Agent skill

Code Investigate

by sd0xdev in sd0xdev/sd0x-harness

Dual-perspective code investigation. An agent skill from sd0xdev/sd0x-harness.

MITAuto-check passedDevelopment

Install Code Investigate

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill code-investigate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness code-investigate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-investigate .claude/skills/code-investigate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-investigate
GitHub stars
192
Token cost
~1.5k tokens
SKILL.md length
339 words
Files
3 (incl. references)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Dual-perspective code investigation. An agent skill from sd0xdev/sd0x-harness.

  • Works in 4 steps: What files are related? → How does the core logic work? → What is the data flow? → …
  • : deep code analysis needing both Claude and Codex perspectives
  • SKILL.md covers Trigger, When NOT to Use, Core Principle and Workflow, plus 8 more sections
  • Calls codex, git and claude

What it does

Code Investigate is an agent skill from sd0xdev/sd0x-harness. Dual-perspective code investigation. Use when: deep code analysis needing both Claude and Codex perspectives. Not for: quick exploration (use code-explore), code review (use codex-code-review). Output: integrated findings from dual analysis.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/output-template.md` and `references/prompts.md`).

It sits in Development, covering Code review. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • : deep code analysis needing both Claude and Codex perspectives
  • Tasks that involve Code review

Example prompts

  • “/code-investigate”

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash(git:*), Bash(node:*), Write

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. What files are related?
  2. How does the core logic work?
  3. What is the data flow?
  4. What are the key dependencies?

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash(git:*)
    • Bash(node:*)
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • codex
    • git
    • claude

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Investigate loads about 1.5k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 339 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 339 words, ~1,509 tokens.

Download SKILL.mdSave it as .claude/skills/code-investigate/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
code-investigate
description
Dual-perspective code investigation. Use when: deep code analysis needing both Claude and Codex perspectives. Not for: quick exploration (use code-explore), code review (use codex-code-review). Output: integrated findings from dual analysis.
allowed-tools
Read, Grep, Glob, Bash(git:*), Bash(node:*), Write
context
fork

Code Investigate Skill

Trigger

  • Keywords: investigate code, how feature works, trace implementation, dual confirmation, deep dive, how code works, what this code does, code research

When NOT to Use

  • Just need quick lookup (use Grep/Glob directly)
  • Code review (use codex-review)
  • System verification (use feature-verify)
  • Git history tracking (use git-investigate)

Core Principle

Codex must explore independently. Feeding Claude's conclusions to Codex is prohibited.
┌─────────────────┐     ┌─────────────────┐
│ Claude Explores  │     │ Codex Explores   │
│ Independently    │     │ Independently    │
│   (Phase 1-2)   │     │    (Phase 3)     │
└────────┬────────┘     └────────┬────────┘
         │                       │
         ▼                       ▼
   ┌───────────┐           ┌───────────┐
   │ Claude    │           │ Codex     │
   │ Conclusion│           │ Conclusion│
   └─────┬─────┘           └─────┬─────┘
         │                       │
         └───────────┬───────────┘
                     ▼
              ┌─────────────┐
              │ Consolidated│
              │   Report    │
              │  (Phase 4)  │
              └─────────────┘

Workflow

PhaseNameActionOutput
1Claude ExploreGrep/Glob/Read to search codeRelated files list
2Claude ConcludeAnalyze logic, form understandingInitial conclusion (internal)
3Codex ExploreInvoke Codex exec to explore independentlyCodex analysis report
4IntegrateCompare both perspectives, mark differencesConsolidated report

Codex Invocation Rules

Dispatch Phase 3 per @skills/codex-code-review/references/codex-transport.md § Start with the template in references/prompts.md. The transport pins the sandbox and the approval policy, and it derives the working directory from git rev-parse --show-toplevel — none of the three is chosen here, and this skill no longer restates them.

Bind every placeholder before writing prompt.md. The template is body-only, so nothing evaluates an expression inside it: ${USER_QUESTION} and ${PROJECT_PATH} must carry real values by the time the file is written.

Correct Approach

Code Investigation Task

Question

${USER_QUESTION}

Project Info

  • Path: ${PROJECT_PATH}
  • Tech Stack: ${TECH_STACK} <!-- one bound value, read from the repository's own manifest and layout. `{FRAMEWORK}`/`{DATABASE}` were never in this file's binding contract and rendered literally, and the hard-coded `TypeScript` was false for any repository that is not one — this project is JavaScript. Omit the line entirely rather than guess. -->

Please independently explore the codebase and answer:

  1. What files are related?
  2. How does the core logic work?
  3. What is the data flow?
  4. What are the key dependencies?

Please grep/read and explore on your own, then provide your analysis.

Show full SKILL.md (108 more words)Show less
Prohibited Approaches
PatternProblemExample
Feeding conclusionClaude's findings leak to CodexClaude found these files: ${findings}
Leading questionPresupposes answerI think the problem is in cache, verify
Scope restrictionPrevents independent explorationOnly look at src/service/

Output

markdown
## Investigation Report
- **Claude findings**: <independent analysis>
- **Codex findings**: <independent analysis>
- **Integrated conclusion**: <merged findings>
- **Confidence**: High / Medium / Low

Verification Checklist

CheckStandard
Claude independent conclusionPhase 2 forms conclusion, not output to user
Codex prompt is cleanContains only question + project path, no Claude findings
Report perspectives separatedClaude / Codex conclusions presented separately
Integration is completeMarks agreement, differences, possible gaps

References

FilePurposeWhen to Read
references/prompts.mdCodex prompt templatesBefore Phase 3
references/output-template.mdReport formatDuring Phase 4

Examples

Feature Investigation
Input: Investigate how order processing works
Phase 1: Grep "processOrder" -> Read src/service/order/*.ts
Phase 2: Form understanding: Controller -> Service -> Repository write
Phase 3: Codex explores independently (only given question + path)
Phase 4: Consolidated report -> mark both perspectives
Mechanism Understanding
Input: How does the API caching mechanism work?
Phase 1: Grep "cache" + "portfolio" -> Read related files
Phase 2: Understand Redis TTL + fallback mechanism
Phase 3: Codex investigates independently
Phase 4: Compare differences -> output consolidated report
Problem Diagnosis
Input: Why is token price sometimes null?
Phase 1: Search price-related logic + error handling
Phase 2: Identify possible fallback paths
Phase 3: Codex diagnoses independently
Phase 4: Synthesize both findings -> list possible causes

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/code-investigate of sd0xdev/sd0x-harness.

  • SKILL.md
  • references/output-template.md
  • references/prompts.md

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Code Investigate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Investigate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Investigate this skillsd0xdev/sd0x-harness192—~1.5kAutomated safety check: PassMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Backend Code Reviewlangflow-ai/langflow156k—~3.5kAutomated safety check: NotesMIT
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
Mole Bug Patternstw93/Mole69k—~2kAutomated safety check: PassGPL-3.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Backend Code Review

    langflow-ai/langflow

    Review backend code for quality, security, maintainability, and best practices based on established checklist rules.

    156k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check: notes
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • A catalog of recurring bug shapes in the Mole Mac cleaner, used to review safety-sensitive diffs for deletion safety, unbounded commands, shell traps and weak tests.

    69k GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Backend Code Review

    langgenius/dify

    Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.

    158k GitHub stars~676 tokensUpdated today
    DevelopmentAuto-check passed

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Code Investigate

What does Code Investigate do?

Dual-perspective code investigation. An agent skill from sd0xdev/sd0x-harness. Code Investigate is an agent skill from sd0xdev/sd0x-harness. Dual-perspective code investigation.

When should I use Code Investigate?

Code Investigate fits situations like: : deep code analysis needing both Claude and Codex perspectives; tasks that involve Code review.

How do I install Code Investigate in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill code-investigate -a claude-code`. Or copy the skill folder (skills/code-investigate in sd0xdev/sd0x-harness) into .claude/skills/code-investigate in your project. Claude Code loads it when a task matches its description.

How do I install Code Investigate in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill code-investigate -a codex`. Or copy the skill folder (skills/code-investigate in sd0xdev/sd0x-harness) into .agents/skills/code-investigate in your project. Codex loads it when a task matches its description.

Can I use Code Investigate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill code-investigate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-investigate, .gemini/skills/code-investigate, .github/skills/code-investigate and .opencode/skills/code-investigate in your project.

What does Code Investigate need to run?

Going by SKILL.md and its folder, Code Investigate needs the command-line tools its instructions call (codex, git and claude). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash(git:*), Bash(node:*), Write.

Does Code Investigate access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Investigate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Investigate use?

Code Investigate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Investigate use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Code Investigate?

Skills that share tags, products or a category with Code Investigate: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Backend Code Review (langflow-ai/langflow, 156k stars) and Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Investigate?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.