Agent skill

Ask Codex

by umputun in umputun/cc-thingz

Consult OpenAI Codex for investigation, debugging, or code review.

MITAuto-check: notesDevelopment

Install Ask Codex

skills CLI
$ npx skills add umputun/cc-thingz --skill ask-codex -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install umputun/cc-thingz ask-codex --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/umputun/cc-thingz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/thinking-tools/skills/ask-codex .claude/skills/ask-codex && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ask-codex
GitHub stars
484
Token cost
~2.6k tokens
SKILL.md length
782 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
MIT

At a glance

Consult OpenAI Codex for investigation, debugging, or code review.

  • Works in 5 steps: Check Availability → Build Context → Construct Prompt → …
  • User explicitly asks to ask codex
  • SKILL.md covers Activation Triggers, Workflow, Important Rules and When NOT to Use, plus 1 more section
  • Calls codex and npm

What it does

Ask Codex is an agent skill from umputun/cc-thingz. Consult OpenAI Codex for investigation, debugging, or code review. Use when user explicitly asks to "ask codex", "check with codex", "codex review", or as a last resort when stuck after 4+ failed attempts at debugging, investigation, or bug fix and completely out of ideas. Codex is slow (2-5 min), so only escalate when truly stuck. Codex runs in read-only mode with full project access — it analyzes, we implement.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Debugging. The repository describes itself as: various things for claude code. The licence is MIT.

When your agent uses it

  • User explicitly asks to ask codex
  • Check with codex
  • As a last resort when stuck after 4+ failed attempts at debugging
  • Bug fix and completely out of ideas

Example prompts

  • “ask codex”
  • “check with codex”
  • “codex review”
  • “/ask-codex”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash, Read, Grep, Glob

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Check Availability
  2. Build Context
  3. Construct Prompt
  4. Execute Codex
  5. Present Results

What it can do on your machine

Read from SKILL.md and the folder at commit 99e1c8d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • codex
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ask Codex loads about 2.6k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 782 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Grep, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from umputun/cc-thingz at commit 99e1c8d, republished under its MIT licence (© umputun). 782 words, ~2,579 tokens.

Download SKILL.mdSave it as .claude/skills/ask-codex/SKILL.md (or your agent's skills folder).
name
ask-codex
description
Consult OpenAI Codex for investigation, debugging, or code review. Use when user explicitly asks to "ask codex", "check with codex", "codex review", or as a last resort when stuck after 4+ failed attempts at debugging, investigation, or bug fix and completely out of ideas. Codex is slow (2-5 min), so only escalate when truly stuck. Codex runs in read-only mode with full project access — it analyzes, we implement.
allowed-tools
Bash, Read, Grep, Glob

Ask Codex

Consult OpenAI Codex (GPT-5.5) as a second opinion for investigation, debugging, or review tasks.

Activation Triggers

Explicit:

  • "ask codex", "check with codex", "codex review"
  • "what does codex think", "get codex opinion"
  • "consult codex", "run codex on this"

Automatic (last resort — stuck detection):

  • 4+ failed attempts at the same bug fix or investigation
  • completely out of ideas, all reasonable approaches exhausted
  • going in circles with no progress despite multiple different strategies

Workflow

Step 1: Check Availability

Run which codex to verify the CLI is installed. If not found, inform the user and stop.

Step 2: Build Context

Gather context from the current conversation:

  1. What's the problem/question — summarize in 2-3 sentences
  2. What we know — relevant files, error messages, behavior observed
  3. What we tried — approaches attempted and why they failed (if applicable)
  4. Specific question — what exactly codex should analyze or answer

Codex does NOT auto-load Claude Code's memory files — it only reads AGENTS.md. To give Codex the same project context Claude follows, prepend the memory-load preamble described in Step 3.

Step 3: Construct Prompt

Build a focused prompt. Do NOT dump entire files — codex has full project access and can read them itself. Provide file paths and line references so codex knows where to look.

Prepend a memory-load preamble. Codex auto-loads only AGENTS.md; it does NOT read Claude Code's memory files (CLAUDE.md, CLAUDE.local.md, .claude/rules/, ~/.claude/CLAUDE.md), so the project conventions Claude follows are invisible to Codex unless you tell it to read them. Prepend this line to the prompt:

First read these project guidance files if present: <ABS_HOME>/.claude/CLAUDE.md, CLAUDE.md, CLAUDE.local.md, .claude/rules/
  • Resolve <ABS_HOME> to the absolute home path (run echo $HOME, e.g. /home/<user>) and write the literal path — do NOT leave the string $HOME in the prompt. Whether $HOME expands depends on how the prompt is passed to Codex, and Codex may open the file with a non-shell tool that never expands it, so only a literal absolute path is reliable.
  • No @ prefix — @file is inert in codex exec (literal text, not an import).
  • The project-relative paths resolve against Codex's working directory; Codex skips any that don't exist.

Template for investigation/debug:

# [Investigation/Debug] Request

## Problem
[2-3 sentence description]

## Context
- Files: [path/to/file.go:lineNumber, ...]
- Observed: [what's happening]
- Expected: [what should happen]

## What We Tried
[List approaches and outcomes, or "First consultation" if fresh question]

## Question
[Specific, focused question for codex to answer]

Provide:
1. Root cause analysis (if debugging)
2. Concrete recommendation with file:line references
3. Why previous approaches failed (if applicable)

Keep response focused and actionable.

Template for code review (adversarial):

When asked for a code review, use this adversarial prompt that requires structured JSON output:

<role>
You are performing an adversarial code review.
Your job is to break confidence in the change, not to validate it.
</role>

<task>
Review the provided changes as if you are trying to find the strongest reasons
this change should not ship yet.
Scope: [files and changes to review — paths, branch diff, or description]
Focus: [specific area if user specified one, otherwise "general"]
</task>

<operating_stance>
Default to skepticism.
Assume the change can fail in subtle, high-cost, or user-visible ways until
the evidence says otherwise. Do not give credit for good intent or partial fixes.
If something only works on the happy path, treat that as a real weakness.
</operating_stance>

<attack_surfaces>
Prioritize failures that are expensive, dangerous, or hard to detect:
- auth, permissions, tenant isolation, and trust boundaries
- data loss, corruption, duplication, and irreversible state changes
- rollback safety, retries, partial failure, and idempotency gaps
- race conditions, ordering assumptions, stale state, and re-entrancy
- empty-state, nil, timeout, and degraded dependency behavior
- version skew, schema drift, migration hazards, and compatibility regressions
- observability gaps that would hide failure or make recovery harder
</attack_surfaces>

<finding_bar>
Report only material findings. No style feedback, naming nitpicks, or speculative
concerns without evidence. Each finding must answer:
1. What can go wrong?
2. Why is this code path vulnerable?
3. What is the likely impact?
4. What concrete change would reduce the risk?
Prefer one strong finding over several weak ones.
</finding_bar>

<grounding_rules>
Every finding must be defensible from actual code you can see.
Do not invent files, lines, code paths, or runtime behavior you cannot support.
If a conclusion depends on an inference, state that explicitly and keep the
confidence score honest.
</grounding_rules>

<structured_output>
Return ONLY valid JSON. Example with concrete values:
{
  "verdict": "needs-attention",
  "summary": "auth middleware skips token validation on retry paths",
  "findings": [
    {
      "severity": "high",
      "title": "token validation bypassed on retry",
      "body": "retryHandler re-enters serveHTTP without revalidating the bearer token, allowing expired tokens through on transient failures",
      "file": "internal/auth/middleware.go",
      "line_start": 42,
      "line_end": 55,
      "confidence": 0.85,
      "recommendation": "move token validation before the retry loop entry point"
    }
  ],
  "next_steps": ["add test for expired-token retry scenario"]
}

Allowed values:
- verdict: "approve" or "needs-attention"
- severity: "critical", "high", "medium", or "low"
- confidence: 0.0 to 1.0

Use "needs-attention" if there is any material risk worth blocking on.
Use "approve" only if you cannot support any substantive finding.
</structured_output>
Step 4: Execute Codex

Run codex in background (it takes 2-5 minutes for complex analysis):

bash
codex exec -m gpt-5.5 \
  --sandbox read-only \
  -c model_reasoning_effort="xhigh" \
  -c stream_idle_timeout_ms=600000 \
  "prompt here" < /dev/null

Execution rules:

  • Always end the invocation with < /dev/null (as shown). codex exec reads stdin to append a <stdin> block even when the prompt is a positional arg, so an inherited open pipe (common under a background launch) never closes and codex blocks forever on "Reading additional input from stdin…"; /dev/null gives immediate EOF.
  • Always use run_in_background: true in Bash tool
  • Monitor with BashOutput every 15-20 seconds
  • Be patient during reasoning phase (1-3 minutes of silence is normal)
  • Total timeout: 10 minutes for standard, 15 for complex

Flags:

  • --sandbox read-only — codex can read all project files but cannot modify anything
  • -m gpt-5.5 — latest model (adjust as newer versions become available)
  • model_reasoning_effort="xhigh" — deepest reasoning tier
Show full SKILL.md (293 more words)Show less
Step 5: Present Results
  1. Extract codex's analysis — skip session info, token counts, prompt echo
  2. Parse structured output — for reviews, codex returns JSON; parse and present as structured findings
  3. Add your assessment — agree, disagree, or note caveats
  4. STOP and ask — do NOT apply any fixes or changes without explicit user approval

For investigation/debug responses (unstructured):

**Codex Analysis:**

[Codex's response — cleaned up and formatted]

---

**Assessment:** [Your 2-3 sentence evaluation]

**Proposed action:** [What codex suggests — awaiting approval]

For review responses (structured JSON):

Parse the JSON output and present findings sorted by severity, filtered by confidence:

**Codex Review: [verdict]**
[summary]

**Findings** (N issues):

1. **[critical]** title (confidence: 0.9)
   file.go:42-55
   [body]
   → [recommendation]

2. **[high]** title (confidence: 0.8)
   ...

**Next steps:** [list]

---

**Assessment:** [Your evaluation — which findings are valid, which are false positives]
  • skip findings with confidence < 0.3 (likely noise)
  • group by severity: critical → high → medium → low
  • if verdict is "approve" and no findings, just say "codex found no material issues"

CRITICAL: After presenting findings, STOP. Do not apply fixes, do not touch files, do not start implementing suggestions. Explicitly ask the user what to do next. Codex findings are input for discussion, not automatic work orders.

Important Rules

  • Read-only always — codex analyzes, we implement. Never let codex edit files.
  • Don't duplicate files — codex has full project access. Provide paths, not content.
  • Focused prompts — specific questions get better answers than broad "review everything".
  • Background execution — always run in background to avoid timeout issues.
  • One question at a time — if multiple concerns, run separate codex queries.
  • Critical thinking — codex can be wrong. Evaluate its suggestions before implementing.

When NOT to Use

  • Simple questions you already know the answer to
  • Tasks where the solution is clear and just needs implementation
  • File searches or codebase navigation (use Grep/Glob instead)

Troubleshooting

  • Codex not found: which codex — install via npm install -g @openai/codex
  • Authentication: codex login if getting auth errors
  • Timeout: increase stream_idle_timeout_ms for complex analyses
  • Off-target response: refine prompt with more specific file:line references
  • Hangs on "Reading additional input from stdin…": the invocation is missing the < /dev/null stdin redirect — add it (see Step 4).

© umputun, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/thinking-tools/skills/ask-codex of umputun/cc-thingz.

Open the folder on GitHubat commit 99e1c8d

Compare with similar skills

Ask Codex next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ask Codex compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ask Codex this skillumputun/cc-thingz484—~2.6kAutomated safety check: NotesMIT
Trellis Session Insightmindfold-ai/Trellis15k4 repos~1.7kAutomated safety check: PassAGPL-3.0
Native Data FetchingCherryHQ/cherry-studio-app4k6 repos~2.9kAutomated safety check: NotesMIT
Debugging Executionsn8n-io/n8n207k—~2.6kAutomated safety check: PassCustom licence
Aoti Debugpytorch/pytorch104k1 repos~1.7kAutomated safety check: PassCustom licence
Herdr Throwaway Reproductionherdrdev/herdr43k—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Trellis Session Insight

    mindfold-ai/Trellis

    Reach into past AI conversation history through the trellis mem CLI.

    15k GitHub starsUsed in 4 repos~1.7k tokens
    DevelopmentAuto-check passed
  • Native Data Fetching

    CherryHQ/cherry-studio-app

    A skill your agent uses when implementing or debugging ANY network request, API call, or data fetching.

    4k GitHub starsUsed in 6 repos~2.9k tokens
    DevelopmentAuto-check: notes
  • Official

    Debug failed or wrong-output workflow executions using executions tools.

    207k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Aoti Debug

    pytorch/pytorch

    Debug AOTInductor (AOTI) errors and crashes. An agent skill from pytorch/pytorch.

    104k GitHub starsUsed in 1 repo~1.7k tokens
    DevelopmentAuto-check passed
  • Runs a disposable, uniquely named Herdr session inside an existing one so runtime, pane, terminal or API bugs can be reproduced without touching the main session.

    43k GitHub stars~2.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Systematic Debugging

    ultralisp/ultralisp

    A skill your agent uses when encountering any bug, test failure, or unexpected behavior, before proposing fixes

    258 GitHub starsUsed in 51 repos~2.4k tokens
    DevelopmentAuto-check passed

More from umputun/cc-thingz

All 16 skills in this repo
  • Exec

    umputun/cc-thingz

    Execute plan tasks sequentially using subagents. An agent skill from umputun/cc-thingz.

    484 GitHub stars~8k tokensUpdated 2 days ago
    Auto-check passed
  • New

    umputun/cc-thingz

    A skill your agent uses when user asks to create a release, cut a release, or publish a version.

    484 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check: notes
  • Root Cause Investigator

    umputun/cc-thingz

    Systematic root cause analysis for errors, bugs, and unexpected behaviors using 5-Why methodology.

    484 GitHub stars~879 tokensUpdated 2 days ago
    Auto-check passed
  • Backlog

    umputun/cc-thingz

    Read, work, and maintain a Git repo's deferred-work items in docs/backlog/, one file per item.

    484 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check: notes
  • Brainstorm

    umputun/cc-thingz

    Use before any creative work or significant changes. An agent skill from umputun/cc-thingz.

    484 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check: notes
  • Clarify

    umputun/cc-thingz

    This skill should be used when user appears confused, frustrated, or shows misalignment between expectations and reality.

    484 GitHub stars~2.1k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Ask Codex

What does Ask Codex do?

Consult OpenAI Codex for investigation, debugging, or code review. Ask Codex is an agent skill from umputun/cc-thingz. Consult OpenAI Codex for investigation, debugging, or code review.

When should I use Ask Codex?

Ask Codex fits situations like: user explicitly asks to ask codex; check with codex; as a last resort when stuck after 4+ failed attempts at debugging; bug fix and completely out of ideas.

How do I install Ask Codex in Claude Code?

Run `npx skills add umputun/cc-thingz --skill ask-codex -a claude-code`. Or copy the skill folder (plugins/thinking-tools/skills/ask-codex in umputun/cc-thingz) into .claude/skills/ask-codex in your project. Claude Code loads it when a task matches its description.

How do I install Ask Codex in Codex?

Run `npx skills add umputun/cc-thingz --skill ask-codex -a codex`. Or copy the skill folder (plugins/thinking-tools/skills/ask-codex in umputun/cc-thingz) into .agents/skills/ask-codex in your project. Codex loads it when a task matches its description.

Can I use Ask Codex in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add umputun/cc-thingz --skill ask-codex -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ask-codex, .gemini/skills/ask-codex, .github/skills/ask-codex and .opencode/skills/ask-codex in your project.

What does Ask Codex need to run?

Going by SKILL.md and its folder, Ask Codex needs the command-line tools its instructions call (codex and npm). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash, Read, Grep, Glob.

Does Ask Codex access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ask Codex safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ask Codex use?

Ask Codex is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ask Codex use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ask Codex?

Skills that share tags, products or a category with Ask Codex: Trellis Session Insight (mindfold-ai/Trellis, 15k stars), Native Data Fetching (CherryHQ/cherry-studio-app, 4k stars), Debugging Executions (n8n-io/n8n, 207k stars) and Aoti Debug (pytorch/pytorch, 104k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ask Codex?

umputun (a GitHub user) maintains it in umputun/cc-thingz, which has 484 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 5, 2026.

Source: umputun/cc-thingz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.