Agent skill

Codex Agent Provider for NanoClaw

by nanocoai in nanocoai/nanoclaw

Installs Codex as an agent provider for NanoClaw groups, with streaming, MCP tools, server-side history and vault-only credentials, next to or instead of Claude.

MITAuto-check: notesAI & LLM Engineering

Install Codex Agent Provider for NanoClaw

skills CLI
$ npx skills add nanocoai/nanoclaw --skill add-codex -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nanocoai/nanoclaw add-codex --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nanocoai/nanoclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/add-codex .claude/skills/add-codex && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-codex
GitHub stars
31k
Token cost
~2.3k tokens
SKILL.md length
833 words
Files
5
Skills in repo
59
Repo updated
First seen
Licence
MIT

At a glance

Installs Codex as an agent provider for NanoClaw groups, with streaming, MCP tools, server-side history and vault-only credentials, next to or instead of Claude.

  • Works in 5 steps: Fetch and copy the payload → Wire the barrels → CLI manifest → …
  • Running a NanoClaw group on Codex instead of Claude
  • SKILL.md covers Install, Authenticate, Use it and Troubleshooting
  • Runs TypeScript scripts from its folder; calls pnpm and codex

What it does

NanoClaw picks each group's backend from `container_configs.provider`, which defaults to Claude. This skill installs the Codex provider by copying a payload from the `providers` branch, adding one import to each of three provider barrels, adding a pinned Codex CLI to `container/cli-tools.json`, rebuilding the image and running an auth walk-through. A provider shortcut command does the same in one step, and a group is switched with `ncl groups config update --provider codex`.

The provider runs `codex app-server` as a child process speaking JSON-RPC over stdio, which gives streaming, MCP tools and conversation history kept server-side, continued by thread ID. Credentials are vault-only: the selected gateway supplies a placeholder `auth.json` and swaps in the real ChatGPT token or API key in transit, so nothing sits in `.env`. Install steps are idempotent and safe to rerun, and the pre-flight requires `src/project-doc-compose.ts`, otherwise run `/update-nanoclaw` first.

When your agent uses it

  • Running a NanoClaw group on Codex instead of Claude
  • Using a ChatGPT subscription or OpenAI API key with NanoClaw, kept in the credential vault
  • Re-running or checking the Codex provider install on an existing setup

Example prompts

  • “Add the Codex provider to NanoClaw and walk me through authenticating with my ChatGPT subscription.”
  • “Switch the support group to the Codex provider and leave the other groups on Claude.”
  • “Check whether the Codex provider payload is already wired into this install.”

Requirements

  • A NanoClaw installation
  • A ChatGPT subscription or an OpenAI API key
  • pnpm and a container image rebuild

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Fetch and copy the payload
  2. Wire the barrels
  3. CLI manifest
  4. Build
  5. Validate

What it can do on your machine

Read from SKILL.md and the folder at commit 66f0823. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript), which the agent can run.

    Shell commands in SKILL.md call:

    • pnpm
    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex Agent Provider for NanoClaw loads about 2.3k tokens when it runs. Until then it costs about 100 tokens; SKILL.md has 833 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:18
    oken or API key on the wire — no key in `.env`, nothing readable in the container.
  • NoteMentions a .env fileSKILL.md:152
    default** (`DEFAULT_AGENT_PROVIDER` in `.env`, or `claude` when unset). Installing this skill wires codex in but does N

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nanocoai/nanoclaw at commit 66f0823, republished under its MIT licence (© nanocoai). 833 words, ~2,259 tokens.

Download SKILL.mdSave it as .claude/skills/add-codex/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
add-codex
description
Use Codex (OpenAI's codex app-server) as a full agent provider — planning, tool orchestration, MCP tools, server-side history, session resume — alongside or instead of Claude. ChatGPT subscription or OpenAI API key, vault-only via the selected gateway. Per-group via `ncl groups config update --provider codex`. Distinct from using OpenAI as an MCP tool (where Claude remains the planner).
metadata.nanoclaw-provider
codex
metadata.nanoclaw-provider-label
Codex
metadata.nanoclaw-provider-hint
OpenAI — ChatGPT subscription or API key
metadata.nanoclaw-provider-offered
true
metadata.nanoclaw-provider-image
local-required

Codex agent provider

Shortcut: pnpm exec tsx setup/index.ts --step provider-auth codex performs this whole install (manifest-driven from the providers branch: files, barrels, CLI manifest entry, image rebuild) plus auth in one command. The steps below are the same operations, for agent-driven or manual application.

NanoClaw selects each group's agent backend from container_configs.provider (default claude). This skill installs the Codex provider: copy the payload from the providers branch, append one import to each of the three provider barrels, add the pinned Codex CLI to the container manifest (container/cli-tools.json), rebuild, then run the vault auth walk-through.

The provider runs codex app-server as a child process speaking JSON-RPC over stdio: native streaming, MCP tools, server-side conversation history (the continuation is a thread id, no on-disk transcript). Credentials are vault-only: The selected gateway serves a sentinel auth.json stub into the container and swaps the real ChatGPT token or API key on the wire — no key in .env, nothing readable in the container.

The mechanical steps under Install carry nc: directive fences: an agent reads the prose and applies them, and a parser can apply them deterministically from the same document. Every directive is idempotent, so the whole skill is safe to re-run; anything a parser can't apply falls back to the prose beside it.

Install

Pre-flight

Requires src/project-doc-compose.ts on trunk. If it is missing, stop and tell the operator to run /update-nanoclaw first.

Check whether the payload is already wired (a prior apply, or a trunk that still carries it). All of these present means installed — skip to Authenticate:

  • src/providers/codex.ts and src/providers/codex-agents-md.ts
  • container/agent-runner/src/providers/codex.ts and codex-app-server.ts
  • setup/providers/codex.ts and both provider-contracts/codex.ts declarations (host and container)
  • import './codex.js'; in the three provider barrels and both contract barrels
  • an @openai/codex entry in container/cli-tools.json
1. Fetch and copy the payload

Fetch the providers branch and copy the Codex payload into all three trees (additive — overwrite each file, never merge the branch). The host files are the provider contribution + the AGENTS.md spec (composition itself lives in trunk's src/project-doc-compose.ts) + their guards; the container files are the provider runtime (turn loop, JSON-RPC wrapper, native memory SessionStart hook, per-exchange archiver) + their guards; the setup file is the picker entry + vault auth walk-through; container/AGENTS.md is the runtime-contract base the composed AGENTS.md embeds.

nccopy
src/providers/codex.ts
src/providers/codex-agents-md.ts
src/providers/codex-registration.test.ts
src/providers/codex-host-contribution.test.ts
src/providers/codex-agents-md.test.ts
container/agent-runner/src/providers/codex.ts
container/agent-runner/src/providers/codex-app-server.ts
container/agent-runner/src/providers/exchange-archive.ts
container/agent-runner/src/providers/exchange-archive.test.ts
container/agent-runner/src/providers/codex-registration.test.ts
container/agent-runner/src/providers/codex.factory.test.ts
container/agent-runner/src/providers/codex.turns.test.ts
container/agent-runner/src/providers/codex-app-server.test.ts
container/agent-runner/src/providers/codex-contract-parity.test.ts
container/agent-runner/src/providers/codex.conformance.test.ts
container/agent-runner/src/providers/codex-cli-tools.test.ts
container/agent-runner/src/provider-contracts/codex.ts
setup/providers/codex-registration.test.ts
container/AGENTS.md
Use the selected gateway for authentication

Install the bundled Codex authentication hook alongside the registry payload. This keeps the same login choices while delegating custody to the selected gateway, and preserves the hook when a provider refresh copies registry files again. These two files are omitted from the registry copy so refresh stays idempotent. The setup screens and step sequence do not change.

nccopy
payload/src/provider-contracts/codex.ts -> src/provider-contracts/codex.ts
payload/setup/providers/codex.ts -> setup/providers/codex.ts
payload/setup/providers/codex.test.ts -> setup/providers/codex.test.ts
2. Wire the barrels

Append the self-registration import to each provider and contract barrel (skipped if already present).

ncappend
import './codex.js';
ncappend
import './codex.js';
ncappend
import './codex.js';
ncappend
import './codex.js';
ncappend
import './codex.js';
3. CLI manifest

The agent's global Node CLIs install from container/cli-tools.json (a json-merge seam), not hand-edited Dockerfile layers. Add Codex by appending one entry — idempotent on name, so a re-run is a no-op. @openai/codex has no native postinstall, so no onlyBuilt. The Dockerfile already installs every manifest entry via pinned pnpm install -g; no Dockerfile edit is needed.

ncjson-merge
{ "name": "@openai/codex", "version": "0.155.1" }

The version (0.155.1) is the canonical pin — this SKILL.md is the source of truth.

Show full SKILL.md (312 more words)Show less
4. Build
ncrun
pnpm run build
pnpm exec tsc -p container/agent-runner/tsconfig.json --noEmit
./container/build.sh
5. Validate
ncrun
pnpm exec tsx scripts/provider-contract-verifier.ts --required-declared codex

The registration tests import only the real barrels — they go red if a barrel line is missing, a barrel fails to evaluate, or the payload is broken.

Authenticate

ncrun
pnpm exec tsx setup/index.ts --step provider-auth codex

The same walk-through fresh installs get from the setup picker: ChatGPT subscription (browser login or device pairing) or an OpenAI API key, landed in the selected gateway’s vault. Idempotent — it short-circuits when a matching secret already exists. It finishes with the install check.

Use it

Per group:

bash
ncl groups config update --id <group-id> --provider codex
ncl groups restart --id <group-id>

Switching is an operator action — run it from the host. Every provider uses the same memory/ tree, so memory carries across automatically. Run /migrate-memory only when upgrading a group that still has legacy .seed.md, CLAUDE.local.md, or unindexed imported memory. See docs/provider-migration.md.

Default new groups to codex (optional)

New groups are created on the instance default (DEFAULT_AGENT_PROVIDER in .env, or claude when unset). Installing this skill wires codex in but does NOT change that default — "installed" is not "authenticated", so the default stays claude until you opt in explicitly.

After install, ask the operator before flipping it:

"Codex is installed. Default new agent groups to codex? Existing groups keep their current provider."

On yes — set it, then restart the host so it takes effect:

bash
pnpm exec tsx setup/index.ts --step set-env -- --key DEFAULT_AGENT_PROVIDER --value codex
launchctl kickstart -k gui/$(id -u)/com.nanoclaw   # macOS; Linux: systemctl --user restart nanoclaw

This affects only groups created afterward. Per-group ncl groups config update --provider still overrides the default in either direction. Creation itself stays provider-agnostic (no --provider flag — provider is a DB property stamped from the instance default at creation).

Troubleshooting

  • Container dies at boot, channel silent: grep 'Container exited non-zero' logs/nanoclaw.error.log — the stderrTail carries the reason (e.g. Unknown provider: codex. Registered: claude means the barrels aren't wired in the running build).
  • In-channel Error: spawn codex ENOENT on every message: the image predates the manifest entry — re-run ./container/build.sh.
  • Auth errors mid-conversation: the vault secret is missing or stale — re-run pnpm exec tsx setup/index.ts --step provider-auth codex (subscription re-login updates the vault copy).

© nanocoai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in .claude/skills/add-codex of nanocoai/nanoclaw.

  • SKILL.md
  • REMOVE.md
  • payload/setup/providers/codex.test.ts
  • payload/setup/providers/codex.ts
  • payload/src/provider-contracts/codex.ts

Open the folder on GitHubat commit 66f0823

Compare with similar skills

Codex Agent Provider for NanoClaw next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex Agent Provider for NanoClaw compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex Agent Provider for NanoClaw this skillnanocoai/nanoclaw31k—~2.3kAutomated safety check: NotesMIT
Auto Review Loop LLMAI4Scientist/nano-scientist1284 repos~1.8kAutomated safety check: WarnNone
Openai Knowledgeopenai/openai-agents-python30k1 repos~408Automated safety check: PassMIT
Openai Docs Skillaiskillstore/marketplace4302 repos~517Automated safety check: PassNone
Openai Docsaafqaq/codex-lb-enhanced1023 repos~861Automated safety check: PassApache-2.0
Openmaopenma-ai/open-managed-agents315—~854Automated safety check: PassApache-2.0

Similar skills

  • Auto Review Loop LLM

    AI4Scientist/nano-scientist

    Autonomous research review loop using any OpenAI-compatible LLM API.

    128 GitHub starsUsed in 4 repos~1.8k tokens
    Agent WorkflowsAuto-check: warnings
  • Openai Knowledge

    openai/openai-agents-python

    Official

    Retrieve authoritative OpenAI API and platform documentation when an integration or claim needs current external evidence.

    30k GitHub starsUsed in 1 repo~408 tokens
    AI & LLM EngineeringAuto-check passed
  • Openai Docs Skill

    aiskillstore/marketplace

    Query the OpenAI developer documentation via the OpenAI Docs MCP server using CLI (curl/jq).

    430 GitHub starsUsed in 2 repos~517 tokens
    AI & LLM EngineeringAuto-check passed
  • Openai Docs

    aafqaq/codex-lb-enhanced

    A skill your agent uses when the user asks how to build with OpenAI products or APIs and needs up-to-date official documentation with citations (for example: Codex, Responses API, Chat Completions…

    102 GitHub starsUsed in 3 repos~861 tokens
    DevOps & CloudAuto-check passed
  • Openma

    openma-ai/open-managed-agents

    Use the openma platform to build, deploy, and manage AI agents.

    315 GitHub stars~854 tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Neurolink Guide

    juspay/neurolink

    Guide for using the NeuroLink SDK and CLI. An agent skill from juspay/neurolink.

    143 GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed

More from nanocoai/nanoclaw

All 59 skills in this repo
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated 2 days ago
    Auto-check: notes
  • Agent Browser

    nanocoai/nanoclaw

    Drives a web browser from the shell with the agent-browser CLI: open pages, read an element snapshot, click and fill by reference, grab text and screenshots.

    31k GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check passed
  • Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.

    31k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check: notes
  • Guides a conversational migration from an OpenClaw install to NanoClaw v2, carrying over identity, channel credentials, scheduled tasks and workspace files.

    31k GitHub stars~6k tokensUpdated 2 days ago
    Auto-check: notes
  • Wires up an additional phone number onto an already-installed Dial channel, so one NanoClaw install answers SMS and AI voice calls on more than one line.

    31k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • NanoClaw LLM Wiki Setup

    nanocoai/nanoclaw

    Adds a persistent wiki knowledge base to a NanoClaw group following Karpathy's LLM Wiki pattern, with folders, a tailored container skill and a CLAUDE.md section.

    31k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed

Questions about Codex Agent Provider for NanoClaw

What does Codex Agent Provider for NanoClaw do?

Installs Codex as an agent provider for NanoClaw groups, with streaming, MCP tools, server-side history and vault-only credentials, next to or instead of Claude. provider`, which defaults to Claude.json`, rebuilding the image and running an auth walk-through.

When should I use Codex Agent Provider for NanoClaw?

Codex Agent Provider for NanoClaw fits situations like: running a NanoClaw group on Codex instead of Claude; using a ChatGPT subscription or OpenAI API key with NanoClaw, kept in the credential vault; re-running or checking the Codex provider install on an existing setup.

How do I install Codex Agent Provider for NanoClaw in Claude Code?

Run `npx skills add nanocoai/nanoclaw --skill add-codex -a claude-code`. Or copy the skill folder (.claude/skills/add-codex in nanocoai/nanoclaw) into .claude/skills/add-codex in your project. Claude Code loads it when a task matches its description.

How do I install Codex Agent Provider for NanoClaw in Codex?

Run `npx skills add nanocoai/nanoclaw --skill add-codex -a codex`. Or copy the skill folder (.claude/skills/add-codex in nanocoai/nanoclaw) into .agents/skills/add-codex in your project. Codex loads it when a task matches its description.

Can I use Codex Agent Provider for NanoClaw in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nanocoai/nanoclaw --skill add-codex -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-codex, .gemini/skills/add-codex, .github/skills/add-codex and .opencode/skills/add-codex in your project.

What does Codex Agent Provider for NanoClaw need to run?

Going by SKILL.md and its folder, Codex Agent Provider for NanoClaw needs TypeScript for the scripts in its folder and the command-line tools its instructions call (pnpm and codex). Our summary lists: A NanoClaw installation; A ChatGPT subscription or an OpenAI API key; pnpm and a container image rebuild.

Does Codex Agent Provider for NanoClaw access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Codex Agent Provider for NanoClaw safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Codex Agent Provider for NanoClaw use?

Codex Agent Provider for NanoClaw is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex Agent Provider for NanoClaw use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codex Agent Provider for NanoClaw?

Skills that share tags, products or a category with Codex Agent Provider for NanoClaw: Auto Review Loop LLM (AI4Scientist/nano-scientist, 128 stars), Openai Knowledge (openai/openai-agents-python, 30k stars), Openai Docs Skill (aiskillstore/marketplace, 430 stars) and Openai Docs (aafqaq/codex-lb-enhanced, 102 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex Agent Provider for NanoClaw?

nanocoai (a GitHub organization) maintains it in nanocoai/nanoclaw, which has 30,897 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on October 6, 2026.

Source: nanocoai/nanoclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.