionsHostId, request-client and prewarm-manager API shape
Footer/layoutFooterInlineControls, Context radial indicator shape, trailing action ownership
Sidebardata-app-action-sidebar-thread-row, data-thread-title-trigger, data-thread-title
Settingsdata-testid="app-shell-header-context-menu-surface" and structural insertion slot
Forkdata-response-annotation-conversation, data-content-search-turn-key, owning callback/Fiber state
Codex usage gateComposer owner props onLocalSubmitStart + boolean submitDisabled; boolean selectors reading authMethod → rate_limit.allowed and reserve hardBlocked; useSyncExternalStore hook layout

Marker counts are triage signals, not conclusions. If a marker moves to another chunk with the same use and live relationship, classify it as relocation. If counts remain equal, still inspect changed relationships and API shape.

Completion criterion: every codexhost-consumed contract is accounted for, including relocation to a new chunk.

3. Trace codexhost ownership paths

Read the current call sites and follow each surface independently from discovery through insertion or routing:

  • Composer and Send/trailing actions;
  • Agent and Model;
  • Permission;
  • Context Usage, Harness Usage, and Credits;
  • Composer DOM identity and React Model target;
  • request bridge and prewarm clear;
  • title policy;
  • sidebar decoration;
  • settings entry;
  • Fork;
  • Codex usage gate (renderer-codex-usage-gate.ts, driven by renderComposerAgentControl's external-submission readiness);
  • Host create and subsequent-Turn routing.

Prefer unique semantic candidates plus ownership checks. Record fail-closed behavior for absent or ambiguous candidates. Keep source relocation separate from an actual anchor or ownership change.

Completion criterion: each reported surface points to the exact codexhost file/line that consumes the contract.

4. Probe the real Renderer

Read-only probe first

If Codex is already running under codexhost, discover the active Inspector endpoint from the process arguments or runtime descriptor and attach through packages/desktop-control. Do not reload the Renderer or reinstall policies merely to read status.

Inspect only sanitized summaries:

  • selected primary app://-/index.html Renderer and element count;
  • populated Composer count and visibility;
  • unique semantic Model, Permission, Context, Send, and portal candidates;
  • direct parent/child/sibling relationships;
  • computed display, visibility, align-items, gap, and bounding rectangles;
  • codexhost control presence, visibility, ordering, overlap, and containment;
  • Renderer Adapter, title policy, and draft-prewarm policy readiness;
  • Harness availability;
  • sidebar rows/icons, settings trigger, and Fork candidates.

Interpret visibility in state. A Credits, Permission, Usage, or Model control hidden because the current Agent, phase, or data availability does not require it is not an impact. For visible controls, alignment and ownership matter more than a fixed pixel height. Equal heights alone do not prove correct placement.

Controlled probe when required

Use tools/renderer-binding/run.mjs only when a clean controlled lifecycle, reload, observer, or submission boundary is required. On macOS pass the executable file:

text
/Applications/ChatGPT.app/Contents/MacOS/ChatGPT

The runner does not accept the .app directory. A controlled flow may verify Agent switching, stale-prewarm clearing, new Thread creation, title behavior, or Fork. State clearly when user interaction or creation boundaries were not exercised.

Show full SKILL.md (870 more words)Show less
Codex usage gate probe

This surface lets an external Harness submit while the ChatGPT-signed-in Codex subscription is out of usage by projecting false for one Composer's two Desktop usage-gate subscriptions. It depends on private React/state-library internals, so check it on every update. npm run audit:codex-desktop reports its structure as the codex-usage-gate surface (see tools/codex-desktop-contract-audit/README.md); codex-usage-account-gate-dormant means the audit ran without a ChatGPT sign-in whose Account gate reads usage. The audit does not verify behavior.

Bundle evidence (evidence only, not contracts): the Composer owner combines submitDisabled from an Account rate-limit selector (authMethod !== "chatgpt" early return, then rate_limit.allowed === false, gated to host local) and a reserve hardBlocked selector. Confirm both still exist and still feed submitDisabled, and that no new Account-wide usage blocker was added beside them. If Desktop now exempts external models/Threads or stops blocking in the Renderer, report that the module can be removed.

Manual read-only live probe, when the audit surface is not no-impact or its counts need explaining, in a Composer inside the primary Renderer. Do not patch getSnapshot, subscribe to the store, or call effect functions:

  1. From the editor's nearest React host, walk committed ancestors; exactly one owner has onLocalSubmitStart and boolean submitDisabled, in both a new draft and an existing Thread.
  2. In its hook list, find subscriber memo candidates with dependencies [store, atom] or Desktop 26.928's [signal, undefined], where the readonly signal exposes atom, store, get, and subscribe. The next hook has queue = { value: boolean, getSnapshot }, followed by effect { create, deps: [subscriber.subscribe] }, without atom.write, and createRender() returning nothing. An instance getter may equal the subscriber getter or be a lazy wrapper; for an unbound wrapper, both snapshots must equal the native boolean store.get(atom).
  3. Replay each candidate's atom.read with tracing proxies, following readonly boolean selector indirections with cycle and work bounds. Exactly one reads hardBlocked without active or Account gate fields (reserve). When signed in with ChatGPT, exactly one reads authMethod and rate_limit.allowed without reserve fields (Account). Each replayed boolean must equal its native value; reject mixed gates.
  4. store.sub, subscriber.getSnapshot, and the instance getSnapshot are writable.

With codexhost running and an external Agent selected, bound gates show an instance getSnapshot of () => false for both hooks. The Agent control's hover title shows the "cannot separate from Codex usage" message when binding failed.

Behavioral check requires a ChatGPT account that is out of Codex usage; API-key sign-in never triggers the gate. With non-empty text and an external Agent, Send is enabled in a new draft and an existing Thread; after switching to Codex it returns to disabled. Do not submit a message unless the user asks. Remove any temporary text without touching text the user typed. Report unverified when no exhausted account is available.

Completion criterion: no surface receives a live verdict from bundle inspection alone.

5. Rank hypotheses and validate narrowly

Before proposing a fix, rank 3–5 falsifiable hypotheses by evidence and name the observation that would disprove each. Run the narrowest relevant tests first, for example:

text
npx vitest run <affected renderer tests> --config tests/vitest.config.js
npm run typecheck
npm run build:renderer
git diff --check

For a requested fix:

  1. Add a regression test that models the observed DOM, Fiber, API-shape, visual relationship, or routing boundary.
  2. Run it red for the observed reason.
  3. Make one minimal production change in the owning module.
  4. Run it green and repeat the relevant live probe.

A test that proves only that a control exists or a mock was called does not prove visual alignment, ownership, or routing.

Completion criterion: a fix is tied to one confirmed failing boundary, not to a changed bundle name or broad suspicion.

6. Report verdict first

The first line must answer the user's question directly:

text
结论:无影响 / 有确认影响 / 可能有影响 / 尚未验证。

Then give 3–5 decisive facts before detailed evidence. Classify every surface as:

  • no impact: bundle contract and relevant live boundary both agree;
  • confirmed impact: a live or focused regression check demonstrates failure;
  • possible impact: evidence changed materially but the decisive boundary is unavailable;
  • unverified: the boundary was not exercised or observable.

Include:

  • reviewed baseline, direct predecessor if known, and current version;
  • exact files/lines consuming each affected contract;
  • old/new semantic evidence and whether it is relocation, styling, relationship, or API-shape change;
  • live commands/checks and sanitized outcomes;
  • focused tests actually run;
  • skipped or blocked checks and why;
  • smallest proposed change only for confirmed impact;
  • confirmation that unrelated worktree changes were preserved.

Do not bury the answer in the evidence. “Frontend changed” and “codexhost is impacted” are separate conclusions.

Common failure modes

  • Comparing current against whatever old bundle is easiest to find instead of the reviewed baseline.
  • Losing the reviewed baseline and downloading hundreds of megabytes on every audit.
  • Treating an asset hash, minified name, marker count, or chunk relocation as compatibility impact.
  • Reloading a user's active Renderer before attempting a read-only inspection.
  • Treating a state-hidden control or a pixel-height change as a visual regression without checking its parent layout and role.
  • Declaring Host routing, title creation, or Fork healthy without exercising that boundary.
  • Updating multiple controls before isolating the failed ownership contract.
  • Reformatting, resetting, staging, or overwriting unrelated work while investigating.
  • Declaring the Codex usage gate healthy from a Codex-selected, empty, API-key-signed-in, or not-exhausted Composer; only the external Agent path with exhausted ChatGPT usage exercises it.
  • Checking only the Send button's DOM disabled; Desktop also guards Enter and the submit function with the same submitDisabled.

© BytePioneer-AI, LGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/codexhost-update-impact-audit of BytePioneer-AI/codex-host.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 08c7d65

Compare with similar skills

Codexhost Update Impact Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codexhost Update Impact Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codexhost Update Impact Audit this skillBytePioneer-AI/codex-host2.8k—~3.5kAutomated safety check: PassLGPL-3.0
Svelte Core Best Practicesrilldata/rill2.9k4 repos~1.8kAutomated safety check: PassApache-2.0
Dify Component Writing Guidelanggenius/dify158k—~626Automated safety check: PassCustom licence
React State Managementinvolvex/youtube-music-cli45613 repos~3kAutomated safety check: PassMIT
Pierre Theming Librarypierrecomputer/pierre6.3k—~661Automated safety check: PassApache-2.0
Frontend Patternskurealnum/dotfiles29019 repos~3.7kAutomated safety check: PassNone

Similar skills

  • Rules for writing idiomatic Svelte 5 code: when to reach for runes like state, derived and effect, and how to handle props, attachments and bindings.

    2.9k GitHub starsUsed in 4 repos~1.8k tokens
    Frontend & DesignAuto-check passed
  • Use when implementing or refactoring React/TypeScript components and the task requires decisions about component ownership, feature boundaries, state, data…

    158k GitHub stars~626 tokensUpdated today
    Frontend & DesignAuto-check passed
  • React State Management

    involvex/youtube-music-cli

    Master modern React state management with Redux Toolkit, Zustand, Jotai, and React Query.

    456 GitHub starsUsed in 13 repos~3k tokens
    Frontend & DesignAuto-check passed
  • Pierre Theming Library

    pierrecomputer/pierre

    Explains how to use the @pierre/theming package to list, resolve, select, switch and persist themes, with controller, color and React references.

    6.3k GitHub stars~661 tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Frontend Patterns

    kurealnum/dotfiles

    Frontend development patterns for React, Next.js, state management, performance optimization, and UI best practices.

    290 GitHub starsUsed in 19 repos~3.7k tokens
    Frontend & DesignAuto-check passed
  • Explains how LobeHub client code fetches data through services, SWR store hooks and cache keys, and when to avoid useEffect fetching or duplicated state.

    83k GitHub stars~1.8k tokensUpdated today
    Frontend & DesignAuto-check passed

More from BytePioneer-AI/codex-host

All 9 skills in this repo
  • Codexhost PR Triage

    BytePioneer-AI/codex-host

    手动增量分诊 codexhost Issue 与 PR,评估 PR 价值和实现克制,生成只读本地看板与回复草稿. An agent skill from BytePioneer-AI/codex-host.

    2.8k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Codexhost Add Harness

    BytePioneer-AI/codex-host

    为 codexhost 新增 Harness 插件,或规划、审查、补全现有 Harness Adapter。按当前公共契约实现原生能力,区分插件后端、预装发行和 Desktop 产品接入;不用于单纯添加 Model、Provider 或账号。

    2.8k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Codexhost Release

    BytePioneer-AI/codex-host

    发布 codexhost 正式版、预览版,编写或确认 Release Notes,检查发布 CI,暂停、恢复或排查发布。支持正常正式发布,以及 npm latest + GitHub Prerelease、不给现有用户更新提示的预览发行。不用于普通代码提交或 Harness CLI 更新。

    2.8k GitHub stars~998 tokensUpdated 2 days ago
    Auto-check passed
  • Web Gui Tester

    BytePioneer-AI/codex-host

    Verify web frontend behavior through real GUI interactions, read-only page inspection, and screenshots.

    2.8k GitHub starsUsed in 1 repo~4.1k tokens
    Auto-check passed
  • Feature Boundary Planner

    BytePioneer-AI/codex-host

    Trace a codexhost feature change across UI surfaces, Host routing, Harness capabilities, state ownership, persistence, and validation.

    2.8k GitHub stars~755 tokensUpdated 2 days ago
    Auto-check passed
  • Control Browser

    BytePioneer-AI/codex-host

    Control a browser using the tools available in the current session to navigate, inspect, click, fill, capture and verify pages.

    2.8k GitHub stars~656 tokensUpdated 2 days ago
    Auto-check passed

Questions about Codexhost Update Impact Audit

What does Codexhost Update Impact Audit do?

Diagnose whether a Codex Desktop update changed codexhost Composer/CDP bindings, private Renderer DOM or React state, Host bridges, routing, the Codex usage submission gate, or injected UI. Codexhost Update Impact Audit is an agent skill from BytePioneer-AI/codex-host. Diagnose whether a Codex Desktop update changed codexhost Composer/CDP bindings, private Renderer DOM or React state, Host bridges, routing, the Codex usage submission gate, or injected UI.

When should I use Codexhost Update Impact Audit?

Codexhost Update Impact Audit fits situations like: tasks that involve State management.

How do I install Codexhost Update Impact Audit in Claude Code?

Run `npx skills add BytePioneer-AI/codex-host --skill codexhost-update-impact-audit -a claude-code`. Or copy the skill folder (.agents/skills/codexhost-update-impact-audit in BytePioneer-AI/codex-host) into .claude/skills/codexhost-update-impact-audit in your project. Claude Code loads it when a task matches its description.

How do I install Codexhost Update Impact Audit in Codex?

Run `npx skills add BytePioneer-AI/codex-host --skill codexhost-update-impact-audit -a codex`. Or copy the skill folder (.agents/skills/codexhost-update-impact-audit in BytePioneer-AI/codex-host) into .agents/skills/codexhost-update-impact-audit in your project. Codex loads it when a task matches its description.

Can I use Codexhost Update Impact Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BytePioneer-AI/codex-host --skill codexhost-update-impact-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codexhost-update-impact-audit, .gemini/skills/codexhost-update-impact-audit, .github/skills/codexhost-update-impact-audit and .opencode/skills/codexhost-update-impact-audit in your project.

What does Codexhost Update Impact Audit need to run?

Going by SKILL.md and its folder, Codexhost Update Impact Audit needs the command-line tools its instructions call (npm and git). Our summary lists: Node.js.

Does Codexhost Update Impact Audit access the network?

SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Codexhost Update Impact Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codexhost Update Impact Audit use?

Codexhost Update Impact Audit is published under the LGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codexhost Update Impact Audit use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codexhost Update Impact Audit?

Skills that share tags, products or a category with Codexhost Update Impact Audit: Svelte Core Best Practices (rilldata/rill, 2.9k stars), Dify Component Writing Guide (langgenius/dify, 158k stars), React State Management (involvex/youtube-music-cli, 456 stars) and Pierre Theming Library (pierrecomputer/pierre, 6.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codexhost Update Impact Audit?

BytePioneer-AI (a GitHub user) maintains it in BytePioneer-AI/codex-host, which has 2,791 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 9, 2026.

Source: BytePioneer-AI/codex-host on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.