Agent Setup Health Audit
tw93/Waza
Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.
Codex CLI artifact schemas: config.toml, .codex-plugin, skills, hooks, AGENTS.md.
$ npx skills add xiaolai/nlpm --skill conventions-codex -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install xiaolai/nlpm conventions-codex --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/nlpm/conventions-codex .claude/skills/conventions-codex && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "conventions-codex" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/conventions-codex into .claude/skills/conventions-codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-codex", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/conventions-codexType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add xiaolai/nlpm --skill conventions-codex -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install xiaolai/nlpm conventions-codex --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/nlpm/conventions-codex .agents/skills/conventions-codex && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "conventions-codex" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/conventions-codex into .agents/skills/conventions-codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-codex", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add xiaolai/nlpm --skill conventions-codex -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install xiaolai/nlpm conventions-codex --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/nlpm/conventions-codex .cursor/skills/conventions-codex && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "conventions-codex" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/conventions-codex into .cursor/skills/conventions-codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-codex", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/xiaolai/nlpm.git --path skills/nlpm/conventions-codex--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add xiaolai/nlpm --skill conventions-codex -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install xiaolai/nlpm conventions-codex --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/nlpm/conventions-codex .gemini/skills/conventions-codex && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "conventions-codex" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/conventions-codex into .gemini/skills/conventions-codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-codex", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install xiaolai/nlpm conventions-codexInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add xiaolai/nlpm --skill conventions-codex -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/nlpm/conventions-codex .github/skills/conventions-codex && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "conventions-codex" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/conventions-codex into .github/skills/conventions-codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-codex", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add xiaolai/nlpm --skill conventions-codex -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install xiaolai/nlpm conventions-codex --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xiaolai/nlpm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/nlpm/conventions-codex .opencode/skills/conventions-codex && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "conventions-codex" agent skill from https://github.com/xiaolai/nlpm/tree/main/skills/nlpm/conventions-codex into .opencode/skills/conventions-codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "conventions-codex", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
conventions-codexCodex CLI artifact schemas: config.toml, .codex-plugin, skills, hooks, AGENTS.md.
Conventions Codex is an agent skill from xiaolai/nlpm. Codex CLI artifact schemas: config.toml, .codex-plugin, skills, hooks, AGENTS.md.
Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering Hooks and plugins and Agent instruction files. The repository describes itself as: Natural-Language Programming Manager — scan, lint, and score NL artifacts with Claude-native quality scoring. The licence is ISC.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6fdbd05. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
codexFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.chatgpt.comgithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CODEX_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Conventions Codex loads about 4.9k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 2,021 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from xiaolai/nlpm at commit 6fdbd05, republished under its ISC licence (© xiaolai). 2,021 words, ~4,858 tokens.
.claude/skills/conventions-codex/SKILL.md (or your agent's skills folder).Tool-specific overlay for OpenAI Codex CLI artifacts. Loaded by the scorer and checker when an artifact is classified as Tier 2-Codex (per agents/scorer.md step 3). The universal floor lives in nlpm:conventions; this overlay adds Codex-specific schemas on top.
Last refreshed: 2026-08-02 against Codex 0.146.0 (2026-07-29); §3/§4 field-type + policy-enum corrections 2026-08-04; §3 artifact-path, commands and symlink corrections 2026-10-01, observed on Codex 0.159.2.
Primary authoritative sources:
developers.openai.com/codex/* tree now 308-redirects here)CLA.md, contributing.md, and machine-readable spec samples like plugin-json-spec.md)Codex separates the cross-tool surface (.agents/) from the Codex-private surface (.codex/). The Claude Code mental model of "everything under one tool directory" does not transfer.
| Artifact | Project scope | User scope |
|---|---|---|
| Skills | .agents/skills/<name>/SKILL.md (CWD→repo-root scan) | ~/.agents/skills/, admin /etc/codex/skills/ |
| Plugin manifest | <plugin-root>/.codex-plugin/plugin.json | — |
| Marketplace | .agents/plugins/marketplace.json (+ legacy .claude-plugin/marketplace.json) | ~/.agents/plugins/marketplace.json |
| AGENTS.md | Git root → CWD; per dir AGENTS.override.md → AGENTS.md → fallback (one file/dir; closer overrides earlier) | ~/.codex/AGENTS.override.md, ~/.codex/AGENTS.md |
| Config | .codex/config.toml (trust-gated) | ~/.codex/config.toml |
| Hooks | .codex/hooks.json OR inline [hooks] in config.toml | ~/.codex/hooks.json |
| Slash commands / prompts | — (not project-shareable) | ~/.codex/prompts/<name>.md |
| MCP servers | [mcp_servers.<id>] table inside config.toml | same |
| Skill sidecar (Codex-specific) | <skill>/agents/openai.yaml next to SKILL.md | — |
Trust gate: Project hooks load only when .codex/ is trusted. Trust is enforced via /hooks and allow_managed_hooks_only in requirements.toml.
name, description required only)Codex reads SKILL.md from .agents/skills/, not .codex/skills/ (reconfirmed 2026-08-02 against build-skills: "Codex reads skills from .agents/skills directories, not .codex/skills"; it scans .agents/skills from CWD up to the repo root, plus ~/.agents/skills and /etc/codex/skills). Skills placed under .codex/skills/ — a common mistake in repos ported from Claude Code's .claude/skills/ habit — are not discovered by Codex; flag them. The required frontmatter is the agentskills.io baseline — name and description — same as every other tool.
Codex-specific extras live in a SIDECAR agents/openai.yaml, not in SKILL.md frontmatter. Treat the sidecar as additive metadata, not a deviation from the open spec.
Sidecar fields:
# <skill>/agents/openai.yaml
interface:
display_name: "My Skill"
short_description: "One-line summary" # added 2026-06
default_prompt: "Use this skill when..."
icon_small: "icon-16.png"
icon_large: "icon-512.png" # added 2026-06
brand_color: "#FF6B00"
policy:
allow_implicit_invocation: true # default true; set false to disable auto-selection
dependencies:
tools:
- type: "bash"
value: "jq"
description: "JSON processor"
transport: "stdio"Correction (2026-06-07): dependencies.tools is an array of tool objects (type, value, description, transport), not a bare string list. The v0.1.0 - bash / - jq form was wrong.
Duplicate-name skills across scopes are NOT merged — both appear in selectors, repo-level wins for local workflows.
.codex-plugin/plugin.json (plugin manifest){
"name": "my-codex-plugin",
"version": "1.0.0",
"description": "Short summary",
"skills": "./skills/",
"mcpServers": "./mcp/servers.json",
"apps": "./apps/",
"hooks": "./hooks.json",
"commands": [],
"interface": {
"displayName": "My Plugin",
"longDescription": "Detailed description for installer UI"
}
}Required field: name (kebab-case) — and only when a plugin.json is present at all. All other top-level fields are optional, including version, description, author, and interface (corrected 2026-08-02 against the vendor's plugin-json-spec.md; the earlier "version + description required" claim was wrong). Codex 0.159.2 installs a plugin whose manifest lacks name but loads none of its skills, so a missing name fails silently.
Optional artifact paths — each a relative-path STRING (corrected 2026-08-04 against the vendor plugin-json-spec.md): skills (string), hooks (string), apps (string), mcpServers (string or object). A bare directory string like "skills": "./skills/" is the documented sample form. Do NOT flag a scalar-string skills/hooks/apps/mcpServers as wrong. (The v0.3.0 overlay showed only an array form; Codex 0.159.2 also accepts a one-element array for skills, but the string is the documented form.)
Optional identity fields (added 2026-06): author ({name, email, url}), homepage, repository, license, keywords.
Optional UI block interface:
displayName, shortDescription, longDescription, developerName, category, capabilitiesdefaultPrompt — an array of starter prompts (not a single string). At most 3 entries (extras ignored); each capped at 128 characters (longer entries truncated).websiteURL, privacyPolicyURL, termsOfServiceURLbrandColor, composerIcon, logo, logoDark (dark-mode logo variant), screenshots (PNG files stored under ./assets/, paths relative to plugin root)Notation: $+ARGUMENTS and $+{CLAUDE_PLUGIN_ROOT} in this file are split by a + so Claude Code does not replace them when it loads this skill; the real tokens have no + (nlpm:conventions-claude §2.4).
A manifest path REPLACES the default location; it does not add to it (observed on Codex 0.159.2 on 2026-10-01 through the app-server skills/list and hooks/list methods; this corrects the earlier "paths supplement default discovery" claim):
skills — with no skills key, Codex loads the plugin-root skills/ directory. With "skills": "./codex/skills/", root skills/ is not loaded.hooks — with no hooks key, Codex loads the plugin-root hooks/hooks.json, including a Claude Code plugin's hooks file (it expands $+{CLAUDE_PLUGIN_ROOT} there). With "hooks": "./codex/hooks.json", the root file is not loaded. To keep a plugin's Claude hooks out of Codex, point hooks at a file holding {"hooks": {}}.apps, mcpServers — replacement vs. addition not verified this pass."commands": [] stops Codex turning a plugin's Claude Code commands/*.md into extra skills. Without it, Codex 0.159.2 converts commands into skills named source-command-<command> (written under .codex-plugin/migrated-command-skills/ in the installed copy), which duplicate a Codex port's own skills. It converts only some commands (commands whose body uses $+ARGUMENTS were skipped in testing, and a few without it were too), so the duplicates are easy to miss. A plugin that ships a Claude commands/ directory alongside a Codex skill tree should set "commands": []; do NOT flag the key as unknown.
A symlinked skill directory is dropped on install (Codex 0.159.2, local and Git marketplace sources alike): the installed copy omits it, so the skill never loads. Ship real directories in a Codex skill tree.
.agents/plugins/marketplace.json (marketplace manifest)Three marketplace tiers exist in Codex:
<repo-root>/.agents/plugins/marketplace.json aggregates plugins shipped from that repo.~/.agents/plugins/marketplace.json.Schema:
{
"name": "xiaolai",
"interface": {
"displayName": "xiaolai Marketplace"
},
"plugins": [
{
"name": "nlpm",
"source": {
"source": "github",
"repo": "xiaolai/nlpm"
},
"policy": {
"installation": "AVAILABLE",
"authentication": "ON_USE"
},
"category": "developer-tools",
"interface": {
"displayName": "nlpm"
}
}
]
}Per-plugin source types: "github", "git", "local".
policy values are UPPERCASE enums (corrected 2026-08-04 against nlpm's own shipping .agents/plugins/marketplace.json and observed real plugins): installation e.g. "AVAILABLE"; authentication e.g. "ON_USE" or "ON_INSTALL". The lowercase "auto"/"none" the v0.3.0 overlay showed was wrong — do NOT flag AVAILABLE/ON_USE/ON_INSTALL as invalid.
.codex/config.tomlTOML — NOT JSON. Top-level sections nlpm cares about:
[features] — feature flags. Breaking change ~2026-04 (CLI 0.129+): [features].codex_hooks was renamed to [features].hooks (boolean; enables hooks from hooks.json or inline [hooks]). Old key is a deprecated alias and emits a warning. Flag config files that still use codex_hooks.[mcp_servers.<id>] — MCP server registrations. Fields: command, args, cwd, url, enabled, enabled_tools, disabled_tools, env, startup_timeout_sec, tool_timeout_sec (per-tool, default 60s — added 2026-06).[hooks.<event>] — inline hook registrations (alternative to .codex/hooks.json).[agents] — global subagent settings ONLY: enabled, max_concurrent_threads_per_session, default_subagent_model, default_subagent_reasoning_effort, interrupt_message. Individual subagents are not [agents.<name>] tables — they are standalone TOML files at .codex/agents/*.toml (project) or ~/.codex/agents/*.toml (personal), one file per agent, with required name + description + developer_instructions and optional model, model_reasoning_effort, sandbox_mode, mcp_servers, skills.config (corrected 2026-08-02 — the old [agents.<name>] / config_file / nickname_candidates schema is gone).[permissions.*] — permission policy.project_doc_max_bytes, project_doc_fallback_filenames — AGENTS.md controls (see §7).REMOVED — [profiles.*] table syntax is gone as of 0.134.0 (2026-05-26). Profiles now live in dedicated per-profile files ~/.codex/<name>.config.toml, selected with --profile <name>. A config still using [profiles.foo] tables is stale — flag it.
No .mcp.json at repo root. Codex does NOT read Claude's .mcp.json — MCP servers live inside config.toml. A bridge from .mcp.json → .codex/config.toml is a common port pattern (see cc-suite:bridge-mcp skill).
Codex hooks mostly mirror Claude Code's event names — easier than the Antigravity divergence.
| Event | In Claude? | In Antigravity? | Notes |
|---|---|---|---|
SessionStart | yes | yes | — |
UserPromptSubmit | yes | — | — |
PreToolUse | yes | — (different model) | — |
PostToolUse | yes | — | — |
PermissionRequest | yes | — | — |
PreCompact | yes | — (uses PreCompress) | — |
PostCompact | yes | — | Claude added PostCompact in its 2026-06 hook set (see conventions-claude §7) |
SubagentStart | yes | — | In Claude too (2026-06 hook set); Codex added it 2026-05-21 in 0.133.0 |
SubagentStop | yes | — | — |
Stop | yes | — | — |
SessionEnd | yes | — | Real Codex event (confirmed 2026-08-02): fires on archive/delete of a still-open conversation, normal Codex close, or after ~30-min idle with no connected client; 1s default timeout (max 3s); advisory-only (output does not steer Codex) |
Absent in Codex (but present in Claude): Notification, FileChanged, StopFailure.
Hook I/O contract: Same JSON-on-stdin / JSON-on-stdout shape as Claude. Stdin: session_id, cwd, hook_event_name, tool_name, tool_input, etc. Stdout fields: continue, stopReason, systemMessage, suppressOutput, hookSpecificOutput. Exit codes: 0 + JSON = success with directives; 0 + plain text = added as context; 2 = block (reason to stderr); other = warning.
Caveats (added 2026-06):
SubagentStart / SubagentStop hook inputs now carry subagent identity, including permission_mode (0.134.0).SubagentStart, continue: false does not stop the subagent.Codex reads AGENTS.md before every turn. Files are concatenated root-down, joined by blank lines; files closer to CWD override earlier ones by position (there is no separate global/project boundary marker — it is pure positional override). Within each directory the search order is AGENTS.override.md → AGENTS.md → fallback filenames, and at most one file per directory is taken; the walk stops at CWD. Global layer: ~/.codex/AGENTS.override.md → ~/.codex/AGENTS.md.
Default cap: 32 KiB per file (project_doc_max_bytes in config.toml).
Fallback filenames: Configurable via project_doc_fallback_filenames — this is the official hook for AGENTS.md / CLAUDE.md / GEMINI.md interop (set the array to include all three to make Codex read whichever exists).
Body conventions (not enforced, but common):
## Working agreements — high-level decisions## Repository expectations — invariants@file.md imports are NOT supported (unlike Gemini's GEMINI.md hierarchy) — use file concatenation instead.The nlpm pattern of CLAUDE.md → one line @AGENTS.md does NOT work for Codex (no @-import). Codex authors should put content directly in AGENTS.md and configure Claude Code's CLAUDE.md to import it instead.
Codex's slash-command / prompt format lives at ~/.codex/prompts/<name>.md (project form .codex/prompts/). The "deprecated in favor of skills" framing is not confirmed in current docs (2026-06-07) — prompts are still documented. nlpm should NOT penalize their presence, and should treat any migration recommendation as advisory/soft rather than asserting deprecation.
Placeholders if scoring legacy prompts: $1..$9, $+ARGUMENTS, $FILE, $TICKET_ID, $$.
| Date | Version | Change |
|---|---|---|
| 2026-03-26 | — | Plugin marketplace launched. New artifact class. |
| ~2026-04 | 0.129.0 | [features].codex_hooks renamed to [features].hooks (deprecation warning) |
| 2026-05-18 | 0.131.0 | Plugin hooks enabled by default; legacy shell tools + built-in MCPs removed; codex doctor added |
| 2026-05-21 | 0.133.0 | Goals enabled by default; SubagentStart event observable by hooks |
| 2026-05-26 | 0.134.0 | [profiles.*] table syntax dropped → per-profile files ~/.codex/<name>.config.toml (--profile); MCP OAuth for HTTP servers + per-server env; read-only MCP tools run concurrently (readOnlyHint); subagent identity in hook inputs |
| 2026-05-28 | 0.135.0 | /permissions understands named permission profiles; expanded codex doctor diagnostics; CODEX_NON_INTERACTIVE=1 |
| 2026-06-01 | 0.136.0 | Session archive (/archive, codex archive/unarchive); CODEX_API_KEY remote-exec registration; 4 security fixes |
| 2026-06-04 | 0.137.0 | codex plugin list --json; Multi-agent v2 per-thread runtime persistence; plugin skill manifest validation improvements; cloud-managed config bundles |
| 2026-07-21 | 0.145.0 | Paginated thread history (experimental); /import migrates Cursor + Claude Code settings/MCP/plugins/sessions/commands/memories; experimental Amazon Bedrock auth; audio I/O; multi-agent V2 stabilized (opt-in) |
| 2026-07-29 | 0.146.0 | Session naming/pinning + thread switching; Agent Plugins manifests + workspace plugin publishing + additional marketplaces (Amazon Bedrock, Claude Code); paginated thread forks; discovery of executor-provided skills (a non-filesystem skill source §1 doesn't cover) |
Latest stable as of 2026-08-02: 0.146.0 (2026-07-29); pre-releases through ~0.147.0-alpha (verify the exact tag before quoting). Versions 0.138.0–0.144.x are omitted here — only non-first-party aggregators carried them this refresh; add rows once a first-party changelog source is read.
Repos relying on the removed built-in MCPs will silently regress under 0.131+. nlpm should flag MCP configs that name MCPs no longer shipped natively. Configs using [profiles.*] tables are stale under 0.134+.
This skill covers Codex CLI conventions. It does NOT cover:
nlpm:conventionsnlpm:scoringagents/checker.mdResolved in the 2026-08-02 refresh:
plugin.json required fields — only name is required; version/description/author/interface are optional (§3)..codex/agents/*.toml files, not [agents.<name>] tables (§5).SessionEnd is a real Codex hook event (§6)..agents/skills/ (not .codex/skills/) reconfirmed as the sole filesystem skill-discovery path (§2).openai/codex itself: external contributions are by invitation only — unsolicited PRs are closed without review; invited contributors sign a lightweight bot-verified CLA via a PR comment. This governs the openai/codex repo only, NOT third-party repos that merely target Codex as a tool (the auditor's actual PR targets). If PR-D ever contributes to openai/codex directly it needs an invite-only DENY-style gate, not the Google URL-CLA flow.Resolved in the 2026-06-07 refresh:
child_agents_md feature flag — not found in any current doc. Treat as removed/never-shipped; do not score against it.Still open (verify before scoring with confidence):
.app.json schema for the plugin apps field — documented but the full schema is still unpublished.agents/openai.yaml dependencies.tools[].url field — seen once in build-skills, not cleanly re-confirmed; do not hard-flag its presence or absence yet.© xiaolai, ISC. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/nlpm/conventions-codex of xiaolai/nlpm.
Open the folder on GitHubat commit 6fdbd05
Conventions Codex next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Conventions Codex this skillxiaolai/nlpm | 146 | — | ~4.9k | Automated safety check: Pass | ISC | |
| Agent Setup Health Audittw93/Waza | 7.2k | — | ~5.2k | Automated safety check: Notes | MIT | |
| Working With Claude Code Docsobra/superpowers-developing-for-claude-code | 142 | — | ~1.5k | Automated safety check: Pass | None | |
| Directional Promptingkingbootoshi/directional-prompting | 143 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Agenticashibing624/agentica | 352 | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | |
| Claude Code Mastery Squadohmyjahh/xquads-squads | 276 | — | ~1.1k | Automated safety check: Pass | MIT |
tw93/Waza
Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.
obra/superpowers-developing-for-claude-code
Looks up official Claude Code documentation stored as reference files instead of guessing about CLI commands, configuration, or plugin APIs.
kingbootoshi/directional-prompting
Write prompts, system instructions, agent directives, slash commands, and skill descriptions using two stacked layers — outcome-first (define the destination, success criteria, stopping condition)…
shibing624/agentica
How to answer questions about the agentica product you are running inside — CLI flags, config.yaml profiles, API keys, models, sessions, resume, workspace, AGENTS.md standing rules, skills, logs…
ohmyjahh/xquads-squads
Routes a request to one of eight specialist agents covering hooks, skills, subagents, MCP integration and context engineering for Claude Code.
earlyaidopters/second-brain
Interactive Obsidian vault configurator. An agent skill from earlyaidopters/second-brain.
xiaolai/nlpm
Universal NL conventions: SKILL.md open spec, AGENTS.md, vague quantifiers, naming.
xiaolai/nlpm
Antigravity and Gemini CLI artifact schemas: .gemini/ paths, extensions, hooks.
xiaolai/nlpm
Multi-agent workflow patterns: parallel dispatch, pipelines, QC gates, retries.
xiaolai/nlpm
NL artifact anti-patterns: vague quantifiers, bare prohibitions, oversized skills.
xiaolai/nlpm
100-point NL artifact rubric: penalty tables per artifact type, calibration cases.
xiaolai/nlpm
NL artifact test specs for /nlpm:test: spec format, TDD for skills and agents.
Categories
Codex CLI artifact schemas: config.toml, .codex-plugin, skills, hooks, AGENTS.md. Conventions Codex is an agent skill from xiaolai/nlpm.md.
Conventions Codex fits situations like: tasks that involve Hooks and plugins; tasks that involve Agent instruction files.
Run `npx skills add xiaolai/nlpm --skill conventions-codex -a claude-code`. Or copy the skill folder (skills/nlpm/conventions-codex in xiaolai/nlpm) into .claude/skills/conventions-codex in your project. Claude Code loads it when a task matches its description.
Run `npx skills add xiaolai/nlpm --skill conventions-codex -a codex`. Or copy the skill folder (skills/nlpm/conventions-codex in xiaolai/nlpm) into .agents/skills/conventions-codex in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xiaolai/nlpm --skill conventions-codex -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/conventions-codex, .gemini/skills/conventions-codex, .github/skills/conventions-codex and .opencode/skills/conventions-codex in your project.
Going by SKILL.md and its folder, Conventions Codex needs the command-line tools its instructions call (codex) and credentials named CODEX_API_KEY.
SKILL.md names 2 domains. As links in the text: learn.chatgpt.com and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Conventions Codex is published under the ISC licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Conventions Codex: Agent Setup Health Audit (tw93/Waza, 7.2k stars), Working With Claude Code Docs (obra/superpowers-developing-for-claude-code, 142 stars), Directional Prompting (kingbootoshi/directional-prompting, 143 stars) and Agentica (shibing624/agentica, 352 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
xiaolai (a GitHub user) maintains it in xiaolai/nlpm, which has 146 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 8, 2026.
Source: xiaolai/nlpm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.