Agent skill

Codex Log Guard

by majiayu000 in majiayu000/spellbook

Diagnose excessive Codex local SQLite diagnostic log writes with read-only evidence by default.

MITAuto-check passedDatabases

Install Codex Log Guard

skills CLI
$ npx skills add majiayu000/spellbook --skill codex-log-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install majiayu000/spellbook codex-log-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/majiayu000/spellbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codex-log-guard .claude/skills/codex-log-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex-log-guard
GitHub stars
287
Token cost
~2.3k tokens
SKILL.md length
1,010 words
Files
2
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Diagnose excessive Codex local SQLite diagnostic log writes with read-only evidence by default.

  • Works in 8 steps: Inspect all candidate live database… → Identify which candidate database is… → Check whether block_log_inserts already… → …
  • A user mentions logs2.sqlite
  • SKILL.md covers Overview, Operating Contract, Default Flow and Evidence Commands, plus 4 more sections
  • Calls sqlite3

What it does

Codex Log Guard is an agent skill from majiayu000/spellbook. Diagnose excessive Codex local SQLite diagnostic log writes with read-only evidence by default. Use when a user mentions logs2.sqlite, logs2.sqlite-wal, blockloginserts, SSD/TBW wear, or explicitly asks to protect, clean up, verify, or restore Codex diagnostic logging.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Databases. It works with SQLite. The repository describes itself as: Cross-runtime skills for Claude Code, Codex, and multi-agent workflows. The licence is MIT.

When your agent uses it

  • A user mentions logs2.sqlite
  • Logs2.sqlite-wal
  • Blockloginserts
  • Explicitly asks to protect

Example prompts

  • “/codex-log-guard”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Inspect all candidate live database files and schemas
  2. Identify which candidate database is currently held by Codex processes.
  3. Check whether block_log_inserts already exists on each candidate with a logs table.
  4. Measure whether logs is still being written using COUNT(*), MIN(id), MAX(id) samples.
  5. Inspect low-level log volume with TRACE/DEBUG counts and top noisy targets.
  6. Check which Codex processes currently hold each candidate database.
  7. Return a diagnosis with
  8. Do not ask the user which command to run. Choose the diagnosis path from the evidence.

What it can do on your machine

Read from SKILL.md and the folder at commit ed52af7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • sqlite3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex Log Guard loads about 2.3k tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 1,010 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from majiayu000/spellbook at commit ed52af7, republished under its MIT licence (© majiayu000). 1,010 words, ~2,299 tokens.

Download SKILL.mdSave it as .claude/skills/codex-log-guard/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
codex-log-guard
description
Diagnose excessive Codex local SQLite diagnostic log writes with read-only evidence by default. Use when a user mentions logs_2.sqlite, logs_2.sqlite-wal, block_log_inserts, SSD/TBW wear, or explicitly asks to protect, clean up, verify, or restore Codex diagnostic logging.

Codex Log Guard

Overview

Diagnose Codex persistent diagnostic logging from local evidence, then give a concise conclusion and the safest next action. Do not make the user choose from a command menu.

Operating Contract

Select one mode from the current user request:

  • diagnose_only is the default for check, inspect, explain, or verify requests. It is read-only.
  • protect requires an explicit request to stop or mitigate log writes. It may install and verify block_log_inserts, but it does not delete rows or vacuum files.
  • cleanup requires an explicit current request to reclaim disk space or clean up logs. It first installs protection when needed, creates and verifies a timestamped backup, and only then deletes log rows and vacuums.
  • restore requires an explicit request to resume diagnostic logging. It may drop only the known block_log_inserts trigger.

Generic wording such as "处理", "修一下", or "止血" selects protect, not cleanup. Prior approval does not carry into a later run. If the requested write mode is ambiguous, return the diagnose_only report and the exact proposed mutation without applying it.

Direct actions:

  • Run local read-only file, SQLite schema, row, and open-process checks.
  • Apply only the mutation authorized by the selected mode and verify its result.

Escalate before:

  • Touching any database outside the two declared Codex log paths, deleting a backup, killing a process, or changing remote telemetry or credentials.

Evidence-backed pushback:

  • Reject cleanup when protection is unverified, the backup check failed, or sampled row IDs still move. Cite the exact database path and failed command instead of treating file size as proof.

Feedback loop:

  • When a new schema, active path, or false-success signal is confirmed more than once, update this Skill's diagnosis rules and a focused contract test before automating that case.

agents/openai.yaml contains discovery UI metadata only; it is not an operational instruction source.

Default Flow

When the user asks to "check", "看看", "诊断", or asks whether the local machine is affected:

  1. Inspect all candidate live database files and schemas:
    • ~/.codex/logs_2.sqlite
    • ~/.codex/sqlite/logs_2.sqlite
  2. Identify which candidate database is currently held by Codex processes.
  3. Check whether block_log_inserts already exists on each candidate with a logs table.
  4. Measure whether logs is still being written using COUNT(*), MIN(id), MAX(id) samples. Treat MAX(id) or MIN(id) movement with stable COUNT(*) as active churn, not necessarily disk growth.
  5. Inspect low-level log volume with TRACE/DEBUG counts and top noisy targets.
  6. Check which Codex processes currently hold each candidate database.
  7. Return a diagnosis with:
    • current state: healthy / protected / affected historically / actively writing / actively growing on disk / missing database / blocked
    • evidence: file sizes, trigger state, row/min-id/max-id samples, level distribution, active path
    • recommended next action: do nothing / install trigger / cleanup later / cleanup now / restore logging
  8. Do not ask the user which command to run. Choose the diagnosis path from the evidence.

In protect mode:

  1. Install block_log_inserts first.
  2. Verify that COUNT(*), MAX(id) stops growing.
  3. Report the protected database path and fresh samples. Do not delete or vacuum rows.

In cleanup mode:

  1. Complete and verify protection first.
  2. Create a timestamped SQLite .backup and require a non-empty file plus a successful PRAGMA quick_check result.
  3. Delete log rows, vacuum, and checkpoint the WAL.
  4. Report the backup path and final file sizes.

In restore mode:

  1. Drop block_log_inserts.
  2. Sample COUNT(*), MAX(id) to confirm logging resumes or stays quiet.

Evidence Commands

Run direct shell/SQLite commands. Use only the needed subset for the user's request; do not paste a menu back to the user.

Inspect files:

bash
for db in ~/.codex/logs_2.sqlite ~/.codex/sqlite/logs_2.sqlite; do
  ls -lh "$db"* 2>/dev/null
  du -h "$db"* 2>/dev/null
done

After lsof identifies the active candidate, validate the selected path in the same shell command before running any later SQLite snippet:

bash
: "${CODEX_LOG_DB:?set CODEX_LOG_DB to the verified active candidate}"
case "$CODEX_LOG_DB" in
  "$HOME/.codex/logs_2.sqlite"|"$HOME/.codex/sqlite/logs_2.sqlite") ;;
  *) echo "refusing unexpected Codex log database path" >&2; exit 2 ;;
esac
readonly db="$CODEX_LOG_DB"

Do not supply a default. If no active path can be proven, stay in diagnose_only and report the ambiguity.

Check schema and trigger:

bash
sqlite3 "$db" ".tables"
sqlite3 "$db" "PRAGMA table_info(logs);"
sqlite3 "$db" "SELECT name, tbl_name, sql FROM sqlite_master WHERE type='trigger' AND name='block_log_inserts';"

Sample writes and growth:

bash
for i in 1 2 3; do
  date '+%F %T'
  sqlite3 "$db" "SELECT COUNT(*) AS rows, MIN(id) AS min_id, MAX(id) AS max_id FROM logs;"
  stat -f '%N %z bytes mtime=%Sm' "$db" "$db-wal" "$db-shm" 2>/dev/null
  sleep 10
done

Inspect levels and noisy targets:

bash
sqlite3 "$db" "SELECT level, COUNT(*) AS n, ROUND(SUM(estimated_bytes)/1024.0/1024.0, 1) AS estimated_mib FROM logs GROUP BY level ORDER BY n DESC;"
sqlite3 "$db" "SELECT target, level, COUNT(*) AS n, ROUND(SUM(estimated_bytes)/1024.0/1024.0, 1) AS estimated_mib FROM logs GROUP BY target, level ORDER BY n DESC LIMIT 15;"

Check open processes:

bash
lsof ~/.codex/logs_2.sqlite ~/.codex/logs_2.sqlite-wal ~/.codex/logs_2.sqlite-shm \
     ~/.codex/sqlite/logs_2.sqlite ~/.codex/sqlite/logs_2.sqlite-wal ~/.codex/sqlite/logs_2.sqlite-shm 2>/dev/null

Install protection:

bash
sqlite3 "$db" "PRAGMA busy_timeout=10000; CREATE TRIGGER IF NOT EXISTS block_log_inserts BEFORE INSERT ON logs BEGIN SELECT RAISE(IGNORE); END;"

Clean up after protection:

bash
backup="$db.bak.$(date +%Y%m%d-%H%M%S)"
sqlite3 "$db" ".backup '$backup'"
test -s "$backup"
test "$(sqlite3 "$backup" 'PRAGMA quick_check;')" = "ok"
sqlite3 "$db" "PRAGMA busy_timeout=10000; PRAGMA wal_checkpoint(TRUNCATE); DELETE FROM logs; VACUUM; PRAGMA wal_checkpoint(TRUNCATE);"
echo "$backup"

Restore persistent logging:

bash
sqlite3 "$db" "DROP TRIGGER IF EXISTS block_log_inserts;"
Show full SKILL.md (367 more words)Show less

Diagnosis Rules

  • Missing all candidate logs_2.sqlite files: healthy/not applicable unless the user expects Codex to have run.
  • If multiple candidates exist, call out the active path from lsof; do not assume the top-level path is the only live database.
  • Trigger present and COUNT/MIN(id)/MAX(id) stable: protected.
  • Trigger absent and MIN(id) or MAX(id) moves: affected and actively writing.
  • If row ids move but file sizes do not materially increase, say "actively writing/churning" rather than "actively growing on disk".
  • Trigger absent, database large, high TRACE/DEBUG, but no sample movement: affected historically; recommend protection, cleanup optional.
  • Main DB or WAL above hundreds of MB: recommend cleanup after installing protection if the active path is affected.
  • WAL mtime or tiny WAL growth alone is not enough; use row/max-id samples.
  • If logs is absent or schema differs, stop and report that the known workaround is not safely applicable.

Safety Rules

  • Run read-only diagnosis before write operations unless the user explicitly asks for a specific command.
  • Do not claim the issue is fixed from file size alone; verify with COUNT(*), MAX(id) sampling.
  • Treat cleanup as reversible only through its timestamped backup. Mention the backup path in the final answer.
  • Do not delete backups automatically.
  • If SQLite reports lock or corruption errors, stop and report the exact error. Do not kill Codex processes unless the user explicitly asks.
  • This skill only manages Codex local SQLite diagnostic logs (~/.codex/logs_2.sqlite* and ~/.codex/sqlite/logs_2.sqlite*); it does not manage conversation archives, repo files, credentials, or remote telemetry.

Gotchas

  • COUNT(*) can stay constant while MIN(id) and MAX(id) move; classify this as churn, not a quiet database.
  • A WAL mtime change alone does not prove material disk growth.
  • Two database candidates may exist. Mutate only the path proven active or explicitly selected; never mirror a write to both paths by assumption.
  • Protection success does not authorize cleanup. Cleanup success requires a verified backup and fresh final sizes.
  • An unknown schema, lock error, failed backup check, or post-write verification failure is a hard error. Do not continue to the next mutation.

Answer Shape

Keep the user-facing answer short:

  1. One-line conclusion.
  2. Key evidence in 3-5 bullets.
  3. Recommended action and whether it was already applied.
  4. Backup path only if cleanup ran.

© majiayu000, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/codex-log-guard of majiayu000/spellbook.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit ed52af7

Compare with similar skills

Codex Log Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex Log Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex Log Guard this skillmajiayu000/spellbook287—~2.3kAutomated safety check: PassMIT
Iptvnator Sqlite DB Worker4gray/iptvnator7.3k—~824Automated safety check: PassMIT
Analyze Nsys Profilemlc-ai/pith-train355—~1.9kAutomated safety check: PassApache-2.0
Reactive Sqlite UIfastrepl/anarlog9.5k—~699Automated safety check: PassMIT
Composer Forensicsdxos/dxos526—~3.1kAutomated safety check: PassCustom licence
Sqlite Schema Designfastrepl/anarlog9.5k—~1.9kAutomated safety check: PassMIT

Similar skills

  • A skill your agent uses when changing Electron SQLite IPC, database-worker operations, request-scoped progress or cancellation, worker packaging, or runtime verification of non-EPG database work.

    7.3k GitHub stars~824 tokensUpdated today
    DatabasesAuto-check passed
  • Analyze Nsys Profile

    mlc-ai/pith-train

    Query a captured PithTrain Nsight Systems profile to measure compute/communication overlap, locate exposed comm by DualPipeV stage, and inspect per-rank stream behavior.

    355 GitHub stars~1.9k tokensUpdated today
    DatabasesAuto-check passed
  • Reactive Sqlite UI

    fastrepl/anarlog

    Build SQLite-backed reactive UI in apps/desktop using stable patterns for reads, selection, forms, writes, and loading states.

    9.5k GitHub stars~699 tokensUpdated today
    DatabasesAuto-check passed
  • Forensically inspect and repair Composer browser profiles — offline (Chrome OPFS / SQLite extract) or live via /recovery.html debug port.

    526 GitHub stars~3.1k tokensUpdated today
    DatabasesAuto-check passed
  • Sqlite Schema Design

    fastrepl/anarlog

    Design or review schemas for crates/cloudsync using SQLite Sync constraints, not generic SQLite advice.

    9.5k GitHub stars~1.9k tokensUpdated today
    DatabasesAuto-check passed
  • Makemigrations

    deusXmachina-dev/memorylane

    Create SQLite migrations for MemoryLane storage schema changes.

    121 GitHub stars~973 tokensUpdated yesterday
    DatabasesAuto-check passed

More from majiayu000/spellbook

All 97 skills in this repo
  • Skill Ecosystem Doctor

    majiayu000/spellbook

    Audits and repairs how coding-agent Skills are owned, copied and exposed across runtimes, from canonical sources to quarantine and retirement.

    287 GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • AGENTS.md Scaffold

    majiayu000/spellbook

    Scans a repository for real evidence and proposes, or on request writes, a small stack of root and scoped AGENTS.md files with validation commands and generated-file boundaries.

    287 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Product Demo Builder

    majiayu000/spellbook

    Plans, produces or diagnoses evidence-backed product demo videos: script, capture plan, pacing checks and verified final media built on real product behavior.

    287 GitHub stars~3.3k tokensUpdated yesterday
    Auto-check passed
  • Flowguard Task Guard

    majiayu000/spellbook

    Single entry point that routes long or ambiguous agent tasks, checks live state, bounds autonomous loops and leaves a resumable handoff.

    287 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Product Manager Toolkit

    majiayu000/spellbook

    Product management helpers: a RICE scoring script, an interview transcript analyzer and PRD templates for prioritizing features, synthesizing research and writing requirements.

    287 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Codex Log Guard

What does Codex Log Guard do?

Diagnose excessive Codex local SQLite diagnostic log writes with read-only evidence by default. Codex Log Guard is an agent skill from majiayu000/spellbook. Diagnose excessive Codex local SQLite diagnostic log writes with read-only evidence by default.

When should I use Codex Log Guard?

Codex Log Guard fits situations like: A user mentions logs2.sqlite; logs2.sqlite-wal; blockloginserts; explicitly asks to protect.

How do I install Codex Log Guard in Claude Code?

Run `npx skills add majiayu000/spellbook --skill codex-log-guard -a claude-code`. Or copy the skill folder (skills/codex-log-guard in majiayu000/spellbook) into .claude/skills/codex-log-guard in your project. Claude Code loads it when a task matches its description.

How do I install Codex Log Guard in Codex?

Run `npx skills add majiayu000/spellbook --skill codex-log-guard -a codex`. Or copy the skill folder (skills/codex-log-guard in majiayu000/spellbook) into .agents/skills/codex-log-guard in your project. Codex loads it when a task matches its description.

Can I use Codex Log Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/spellbook --skill codex-log-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-log-guard, .gemini/skills/codex-log-guard, .github/skills/codex-log-guard and .opencode/skills/codex-log-guard in your project.

What does Codex Log Guard need to run?

Going by SKILL.md and its folder, Codex Log Guard needs the command-line tools its instructions call (sqlite3).

Does Codex Log Guard access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Codex Log Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codex Log Guard use?

Codex Log Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex Log Guard use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codex Log Guard?

Skills that share tags, products or a category with Codex Log Guard: Iptvnator Sqlite DB Worker (4gray/iptvnator, 7.3k stars), Analyze Nsys Profile (mlc-ai/pith-train, 355 stars), Reactive Sqlite UI (fastrepl/anarlog, 9.5k stars) and Composer Forensics (dxos/dxos, 526 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex Log Guard?

majiayu000 (a GitHub user) maintains it in majiayu000/spellbook, which has 287 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 8, 2026.

Source: majiayu000/spellbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.