Agent skill

Codex Activity Report

by SpecterOps in SpecterOps/skills

Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

Apache-2.0Auto-check passedDatabases

Install Codex Activity Report

skills CLI
$ npx skills add SpecterOps/skills --skill codex-activity-report -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SpecterOps/skills codex-activity-report --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/codex-observability/skills/codex-activity-report .claude/skills/codex-activity-report && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex-activity-report
GitHub stars
702
Token cost
~805 tokens
SKILL.md length
330 words
Files
6 (incl. scripts, references, assets)
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

  • Works in 4 steps: Resolve the target repository root.… → Run the bundled generator script and let… → Review the generated Markdown only for… → …
  • Codex needs to turn .codex logs
  • SKILL.md covers Overview, Workflow, Command and Output Rules, plus 1 more section
  • Runs Python scripts from its folder; calls python3

What it does

Codex Activity Report is an agent skill from SpecterOps/skills. Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts. Use when Codex needs to turn .codex logs, rollout JSONL files, archived session bundles, history files, SQLite logs, or planner state into Markdown reporting under reports/, especially for after-action reporting, operator handoff, chronology reconstruction, or evidence-backed engagement summaries.

Its SKILL.md is about 810 tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts, reference files and assets (for example `agents/openai.yaml`, `references/log-sources.md` and `scripts/generate_codex_activity_report.py`).

It sits in Databases, covering Retrospectives. It works with SQLite. The repository describes itself as: A marketplace for LLM skills. The licence is Apache-2.0.

When your agent uses it

  • Codex needs to turn .codex logs
  • Rollout JSONL files
  • Archived session bundles
  • Planner state into Markdown reporting under reports/

Example prompts

  • “/codex-activity-report”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Resolve the target repository root. Default to the current repository when it contains .codex/.
  2. Run the bundled generator script and let it write into reports/.
  3. Review the generated Markdown only for obvious formatting issues or user-requested voice changes. Do not rewrite timestamps, prompts, or…
  4. Keep both outputs in UTC.

What it can do on your machine

Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codex Activity Report loads about 805 tokens when it runs, and up to ~1.3k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 330 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~805
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from SpecterOps/skills at commit e655f93, republished under its Apache-2.0 licence (© SpecterOps). 330 words, ~805 tokens.

Download SKILL.mdSave it as .claude/skills/codex-activity-report/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
codex-activity-report
description
Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts. Use when Codex needs to turn `.codex` logs, rollout JSONL files, archived session bundles, history files, SQLite logs, or planner state into Markdown reporting under `reports/`, especially for after-action reporting, operator handoff, chronology reconstruction, or evidence-backed engagement summaries.
metadata.author
GhostWorks

Codex Activity Report

Overview

Generate two Markdown reports from the local Codex evidence trail: a normalized timeline and a narrative chronology. Use the bundled generator to preserve exact UTC timestamps, exact operator prompts, and exact command strings while keeping the output readable.

Workflow

  1. Resolve the target repository root. Default to the current repository when it contains .codex/.
  2. Run the bundled generator script and let it write into reports/.
  3. Review the generated Markdown only for obvious formatting issues or user-requested voice changes. Do not rewrite timestamps, prompts, or commands.
  4. Keep both outputs in UTC.

Command

Run the generator from the repository root or pass --repo-root explicitly:

bash
python3 plugins/codex-observability/skills/codex-activity-report/scripts/generate_codex_activity_report.py

Useful flags:

  • --repo-root /absolute/path/to/repo
  • --codex-home /absolute/path/to/.codex
  • --output-dir /absolute/path/to/repo/reports
  • --timeline-name custom-timeline.md
  • --narrative-name custom-narrative.md
  • --session-id <session-id>
  • --focus-pattern 'app-server-experiments|codex-app-server-client'
  • --no-archives

Use --focus-pattern when you want a report for one workstream inside a larger .codex history. The generator seeds sessions from matching events and then keeps the full session chronology so the resulting timeline does not lose nearby actions that used generic commands.

Output Rules

  • Write the reports to reports/ unless the operator asks for a different output directory.
  • Generate a normalized timeline:
    • keep prompts, approvals, patches, warnings, errors, and saved state artifacts discrete;
    • group repetitive read-only inspection commands and empty PTY polls.
  • Generate a narrative chronology:
    • keep the tone evidence-based and in active voice;
    • use the operator, Codex, or the Codex harness as the actor names;
    • use On <Month Day, Year> at HH:MM:SS UTC, ... for the first event of a day;
    • use At HH:MM:SS UTC, ... for later same-day events.
  • Quote user prompts and exact commands verbatim when the artifacts contain them.
  • Preserve UTC in both files even when the source artifact also exposes local filesystem metadata.

Sources

The generator already knows how to parse the primary Codex artifacts in this repository class:

  • rollout JSONL files under .codex/sessions/
  • archived rollout JSONL files inside .codex/sessions/**/*.zip
  • .codex/history.jsonl
  • .codex/log/codex-tui.log
  • .codex/logs*.sqlite
  • planner and agent artifacts under .codex/state/

Read references/log-sources.md only when you need the exact precedence and normalization details.

© SpecterOps, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references, assets) in plugins/codex-observability/skills/codex-activity-report of SpecterOps/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/icon.png
  • assets/icon.svg
  • references/log-sources.md
  • scripts/generate_codex_activity_report.py

Open the folder on GitHubat commit e655f93

Compare with similar skills

Codex Activity Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codex Activity Report compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codex Activity Report this skillSpecterOps/skills702—~805Automated safety check: PassApache-2.0
Breach Patternsbriiirussell/cybersecurity-skills413—~3.5kAutomated safety check: NotesMIT
Iptvnator Sqlite DB Worker4gray/iptvnator7.3k—~824Automated safety check: PassMIT
Analyze Nsys Profilemlc-ai/pith-train355—~1.9kAutomated safety check: PassApache-2.0
DB Ops SopOpenDCAI/DataMind423—~388Automated safety check: PassApache-2.0
Reactive Sqlite UIfastrepl/anarlog9.5k—~699Automated safety check: PassMIT

Similar skills

  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    DatabasesAuto-check: notes
  • A skill your agent uses when changing Electron SQLite IPC, database-worker operations, request-scoped progress or cancellation, worker packaging, or runtime verification of non-EPG database work.

    7.3k GitHub stars~824 tokensUpdated today
    DatabasesAuto-check passed
  • Analyze Nsys Profile

    mlc-ai/pith-train

    Query a captured PithTrain Nsight Systems profile to measure compute/communication overlap, locate exposed comm by DualPipeV stage, and inspect per-rank stream behavior.

    355 GitHub stars~1.9k tokensUpdated 4 days ago
    DatabasesAuto-check passed
  • DB Ops Sop

    OpenDCAI/DataMind

    Database operations runbook — backup, recovery, performance tuning, troubleshooting.

    423 GitHub stars~388 tokensUpdated 18 days ago
    DatabasesAuto-check passed
  • Reactive Sqlite UI

    fastrepl/anarlog

    Build SQLite-backed reactive UI in apps/desktop using stable patterns for reads, selection, forms, writes, and loading states.

    9.5k GitHub stars~699 tokensUpdated today
    DatabasesAuto-check passed
  • Forensically inspect and repair Composer browser profiles — offline (Chrome OPFS / SQLite extract) or live via /recovery.html debug port.

    525 GitHub stars~3.1k tokensUpdated today
    DatabasesAuto-check passed

More from SpecterOps/skills

All 38 skills in this repo
  • Com Proxy Triage

    SpecterOps/skills

    A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…

    702 GitHub stars~1.5k tokensUpdated 15 days ago
    Auto-check passed
  • Cwe Code Review

    SpecterOps/skills

    Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

    702 GitHub stars~2.4k tokensUpdated 15 days ago
    Auto-check passed
  • Ghostwriter Oplog

    SpecterOps/skills

    A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.

    702 GitHub stars~665 tokensUpdated 15 days ago
    Auto-check passed
  • Nmap Parse

    SpecterOps/skills

    Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.

    702 GitHub stars~738 tokensUpdated 15 days ago
    Auto-check passed
  • Osint Recon

    SpecterOps/skills

    Perform OSINT and external reconnaissance for approved targets.

    702 GitHub stars~813 tokensUpdated 15 days ago
    Auto-check passed
  • Proxychains Tunnel

    SpecterOps/skills

    Run in-scope network commands through a SOCKS5 tunnel with proxychains4, including tunnel readiness checks and evidence capture.

    702 GitHub stars~826 tokensUpdated 15 days ago
    Auto-check passed

Works with

Questions about Codex Activity Report

What does Codex Activity Report do?

Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts. Codex Activity Report is an agent skill from SpecterOps/skills. Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

When should I use Codex Activity Report?

Codex Activity Report fits situations like: Codex needs to turn .codex logs; rollout JSONL files; archived session bundles; planner state into Markdown reporting under reports/.

How do I install Codex Activity Report in Claude Code?

Run `npx skills add SpecterOps/skills --skill codex-activity-report -a claude-code`. Or copy the skill folder (plugins/codex-observability/skills/codex-activity-report in SpecterOps/skills) into .claude/skills/codex-activity-report in your project. Claude Code loads it when a task matches its description.

How do I install Codex Activity Report in Codex?

Run `npx skills add SpecterOps/skills --skill codex-activity-report -a codex`. Or copy the skill folder (plugins/codex-observability/skills/codex-activity-report in SpecterOps/skills) into .agents/skills/codex-activity-report in your project. Codex loads it when a task matches its description.

Can I use Codex Activity Report in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill codex-activity-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex-activity-report, .gemini/skills/codex-activity-report, .github/skills/codex-activity-report and .opencode/skills/codex-activity-report in your project.

What does Codex Activity Report need to run?

Going by SKILL.md and its folder, Codex Activity Report needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Codex Activity Report access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Codex Activity Report safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Codex Activity Report use?

Codex Activity Report is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codex Activity Report use?

About 805 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 541 tokens, read only when the agent opens those files.

What are the alternatives to Codex Activity Report?

Skills that share tags, products or a category with Codex Activity Report: Breach Patterns (briiirussell/cybersecurity-skills, 413 stars), Iptvnator Sqlite DB Worker (4gray/iptvnator, 7.3k stars), Analyze Nsys Profile (mlc-ai/pith-train, 355 stars) and DB Ops Sop (OpenDCAI/DataMind, 423 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codex Activity Report?

SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 702 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.

Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.