Agent skill

OpenCodex Proxy Operations

by lidge-jun in lidge-jun/opencodex

Operates an opencodex (`ocx`) proxy: finds CLI tasks offline, checks local configuration, and manages accounts, providers, models, routing and usage reports.

MITAuto-check passedAI & LLM Engineering

Install OpenCodex Proxy Operations

skills CLI
$ npx skills add lidge-jun/opencodex --skill ocx -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install lidge-jun/opencodex ocx --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/lidge-jun/opencodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ocx .claude/skills/ocx && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ocx
GitHub stars
17k
Token cost
~3.1k tokens
SKILL.md length
1,411 words
Files
14 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Operates an opencodex (`ocx`) proxy: finds CLI tasks offline, checks local configuration, and manages accounts, providers, models, routing and usage reports.

  • Works in 3 steps: ocx ready --json checks readiness… → ocx status --json checks the target and… → Run the task with --json only when that…
  • Checking whether a running opencodex proxy is healthy and ready
  • SKILL.md covers Find the task offline, Choose a workflow, Before live management work and Observation and explicit-key…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

This skill is for running a proxy, not for changing the opencodex source; installation and operating consent live in `AGENTS_INSTALL.md` and code changes in the repository's `AGENTS.md`. It stresses that coverage differs per task: provider edits, account selection, model visibility, routing reads, client integration controls and diagnostics each have their own transports and limits, so a shared API prefix does not mean every dashboard action has a CLI equivalent.

The agent starts offline with `ocx help`, narrowing from the root to a model family and then a specific leaf, and reads only the matching chapter among the reference files. An optional `ocx capabilities` lookup with `--json` checks whether the installed CLI declares a given API route; exit code 4 means no declaration matched. Workflows are chosen from a table by task domain, beginning with a named read or preview such as `ocx status --json` for lifecycle questions, and a listed write still needs authority for that task. The references cover accounts, routing, providers and models, remote access, JSON shapes, recipes, failure semantics and the remote hub.

When your agent uses it

  • Checking whether a running opencodex proxy is healthy and ready
  • Adding or switching providers and accounts on the proxy
  • Finding which `ocx` command covers a management task
  • Reading routing, model and usage reports from the proxy

Example prompts

  • “Check the status of my opencodex proxy and tell me if anything is unreachable.”
  • “Which ocx command shows model visibility for each provider?”
  • “Show me the usage report from the proxy.”
  • “Help me work out why the management API is unreachable.”

Requirements

  • The `ocx` CLI from opencodex
  • A running proxy for live management tasks; help works offline

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. ocx ready --json checks readiness (ready, pending, failed, unreachable).
  2. ocx status --json checks the target and versionSkew.relation. unknown is
  3. Run the task with --json only when that leaf supports it. ocx doctor

What it can do on your machine

Read from SKILL.md and the folder at commit 250f17a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

OpenCodex Proxy Operations loads about 3.1k tokens when it runs, and up to ~104k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 1,411 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~104k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from lidge-jun/opencodex at commit 250f17a, republished under its MIT licence (© lidge-jun). 1,411 words, ~3,113 tokens.

Download SKILL.mdSave it as .claude/skills/ocx/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
ocx
description
Operate opencodex (`ocx`): discover CLI tasks offline, inspect local configuration, and manage a running proxy’s account pool, providers, models, routing, usage report, and management API. Use for proxy operation rather than editing the opencodex codebase.

Operating ocx

ocx supports local configuration and named live management workflows. Coverage is per task: provider edits, account selection, model visibility, routing reads, client integration controls and diagnostics have different transports and limits. A shared API prefix does not prove that every dashboard action has a CLI equivalent.

This skill is for operating a proxy. AGENTS_INSTALL.md covers installation and operating consent; the repository AGENTS.md covers code changes.

Find the task offline

Start at the smallest useful level; no running proxy is needed for help:

bash
ocx help                         # compact root
ocx help models                  # family and declared children
ocx help models preset show      # exact leaf, when declared
ocx help --all                   # full top-level reference, when needed

Then read only the matching task chapter. For example, use providers/models for catalog work or Lab for local evidence. Use ocx help <family> <leaf> or appended --help, not a trailing bare help after nested operands. Missing detail can fall back to family help; it is not proof that a runtime operation is absent.

For a route you already know, an optional lookup is:

bash
ocx capabilities --route '/api/providers/{provider}/model-costs' --json

This matches the declared path template, not a concrete provider URL or HTTP method. Exit 4 means no declaration matched. Full ocx capabilities --json and --mutating-only --json are useful for broad inventories, not mandatory preflight. Declarations describe the installed CLI; actual handlers remain the grammar authority.

Choose a workflow

Start with the named read or preview, then follow its recipe. Help is offline; the target column describes execution. A listed write still needs authority for that task, and read-oriented probes can contact upstream services.

Task domainStartExecution targetVerify the result
Lifecycleocx status --jsonLocal runtimeCompare readiness, runtime identity and version; diagnosis
Providers and modelsocx provider snapshot --jsonLive management; local authoring is separateRead saved state and catalog disposition; provider edits, model identities
Accountsocx account list --jsonLive managementRead active/selected state; quota is opt-in and can probe upstream; pool policy, per-key quota
Agents and routingocx route policy list --jsonLive management; v2 distinguishes local and liveInspect revision, saved overrides and apply outcome; routing edits, runtime settings
Integrationsocx help integrationSelected runtime and its client filesPreview before applying; inspect refusals and ownership; file integrations
Observation and maintenanceocx logs filter --helpLive management; connected usage is self-scopedRetain window, filter and incomplete/partial facts; filtered reads, companion totals
Access and remoteocx connect status --jsonLocal connection; management runs on its serving hostSeparate connection health, key scope and revocation; remote targeting, private key handoff
Labocx help labLocal evidence; explicit probes and automation have effectsInspect evidence and export/probe limits; Lab workflow

These are task entry points, not a count of GUI parity. Native window focus, browser presentation and session-only actions retain their own interfaces. Grant inspection does not authorize grant consumption; persisted local Desktop export does not export an unsaved dashboard draft.

Before live management work

  1. ocx ready --json checks readiness (ready, pending, failed, unreachable).
  2. ocx status --json checks the target and versionSkew.relation. unknown is not a confirmed match; a mismatch needs the intended installation resolved.
  3. Run the task with --json only when that leaf supports it. ocx doctor rejects it; ocx v2 supports JSON for both local and explicit live targets.

These checks do not require starting a proxy for offline help, local provider configuration, config validation or local Lab inspection. On a connected client, ordinary management commands do not automatically target the hub: perform them on the hub or use its dashboard. See remote targeting.

Inspect both the exit code and receipt. Saved config, runtime application, client file convergence, skipped work and partial completion are different outcomes; read back the relevant setting after a write. Exit 0 also covers previews and intentional no-ops. Management failures normally print stderr prose even with --json; usage codes include 2 and legacy 64 exceptions for capabilities, ready, and resolve. See JSON shapes and failure semantics before scripting recovery.

Observation and explicit-key API tasks

For request/injection follow, timeline exclusions and scoped usage, start with observation recipes. Use versioned log events to reconstruct observed windows; row JSONL cannot express removals. Neither stream guarantees lossless traffic history.

Selected-key model/audio tasks are separate from management calls. They require explicit operator authorization for upstream calls/uploads and a private human terminal handoff for key input. Never collect the key in this agent session, argv or environment, and never substitute an admin/enrolled credential. Read the selected-key and audio recipe before proposing one. Reports are observations, not key-scope/billing certificates.

Do not star the repository on the user's behalf. ocx inspect star reads the status, and that is the entire CLI surface for it. The starring POST requires a dashboard session, so an ordinary admin-token management call cannot perform it. That is not a barrier against a determined local agent; the consent rule still binds every mechanism because it spends their GitHub identity. Do not route around it with gh, a direct HTTP call, or a minted session. If starring would be useful, say so and let the user decide.

The same boundary covers the session-gated /api/codex-prompt writes: read them with ocx inspect codex-prompt, and leave the writes to the dashboard.

Show full SKILL.md (572 more words)Show less

Secret-bearing commands

Do not create an access key or start an access-key rotation from an agent session. This covers the create and rotation-start operations under ocx access key, ocx access keys, and ocx api-key, their opencodex equivalents and executable wrappers, and direct POST requests to /api/keys and /api/keys/rotate. Both text and JSON responses contain a one-time plaintext data-plane credential, which can enter the agent transcript. Ask the user to perform that step in a human-operated terminal outside the agent session, configure and verify the replacement, and report only confirmation plus non-secret key/rotation IDs. Never ask for the plaintext key in chat or offer a pipe, redirection, or API workaround to perform the secret-returning step inside the agent session.

ocx hub invite has the same boundary: text and JSON output expose a plaintext pairing grant or a command embedding it. Use the human-operated terminal handoff in recipe 10; never ask for the grant or generated command in chat. Continue non-secret setup and verification normally.

Configuration confirmation is not approval to revoke the existing credential. Identify the existing key ID and obtain separate explicit revocation approval before committing an in-place rotation or removing an old, separately replaced key. An existing explicit approval for that exact revocation remains valid; setup confirmation alone does not supply it. Commit and abort return no plaintext key, but still require authority for their state changes. Follow recipe 5.

Destructive verbs

storage trash restore and storage policy run refuse without --yes (exit 2, nothing sent). storage cleanup without --yes is a preview that exits 0 having mutated nothing — do not treat that 0 as a delete. There is no interactive prompt.

The expected sequence is preview, report, then ask:

bash
ocx storage cleanup --percent 25 --json      # previews; deletes nothing; exits 0

Report the count and bytes from that output and get explicit approval before adding --yes. --mode quarantine (the default) can be undone with storage trash restore; --mode permanent cannot.

Remote hub

Read ocx status on the hub and ocx connect status --json on the client before changing their configuration. Pairing is not required to configure the hub. The optional loopback companion serves inference only, never management calls. A human transfers the invite directly to the joining machine outside this session. Remote credential inputs remain stdin-only (--pairing-code-stdin, --admin-token-stdin), never literal argv or environment values.

Disconnect restores local state but leaves the hub key valid. With explicit revocation authority, revoke while still connected, or have the operator revoke on the hub after disconnection. Do not work around ownership or partial-restore refusals. Remote hub covers the one-port setup, credential handoff, managed rotation and disconnection order.

References

FileUse it for
Management indexdeclared capabilities in eight task chapters, with routes, flags and mutation notes (generated)
JSON shapesresponse envelopes and error shapes
Recipescopy-paste sequences for real tasks
Failure semanticsexit codes, 503 classes, what to retry
Remote hubhub/client roles, when pairing is and is not needed, key rotation, disconnection

The generated index routes to eight task chapters. Lab includes local reads, public evidence operations and explicit automation controls; it is not read-only. Read-oriented probes can contact providers, consume quota or refresh caches. Routing-profile writes use explicit file/revision workflows; discovered-model display-name edits use raw upstream IDs, distinct from custom-model editing. Browser presentation and session-only consent actions remain outside agent management authority.

The index and chapters are generated by scripts/generate-ocx-skill-surface.ts. If metadata and execution disagree, check the installed CLI version and the live target before reporting unsupported behavior; do not infer a new flag.

© lidge-jun, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (references) in skills/ocx of lidge-jun/opencodex.

  • SKILL.md
  • references/01_management_surface.md
  • references/01_surface_access-remote.md
  • references/01_surface_accounts.md
  • references/01_surface_agents-routing.md
  • references/01_surface_integrations.md
  • references/01_surface_lab.md
  • references/01_surface_lifecycle.md
  • references/01_surface_observe-system.md
  • references/01_surface_providers-models.md
  • references/02_json_shapes.md
  • references/03_recipes.md
  • references/04_failure_semantics.md
  • references/05_remote_hub.md

Open the folder on GitHubat commit 250f17a

Compare with similar skills

OpenCodex Proxy Operations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

OpenCodex Proxy Operations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
OpenCodex Proxy Operations this skilllidge-jun/opencodex17k—~3.1kAutomated safety check: PassMIT
9Router AI Gateway Setupdecolua/9router30k—~744Automated safety check: PassMIT
9Router Chat Completionsdecolua/9router30k—~635Automated safety check: PassMIT
Pinme LLMglitternetwork/pinme3.7k1 repos~2.8kAutomated safety check: PassMIT
Using Ccproxy Inspectorstarbaser/ccproxy350—~2.7kAutomated safety check: PassCustom licence
OmniRoute Providers CLIdiegosouzapw/OmniRoute74k1 repos~2.2kAutomated safety check: PassMIT

Similar skills

  • Sets up access to the 9Router AI gateway, an OpenAI-compatible REST endpoint for chat, images, speech, embeddings, web search and web fetch, and indexes its capability skills.

    30k GitHub stars~744 tokensUpdated 7 days ago
    AI & LLM EngineeringAuto-check passed
  • Sends chat and code-generation requests through a 9Router gateway using OpenAI or Anthropic message formats, with streaming and auto-fallback combos.

    30k GitHub stars~635 tokensUpdated 7 days ago
    AI & LLM EngineeringAuto-check passed
  • Pinme LLM

    glitternetwork/pinme

    A skill your agent uses when a PinMe project (Worker TypeScript) needs to call OpenRouter-backed LLM APIs, including models, chat/completions, streaming, or OpenRouter web search.

    3.7k GitHub starsUsed in 1 repo~2.8k tokens
    AI & LLM EngineeringAuto-check passed
  • Using Ccproxy Inspector

    starbaser/ccproxy

    Operates the ccproxy inspector MITM system for intercepting, inspecting, and transforming LLM API traffic.

    350 GitHub stars~2.7k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • OmniRoute Providers CLI

    diegosouzapw/OmniRoute

    Command reference for managing provider connections in the omniroute gateway: browse the catalog, test and validate connections, rotate API keys and read per-provider metrics.

    74k GitHub starsUsed in 1 repo~2.2k tokens
    AI & LLM EngineeringAuto-check passed
  • Using Ccproxy API

    starbaser/ccproxy

    Guides users through ccproxy as an OpenAI-compatible and Anthropic-compatible LLM API server with SDK integration, OAuth authentication, sentinel key substitution, model routing, and troubleshooting.

    350 GitHub stars~4k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed

Questions about OpenCodex Proxy Operations

What does OpenCodex Proxy Operations do?

Operates an opencodex (`ocx`) proxy: finds CLI tasks offline, checks local configuration, and manages accounts, providers, models, routing and usage reports. md`. It stresses that coverage differs per task: provider edits, account selection, model visibility, routing reads, client integration controls and diagnostics each have their own transports and limits, so a shared API prefix does not mean every dashboard action has a CLI equivalent.

When should I use OpenCodex Proxy Operations?

OpenCodex Proxy Operations fits situations like: checking whether a running opencodex proxy is healthy and ready; adding or switching providers and accounts on the proxy; finding which `ocx` command covers a management task; reading routing, model and usage reports from the proxy.

How do I install OpenCodex Proxy Operations in Claude Code?

Run `npx skills add lidge-jun/opencodex --skill ocx -a claude-code`. Or copy the skill folder (skills/ocx in lidge-jun/opencodex) into .claude/skills/ocx in your project. Claude Code loads it when a task matches its description.

How do I install OpenCodex Proxy Operations in Codex?

Run `npx skills add lidge-jun/opencodex --skill ocx -a codex`. Or copy the skill folder (skills/ocx in lidge-jun/opencodex) into .agents/skills/ocx in your project. Codex loads it when a task matches its description.

Can I use OpenCodex Proxy Operations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lidge-jun/opencodex --skill ocx -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ocx, .gemini/skills/ocx, .github/skills/ocx and .opencode/skills/ocx in your project.

What does OpenCodex Proxy Operations need to run?

SKILL.md names no scripts, command-line tools or credentials: OpenCodex Proxy Operations is instructions for the agent only. Our summary lists: The `ocx` CLI from opencodex; A running proxy for live management tasks; help works offline.

Does OpenCodex Proxy Operations access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is OpenCodex Proxy Operations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does OpenCodex Proxy Operations use?

OpenCodex Proxy Operations is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does OpenCodex Proxy Operations use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 100k tokens, read only when the agent opens those files.

What are the alternatives to OpenCodex Proxy Operations?

Skills that share tags, products or a category with OpenCodex Proxy Operations: 9Router AI Gateway Setup (decolua/9router, 30k stars), 9Router Chat Completions (decolua/9router, 30k stars), Pinme LLM (glitternetwork/pinme, 3.7k stars) and Using Ccproxy Inspector (starbaser/ccproxy, 350 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains OpenCodex Proxy Operations?

lidge-jun (a GitHub user) maintains it in lidge-jun/opencodex, which has 17,083 GitHub stars. The repository was last updated on October 8, 2026.

Source: lidge-jun/opencodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.