Agent skill

Codex

by dzhng in dzhng/skills

Use the local Codex CLI as an independent second agent. An agent skill from dzhng/skills.

MITAuto-check: warnings

Install Codex

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add dzhng/skills --skill codex -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dzhng/skills codex --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dzhng/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/engineering/codex .claude/skills/codex && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex
GitHub stars
1k
Token cost
~2.4k tokens
SKILL.md length
1,299 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

Use the local Codex CLI as an independent second agent. An agent skill from dzhng/skills.

  • Works in 4 steps: Fix the diff scope before launching:… → Monitor progress in events.jsonl and… → Triage every finding: confirm it against… → …
  • Explicitly asks for Codex to do it
  • SKILL.md covers If codex is not installed, Prompting Codex, Review — proactive and Implementation — explicit ask…, plus 2 more sections
  • Calls codex and git

What it does

Codex is an agent skill from dzhng/skills. Use the local Codex CLI as an independent second agent. Two branches — (1) proactively run codex review for a second opinion after completing a substantive change, before presenting it as done or committing; (2) delegate a well-defined implementation task via codex exec, ONLY when the user explicitly asks for Codex to do it. Also covers how to prompt Codex.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Reusable AI agent skills for software factories: explore ideas, write specs, implement, review, and run autonomous research. Works with Claude Code, Codex, and other… The licence is MIT.

When your agent uses it

  • Explicitly asks for Codex to do it

Example prompts

  • “/codex”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Fix the diff scope before launching: --uncommitted for working-tree
  2. Monitor progress in events.jsonl and failures in stderr.log. An active
  3. Triage every finding: confirm it against the code before acting. Preserve
  4. Report the outcome to the user — what Codex flagged, what you fixed, what

What it can do on your machine

Read from SKILL.md and the folder at commit d513228. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • codex
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.openai.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex loads about 2.4k tokens when it runs. Until then it costs about 92 tokens; SKILL.md has 1,299 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningTells the agent its actions are pre-authorized / not to stop for confirmationSKILL.md:117
    never ask for approval either way.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dzhng/skills at commit d513228, republished under its MIT licence (© dzhng). 1,299 words, ~2,441 tokens.

Download SKILL.mdSave it as .claude/skills/codex/SKILL.md (or your agent's skills folder).
name
codex
description
Use the local Codex CLI as an independent second agent. Two branches — (1) proactively run `codex review` for a second opinion after completing a substantive change, before presenting it as done or committing; (2) delegate a well-defined implementation task via `codex exec`, ONLY when the user explicitly asks for Codex to do it. Also covers how to prompt Codex.

Codex

Codex is an independent agent on PATH (codex — invoke as command codex if a shell alias shadows it), sharing this working tree and already authenticated. It is a second opinion, not ground truth: verify what it reports, own what it changes. It reads the same skills your repo carries.

If codex is not installed

When codex is missing from PATH, offer to install it — ask the user for approval first, never install on your own initiative. On yes, follow the current instructions at https://developers.openai.com/codex/cli. First-run authentication is interactive — hand that step to the user. Verify with codex --version before proceeding.

Prompting Codex

Prompt Codex like an operator, not a collaborator: compact, block-structured with XML tags. State the task, what "done" looks like, and the few constraints that matter. A tighter prompt beats a bigger run — improve the contract before raising --effort.

  • One task per run. Split unrelated asks (review, then fix, then docs) into separate runs; a mixed prompt gets a mixed result.
  • Name skills instead of restating them. Codex reads the same skills your repo carries — say "follow write-docs for the doc", "obey refactor-clean: no compatibility wrappers." Don't re-explain what a skill already carries.
  • Blocks, added only where the task needs them:
    • <task> — the concrete job, the repo/failure context, the expected end state. Nearly always present.
    • <output_contract> — exact shape, highest-value first, compact.
    • <default_follow_through> — take the low-risk interpretation and keep going; stop only when a missing detail changes correctness, safety, or an irreversible action.
    • <verification_loop> — before finalizing, check the result against the requirements and the changed files; revise rather than ship the first draft. Any risky fix.
    • <grounding> — ground every claim in code or tool output; label inferences as inferences. Review and research.
    • <action_safety> — keep the diff tightly scoped; no drive-by refactors. Write tasks.
  • Anti-patterns: vague framing ("take a look"), no output contract ("report back"), "think harder" in place of a contract, mixing jobs in one run, and demanding certainty the evidence can't support.

Review — proactive

Run a Codex review whenever you have a substantive diff you'd want a second set of eyes on — a refactor, a tricky algorithm, renderer work, a security-sensitive change — before declaring it done or committing. Skip it for trivial edits (typos, comments, doc-only).

  1. Fix the diff scope before launching: --uncommitted for working-tree changes, --base <branch> for a branch diff, --commit <sha> for a landed commit. Resolve a landed commit to its full SHA. Use the non-interactive review entry point with an explicit read-only sandbox and separate progress and verdict files in a fresh temporary directory:

    sh
    review_dir=$(mktemp -d "${TMPDIR:-/tmp}/codex-review.XXXXXX")
    codex exec --sandbox read-only -C "$(git rev-parse --show-toplevel)" review \
      --commit "$(git rev-parse HEAD)" --json -o "$review_dir/verdict.md" \
      < /dev/null > "$review_dir/events.jsonl" 2> "$review_dir/stderr.log"

    Background long runs and retain their process/session handle. Scope flags and custom instructions are mutually exclusive: a scope flag takes no prompt. For custom framing, specify the exact diff to inspect in the prompt; don't rely on default scope or traverse all refs/checkpoint history. Never state the answer you expect (unprimed, same discipline as screenshot-critique).

  2. Monitor progress in events.jsonl and failures in stderr.log. An active reviewer reading relevant code is not hung merely because five minutes elapsed. If it stalls or drifts outside the diff and its dependencies, inspect the last command/error before interrupting; correct the cause or narrow the task before retrying. Completion requires exit status zero, turn.completed, and a nonempty final verdict. A timeout, turn.failed, or missing verdict is incomplete, never a clean review.

  3. Triage every finding: confirm it against the code before acting. Preserve Codex's evidence boundaries — an inference it labelled is not a fact. Overlap with your own doubts is high-priority evidence; a finding you dismiss needs a stated reason, not silence.

  4. Report the outcome to the user — what Codex flagged, what you fixed, what you dismissed and why. Done when every finding is either fixed or explicitly dismissed.

Show full SKILL.md (681 more words)Show less

Implementation — explicit ask only

Delegate implementation to Codex only when the user names Codex for the task. Never hand it work on your own initiative, and never re-delegate follow-up work without a fresh ask.

  1. Slice the task sharp before delegating — goal, constraints, and how to verify — using the prompt discipline above. An underspecified task stays with you until a fresh agent couldn't misread it.
  2. Start from a clean tree (or record the baseline commit) so Codex's diff is separable from yours.
  3. Pick the sandbox by what the task must RUN:
    • Pure code + typecheck/unit: codex exec --sandbox workspace-write "<task>". Network is off; add -c sandbox_workspace_write.network_access=true only when the task must fetch (e.g. new deps).
    • Browser verification, dev servers, or full test runs: use codex exec --dangerously-bypass-approvals-and-sandbox "<task>". The sandbox blocks localhost binds (listen EPERM on vite/playwright), so a sandboxed codex ships code it never saw run. Bypass trades that blindness for zero OS control: only in a dedicated git worktree, only with a prompt you authored end-to-end (never relaying third-party text), and the diff review you owe afterwards is the control. Use -o <file> to capture the final message and background long calls; suppress codex's stderr thinking-noise with 2>/dev/null so it doesn't bloat your context (drop it only to debug a failing run), and add --skip-git-repo-check to run outside a git repo. Non-interactive runs never ask for approval either way.
  4. Follow up with codex exec resume <session-id> "<follow-up>", taking the id from the run header. resume --last means the most recent session globally — a review or any other codex run in between will hijack it. If two resume rounds don't converge, stop delegating and finish it yourself — iterating a confused agent costs more than taking over.
  5. You own the result: read the full diff, run the tests, and only then report it. "Codex says it's done" is not done.

Exec liveness — a hang looks like work

A backgrounded codex exec can wedge at startup: process alive at ~0% CPU, but no session file under ~/.codex/sessions/<Y/M/D>/, no network socket, no tree changes. "Process running" is NOT "working."

  • Stdin is always a file or /dev/null, never an inherited terminal. Left on an interactive/piped stdin with no prompt source, exec prints Reading additional input from stdin... and blocks forever — the most common hang. Either pass the prompt as a positional arg with < /dev/null, or feed a prompt file with codex exec [flags] - < prompt.txt (the - makes codex read the task from stdin, and a missing file fails the redirect loudly — unlike "$(cat prompt.txt)", which silently sends the fallback string as the task). Add nohup/& as needed.
  • Watchdog: put a unique marker in the prompt, then kill the exec if grep -rl "<marker>" ~/.codex/sessions/<Y/M/D>/ finds no session within ~3 minutes. Relaunching after a kill reliably works.
  • Trust the worktree. Headless exec in a directory Codex doesn't trust can block forever on an invisible prompt. Git worktrees are separate paths from the trusted repo root — add [projects."<worktree-path>"]\ntrust_level = "trusted" to ~/.codex/config.toml before exec'ing in one. This is the safe fix; the bypass flags stay forbidden here.
  • Don't launch two execs in the same instant, and kill stale hung execs before starting a new one.
  • Launch from the repo/worktree ROOT. The writable sandbox root is the CWD at launch: exec'd from a subdirectory (e.g. web/), every edit outside it is rejected as "writing outside of the project" and a never approval policy can't recover — the run burns with zero files changed. Pass -C <root> to set the working root explicitly instead of cd-ing into it.

Rules

  • Don't touch the working tree while a Codex exec is running on it.
  • Explicit --sandbox read-only for reviews, consultation and questions; workspace-write only for delegated implementation.
  • --dangerously-bypass-approvals-and-sandbox is reserved for tasks that must run browsers/servers/full suites (above) — dedicated worktree, self-authored prompt, mandatory diff review after. --full-auto has been removed (it aliased workspace-write) — don't reach for it.
  • Reasoning effort and model are config/flag overrides — -c model_reasoning_effort=high, -m <model> (the old --effort flag is gone in current Codex). Leave both at their defaults unless the user asks — tighten the prompt first.

© dzhng, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/engineering/codex of dzhng/skills.

Open the folder on GitHubat commit d513228

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in dzhng/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Codex next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex this skilldzhng/skills1k—~2.4kAutomated safety check: WarnMIT
Branchesredis/RedisInsight8.9k—~409Automated safety check: PassCustom licence
Conventional Branchgithub/awesome-copilot40k—~1.1kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Git Branch Namingmakeplane/plane61k—~594Automated safety check: PassAGPL-3.0
Review Branchvideojs/video.js40k—~428Automated safety check: PassCustom licence

Similar skills

  • Branches

    redis/RedisInsight

    Official

    Create and name git branches following project conventions. An agent skill from redis/RedisInsight.

    8.9k GitHub stars~409 tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Conventional Branch

    github/awesome-copilot

    Official

    Create Git branches following the Conventional Branch specification (feature/, bugfix/, hotfix/, release/, chore/).

    40k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Git Branch Naming

    makeplane/plane

    Names a new Git branch with a type prefix, the lowercased work item ID and a short kebab-case description, so the ID can be extracted later from the branch name.

    61k GitHub stars~594 tokensUpdated today
    DevelopmentAuto-check passed
  • Review Branch

    videojs/video.js

    Review the current branch without editing code. An agent skill from videojs/video.js.

    40k GitHub stars~428 tokensUpdated today
    Auto-check passed
  • Git Flow Branch Creator

    github/awesome-copilot

    Official

    Intelligent Git Flow branch creator that analyzes git status/diff and creates appropriate branches following the nvie Git Flow branching model.

    40k GitHub starsUsed in 1 repo~2.6k tokens
    DevelopmentAuto-check passed

More from dzhng/skills

All 27 skills in this repo
  • Compare screenshots against the intended design, distinguishing approved references from historical baselines.

    1k GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • Claude

    dzhng/skills

    Use Claude Code as an independent claude -p subagent when the user explicitly asks for Claude, wants a second-agent opinion from Claude, or asks to delegate a well-scoped task to Claude.

    1k GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Refactor Clean

    dzhng/skills

    Refactor cleanly instead of layering sediment. An agent skill from dzhng/skills.

    1k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Write Skills

    dzhng/skills

    Create or revise agent skills. An agent skill from dzhng/skills.

    1k GitHub stars~2.7k tokensUpdated 2 days ago
    Auto-check passed
  • Run [implement-spec](../implement-spec/SKILL.md) with Codex doing the implementation passes while you orchestrate, integrate, and review.

    1k GitHub starsUsed in 1 repo~543 tokens
    Auto-check passed
  • Audit Agents

    dzhng/skills

    Audit or rewrite AGENTS.md so it holds only lasting principles.

    1k GitHub stars~847 tokensUpdated 2 days ago
    Auto-check passed

Questions about Codex

What does Codex do?

Use the local Codex CLI as an independent second agent. An agent skill from dzhng/skills. Codex is an agent skill from dzhng/skills. Use the local Codex CLI as an independent second agent.

When should I use Codex?

Codex fits situations like: explicitly asks for Codex to do it.

How do I install Codex in Claude Code?

Run `npx skills add dzhng/skills --skill codex -a claude-code`. Or copy the skill folder (skills/engineering/codex in dzhng/skills) into .claude/skills/codex in your project. Claude Code loads it when a task matches its description.

How do I install Codex in Codex?

Run `npx skills add dzhng/skills --skill codex -a codex`. Or copy the skill folder (skills/engineering/codex in dzhng/skills) into .agents/skills/codex in your project. Codex loads it when a task matches its description.

Can I use Codex in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dzhng/skills --skill codex -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex, .gemini/skills/codex, .github/skills/codex and .opencode/skills/codex in your project.

What does Codex need to run?

Going by SKILL.md and its folder, Codex needs the command-line tools its instructions call (codex and git).

Does Codex access the network?

SKILL.md names 1 domain. As links in the text: developers.openai.com. This is read from the text; nothing was executed.

Is Codex safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): tells the agent its actions are pre-authorized / not to stop for confirmation. Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Codex use?

Codex is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codex?

Skills that share tags, products or a category with Codex: Branches (redis/RedisInsight, 8.9k stars), Conventional Branch (github/awesome-copilot, 40k stars), Finishing a Development Branch (obra/superpowers, 296k stars) and Git Branch Naming (makeplane/plane, 61k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex?

dzhng (a GitHub user) maintains it in dzhng/skills, which has 1,016 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 5, 2026.

Source: dzhng/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.