Agent skill

Codex On Ish

by OpenMinis in OpenMinis/MinisSkills

Install and run OpenAI Codex CLI inside the Minis/iSH Alpine sandbox on iOS, where rustls TLS and async sockets are broken.

MITAuto-check passedBackend & APIs

Install Codex On Ish

skills CLI
$ npx skills add OpenMinis/MinisSkills --skill codex-on-ish -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OpenMinis/MinisSkills codex-on-ish --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OpenMinis/MinisSkills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/codex-on-ish .claude/skills/codex-on-ish && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex-on-ish
GitHub stars
444
Token cost
~1k tokens
SKILL.md length
410 words
Files
9 (incl. scripts, references)
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

Install and run OpenAI Codex CLI inside the Minis/iSH Alpine sandbox on iOS, where rustls TLS and async sockets are broken.

  • Works in 2 steps: rustls misbehaves on iSH's translated… → Async sockets to remote hosts fail…
  • The user wants Codex
  • SKILL.md covers Why this is needed (the two…, Install, Login (ChatGPT account) and What the wrapper does, plus 2 more sections
  • Runs Shell and Python scripts from its folder; calls sh and codex; reaches auth.openai.com

What it does

Codex On Ish is an agent skill from OpenMinis/MinisSkills. Install and run OpenAI Codex CLI inside the Minis/iSH Alpine sandbox on iOS, where rustls TLS and async sockets are broken. Covers the local MITM proxy with P-256 certs, version-spoofing to unlock newer models (gpt-5.6 family), forcing SSE instead of websockets, ChatGPT device-auth login driven by curl, and the refcounted proxy wrapper. Use when the user wants Codex or other Rust-based AI CLIs on the iPhone/iPad Minis shell, or hits "error sending request", "must support ECDSANISTP521SHA512" panics, model…

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts and reference files (for example `evals/evals.json`, `references/auth-protocol.md` and `references/troubleshooting.md`).

It sits in Backend & APIs, covering Realtime and WebSockets. It works with OpenAI, iOS, Rust and npm. The repository describes itself as: Skills collection for Minis. The licence is MIT.

When your agent uses it

  • The user wants Codex
  • Other Rust-based AI CLIs on the iPhone/iPad Minis shell
  • Hits error sending request
  • Must support ECDSANISTP521SHA512 panics

Example prompts

  • “error sending request”
  • “must support ECDSANISTP521SHA512”
  • “requires a newer version of Codex”
  • “/codex-on-ish”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. rustls misbehaves on iSH's translated CPU. Official musl binaries ≥ v0.143
  2. Async sockets to remote hosts fail (connect errno 65 / reqwest

What it can do on your machine

Read from SKILL.md and the folder at commit ae8c5db. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • sh
    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • auth.openai.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex On Ish loads about 1k tokens when it runs, and up to ~2.3k if it reads all its reference files. Until then it costs about 148 tokens; SKILL.md has 410 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~148
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from OpenMinis/MinisSkills at commit ae8c5db, republished under its MIT licence (© OpenMinis). 410 words, ~1,028 tokens.

Download SKILL.mdSave it as .claude/skills/codex-on-ish/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
codex-on-ish
description
Install and run OpenAI Codex CLI inside the Minis/iSH Alpine sandbox on iOS, where rustls TLS and async sockets are broken. Covers the local MITM proxy with P-256 certs, version-spoofing to unlock newer models (gpt-5.6 family), forcing SSE instead of websockets, ChatGPT device-auth login driven by curl, and the refcounted proxy wrapper. Use when the user wants Codex or other Rust-based AI CLIs on the iPhone/iPad Minis shell, or hits "error sending request", "must support ECDSA_NISTP521_SHA512" panics, model "requires a newer version of Codex", or npm errno 65 inside iSH.

Codex on iSH (Minis iOS sandbox)

Run the OpenAI Codex CLI natively in the Alpine/iSH environment. Works around the platform's broken Rust networking stack with a local MITM proxy.

Why this is needed (the two bugs)

  1. rustls misbehaves on iSH's translated CPU. Official musl binaries ≥ v0.143 panic at the first TLS handshake (installed rustls crypto provider must support ECDSA_NISTP521_SHA512) because aws-lc-rs CPU detection fails in the emulator. v0.130 (ring provider) handshakes, but ONLY with ECDSA P-256 certificates — RSA and P-521 get refused.
  2. Async sockets to remote hosts fail (connect errno 65 / reqwest error sending request). Blocking-socket clients (curl, Python) work fine; loopback connections work fine. Routing Rust traffic through a local proxy converts the hostile leg into a reliable one.

Both bugs are iSH-specific. Termux forks do NOT fix them (verified: their rustls code is identical to upstream).

Install

sh scripts/setup.sh

This downloads codex v0.130.0 musl aarch64, generates the P-256 CA/server certs, installs pyproxy6.py (proxy) and the codex wrapper into /usr/local/bin, and writes ~/.codex/config.toml defaults (model, yolo approval policy).

Login (ChatGPT account)

Codex's own login flows die within minutes (iOS kills the app at 48 CPU-s/min in background), so drive the OAuth device flow with curl instead:

sh scripts/token_poller3.sh &     # prints a live user_code, auto-renews
# user visits https://auth.openai.com/codex/device, enters the code
# poller exchanges the artifact and writes /tmp/token_result.json
sh scripts/write_auth_json.sh     # installs ~/.codex/auth.json
codex login status                # -> "Logged in using ChatGPT"

Key protocol facts (see references/auth-protocol.md):

  • POST /api/accounts/deviceauth/usercode JSON {client_id} → device_auth_id + user_code
  • poll /deviceauth/token with {device_auth_id, client_id, user_code} until it returns authorization_code + code_verifier
  • exchange at /oauth/token form-encoded (JSON is rejected) with redirect_uri=https://auth.openai.com/deviceauth/callback → id/access/refresh tokens
  • Python urllib is blocked by Cloudflare on these endpoints — always use curl.
Show full SKILL.md (168 more words)Show less

What the wrapper does

codex (wrapper) registers a refcount file, starts the proxy as a singleton (pidfile + pgrep guard), waits for the port, execs codex.bin with SSL_CERT_FILE/HTTPS_PROXY env, and cleans up on exit. The proxy tears itself down ~8 s after the last client leaves. Output is silent; logs live in /tmp/codex-proxy/.

Model gating and the version spoof

The backend gates models by reported client version (e.g. gpt-5.6-* requires ≥ 0.144.0 — the exact versions that panic on iSH). The proxy rewrites 0.130.0 → 0.151.0 in-flight (same byte length, so HTTP framing survives) in the request line, version: header, and bodies.

It also down-translates the models catalog: drops max/ultra reasoning efforts v0.130 can't parse, forces prefer_websockets=false, and rewrites Content-Length. Websocket upgrades on /backend-api/codex/responses get a local 501 so codex falls back to SSE (WS frames would stall the HTTP-framed relay); other WS upgrades pass through raw.

Troubleshooting

See references/troubleshooting.md for: cert re-generation, DNS EAI_AGAIN retries, "models list failed to refresh", login poller death, upstream 502s, and the iOS background CPU-budget kills.

© OpenMinis, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references) in codex-on-ish of OpenMinis/MinisSkills.

  • SKILL.md
  • evals/evals.json
  • references/auth-protocol.md
  • references/troubleshooting.md
  • scripts/codex-wrapper.sh
  • scripts/pyproxy6.py
  • scripts/setup.sh
  • scripts/token_poller3.sh
  • scripts/write_auth_json.sh

Open the folder on GitHubat commit ae8c5db

Compare with similar skills

Codex On Ish next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex On Ish compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex On Ish this skillOpenMinis/MinisSkills444—~1kAutomated safety check: PassMIT
Media over QUICmoq-dev/moq1.6k—~460Automated safety check: PassApache-2.0
Collaborating With Codexbkywksj/knowledge-base330—~1.1kAutomated safety check: PassCustom licence
Dev Rulesrust-dd/tako162—~810Automated safety check: PassMIT
Docs Writingrust-dd/tako162—~2.8kAutomated safety check: PassMIT
Kkrpc Interopkunkunsh/kkrpc174—~1.8kAutomated safety check: PassMIT

Similar skills

  • Media over QUIC

    moq-dev/moq

    Build live video, audio, and real-time data apps with Media over QUIC (MoQ). Use when adding live streaming, conferencing, voice AI, or real-time pub/sub to…

    1.6k GitHub stars~460 tokensUpdated today
    Backend & APIsAuto-check passed
  • Collaborating With Codex

    bkywksj/knowledge-base

    当用户明确点名要用 OpenAI Codex CLI 协同时使用此 Skill,把指定任务委托给 Codex 执行并整合结果。

    330 GitHub stars~1.1k tokensUpdated 6 days ago
    AI & LLM EngineeringAuto-check passed
  • Dev Rules

    rust-dd/tako

    General coding-style rules to apply to every project. An agent skill from rust-dd/tako.

    162 GitHub stars~810 tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • Docs Writing

    rust-dd/tako

    Conventions for writing and maintaining tako documentation pages under website/content/docs/.

    162 GitHub stars~2.8k tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • Kkrpc Interop

    kunkunsh/kkrpc

    A skill your agent uses when implementing kkrpc clients or servers in non-TypeScript languages, speaking the stable compact protocol, transports, and reference implementations in Go, Python, Rust…

    174 GitHub stars~1.8k tokensUpdated 26 days ago
    Backend & APIsAuto-check passed
  • Openclone CLI

    team-attention/openclone

    A skill your agent uses when the user wants to consult an AI persona "clone" for advice, strategy, analysis, or domain expertise—especially in startup, VC, tech, growth, HR, or business contexts.

    130 GitHub stars~712 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from OpenMinis/MinisSkills

All 49 skills in this repo
  • Android UI Automation

    OpenMinis/MinisSkills

    Automate Android apps that have no public API or web version by driving the UI layer through the Accessibility Service.

    444 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Evidence Chain Builder

    OpenMinis/MinisSkills

    Score a claim against the evidence behind it. An agent skill from OpenMinis/MinisSkills.

    444 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Hyperframes CLI

    OpenMinis/MinisSkills

    HyperFrames CLI and Minis rendering. An agent skill from OpenMinis/MinisSkills.

    444 GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • Whenpeak

    OpenMinis/MinisSkills

    Predict when a person's brain works best from their sleep, using the WhenPeak performance-intelligence API, and turn it into concrete scheduling advice.

    444 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Openstreetmap Marker

    OpenMinis/MinisSkills

    Generate a mobile-first, immersive, Amap(Gaode)-style custom landmark marker HTML map for travel itinerary planning, place showcasing, location sharing, etc.

    444 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • PDF Converter

    OpenMinis/MinisSkills

    Convert documents to PDF via a typst-based pipeline. An agent skill from OpenMinis/MinisSkills.

    444 GitHub stars~2.1k tokensUpdated today
    Auto-check passed

Categories

Questions about Codex On Ish

What does Codex On Ish do?

Install and run OpenAI Codex CLI inside the Minis/iSH Alpine sandbox on iOS, where rustls TLS and async sockets are broken. Codex On Ish is an agent skill from OpenMinis/MinisSkills. Install and run OpenAI Codex CLI inside the Minis/iSH Alpine sandbox on iOS, where rustls TLS and async sockets are broken.

When should I use Codex On Ish?

Codex On Ish fits situations like: the user wants Codex; other Rust-based AI CLIs on the iPhone/iPad Minis shell; hits error sending request; must support ECDSANISTP521SHA512 panics.

How do I install Codex On Ish in Claude Code?

Run `npx skills add OpenMinis/MinisSkills --skill codex-on-ish -a claude-code`. Or copy the skill folder (codex-on-ish in OpenMinis/MinisSkills) into .claude/skills/codex-on-ish in your project. Claude Code loads it when a task matches its description.

How do I install Codex On Ish in Codex?

Run `npx skills add OpenMinis/MinisSkills --skill codex-on-ish -a codex`. Or copy the skill folder (codex-on-ish in OpenMinis/MinisSkills) into .agents/skills/codex-on-ish in your project. Codex loads it when a task matches its description.

Can I use Codex On Ish in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OpenMinis/MinisSkills --skill codex-on-ish -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-on-ish, .gemini/skills/codex-on-ish, .github/skills/codex-on-ish and .opencode/skills/codex-on-ish in your project.

What does Codex On Ish need to run?

Going by SKILL.md and its folder, Codex On Ish needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (sh and codex). Our summary lists: Python 3; A Bash shell.

Does Codex On Ish access the network?

SKILL.md names 1 domain. In commands or code: auth.openai.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Codex On Ish safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Codex On Ish use?

Codex On Ish is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex On Ish use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Codex On Ish?

Skills that share tags, products or a category with Codex On Ish: Media over QUIC (moq-dev/moq, 1.6k stars), Collaborating With Codex (bkywksj/knowledge-base, 330 stars), Dev Rules (rust-dd/tako, 162 stars) and Docs Writing (rust-dd/tako, 162 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex On Ish?

OpenMinis (a GitHub organization) maintains it in OpenMinis/MinisSkills, which has 444 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 7, 2026.

Source: OpenMinis/MinisSkills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.