Agent skill

Headless Codex CLI Automation

by XiaomiMiMo in XiaomiMiMo/MiMo-Code

Runs OpenAI Codex CLI as a non-interactive worker for CI, Docker, Kubernetes or remote servers, with sandbox modes and JSONL-friendly output.

MITAuto-check passedDevOps & Cloud

Install Headless Codex CLI Automation

skills CLI
$ npx skills add XiaomiMiMo/MiMo-Code --skill codex -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install XiaomiMiMo/MiMo-Code codex --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/XiaomiMiMo/MiMo-Code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/cli/src/skill/builtin/.bundle/codex .claude/skills/codex && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codex
GitHub stars
14k
Token cost
~2.7k tokens
SKILL.md length
1,019 words
Files
4 (incl. references)
Skills in repo
22
Repo updated
First seen
Licence
MIT

At a glance

Runs OpenAI Codex CLI as a non-interactive worker for CI, Docker, Kubernetes or remote servers, with sandbox modes and JSONL-friendly output.

  • Works in 9 steps: Use codex exec, not the interactive… → Pass the task as the positional PROMPT… → For ordinary unattended code changes,… → …
  • Running Codex CLI unattended inside a CI pipeline
  • SKILL.md covers Operating Rules, Choose the Execution Mode, Construct an Autonomous Prompt and Handle request_user_input…, plus 9 more sections
  • Calls codex and npm; needs CODEX_API_KEY and OPENAI_API_KEY

What it does

The guidance is to use `codex exec` rather than the interactive TUI, pass the task as the positional prompt argument, and for ordinary unattended changes run it with a workspace-write sandbox. For harnesses and CI it prefers `--json` plus `--output-last-message`, and treats the run as something that must never depend on a human answering a question, resolving ambiguity from repository evidence and conservative defaults instead.

Three execution modes are named: read-only analysis when files must not change, workspace-scoped implementation as the default for autonomous repository work, and an externally isolated unrestricted mode using `--yolo`, which disables approvals and sandboxing and is only safe inside a container or VM that enforces its own security boundary, never on a machine with host secrets, SSH keys or a Docker socket nearby. On Windows it calls for picking one execution environment, native PowerShell or WSL2, per task rather than mixing them.

When your agent uses it

  • Running Codex CLI unattended inside a CI pipeline
  • Automating Codex inside a Docker or Kubernetes job
  • Choosing a sandbox and approval mode for a headless Codex run
  • Recovering from a Codex run stuck waiting on user input

Example prompts

  • “Set up a read-only Codex exec command to review this repo for a CI check.”
  • “Write a workspace-write Codex exec call that won't stop for approval prompts.”
  • “Why does my Codex job hang waiting for input inside Kubernetes?”

Requirements

  • OpenAI Codex CLI

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Use codex exec, not the interactive codex TUI.
  2. Pass the task as the positional PROMPT argument. Do not use -p for the prompt; -p selects a profile.
  3. For ordinary unattended code changes, prefer
  4. Use --yolo only inside an externally hardened and disposable runner. It disables Codex approvals and sandboxing.
  5. For harnesses and CI, prefer --json plus --output-last-message.
  6. Do not make the run depend on a human answering questions. Resolve ambiguity using repository evidence and conservative defaults.
  7. Treat credentials as secrets. Inject CODEX_API_KEY only into the single codex exec process when possible.
  8. Before giving version-sensitive advice, inspect codex exec --help or current official Codex documentation if available.
  9. On Windows, choose one execution environment per task: native PowerShell for Windows toolchains or WSL2 for Linux toolchains. Do not…

What it can do on your machine

Read from SKILL.md and the folder at commit 6babeb0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • codex
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CODEX_API_KEY
    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Headless Codex CLI Automation loads about 2.7k tokens when it runs, and up to ~7.4k if it reads all its reference files. Until then it costs about 131 tokens; SKILL.md has 1,019 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from XiaomiMiMo/MiMo-Code at commit 6babeb0, republished under its MIT licence (© XiaomiMiMo). 1,019 words, ~2,683 tokens.

Download SKILL.mdSave it as .claude/skills/codex/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
codex
description
Run, configure, and troubleshoot OpenAI Codex CLI in non-interactive headless environments. Use for Codex automation in Bash or PowerShell, native Windows or WSL2, shell scripts, CI/CD, Docker, Kubernetes, remote servers, agent harnesses, or batch jobs; for constructing `codex exec` commands; selecting sandbox and approval modes; consuming JSONL events or structured output; resuming sessions; passing prompts through stdin; and handling failures caused by unavailable interactive input such as `request_user_input`.

Codex CLI

Use Codex CLI as a deterministic, non-interactive worker suitable for automation and agent orchestration.

Operating Rules

  1. Use codex exec, not the interactive codex TUI.
  2. Pass the task as the positional PROMPT argument. Do not use -p for the prompt; -p selects a profile.
  3. For ordinary unattended code changes, prefer:
bash
codex exec \
  -C /path/to/repo \
  --sandbox workspace-write \
  --ask-for-approval never \
  "<TASK>"
  1. Use --yolo only inside an externally hardened and disposable runner. It disables Codex approvals and sandboxing.
  2. For harnesses and CI, prefer --json plus --output-last-message.
  3. Do not make the run depend on a human answering questions. Resolve ambiguity using repository evidence and conservative defaults.
  4. Treat credentials as secrets. Inject CODEX_API_KEY only into the single codex exec process when possible.
  5. Before giving version-sensitive advice, inspect codex exec --help or current official Codex documentation if available.
  6. On Windows, choose one execution environment per task: native PowerShell for Windows toolchains or WSL2 for Linux toolchains. Do not casually mix paths, installations, or authentication across them.

Choose the Execution Mode

Read-only analysis

Use when the task must not modify files:

bash
codex exec \
  -C /path/to/repo \
  --sandbox read-only \
  --ask-for-approval never \
  "Analyze the repository and report risks. Do not modify files."
Workspace-scoped implementation

Use as the default for autonomous repository work:

bash
codex exec \
  -C /path/to/repo \
  --sandbox workspace-write \
  --ask-for-approval never \
  "Implement the task, run relevant tests, and report unresolved blockers."
Externally isolated unrestricted execution

Use only when the enclosing container, VM, or sandbox enforces the real security boundary:

bash
codex exec \
  -C /workspace/repo \
  --yolo \
  "Implement the task and validate the result."

Never recommend --yolo on a normal developer machine or a runner containing unrelated secrets, host mounts, SSH keys, cloud credentials, or a Docker socket.

Construct an Autonomous Prompt

When headless execution could encounter choices, prepend these instructions:

text
Work fully autonomously.

Do not ask the user questions and do not request interactive input.
Inspect the repository and available context before making assumptions.
When several valid approaches exist, choose the option that:
1. minimizes unrelated changes,
2. preserves backward compatibility,
3. introduces the fewest new dependencies,
4. avoids destructive or irreversible actions.

Continue until the task is complete or a concrete blocking error is reached.
Record assumptions, validation performed, and unresolved blockers in the final response.

Do not simulate "always select the first option." Option ordering is not a safety or quality policy. Apply the explicit decision rules above instead.

Handle request_user_input Failures

When Codex reports that request_user_input is unavailable in Default mode or non-interactive mode:

  1. Confirm the invocation uses codex exec and is intentionally headless.
  2. Add the autonomous prompt policy above.
  3. Supply missing decisions in the task prompt or AGENTS.md when they are known in advance.
  4. Replace open-ended requests such as "ask me which approach" with deterministic selection criteria.
  5. If the choice is safety-critical, destructive, or impossible to infer, make the run fail clearly rather than selecting randomly.
  6. Do not attempt to emulate terminal keystrokes unless the subprocess itself, rather than Codex, requires input and the workflow explicitly defines the safe answer.

Pass Prompts and Context

Use a direct positional prompt:

bash
codex exec "Summarize the repository structure."

Read the prompt from stdin:

bash
codex exec - < prompt.md

Pipe dynamic context while retaining an explicit task:

bash
npm test 2>&1 | codex exec "Analyze this test output and fix the repository."

Use --skip-git-repo-check only for intentional one-off directories outside Git:

bash
codex exec \
  --skip-git-repo-check \
  -C /tmp/task \
  "Analyze the files in this directory."

Produce Harness-Friendly Output

Capture only the final message
bash
codex exec \
  -C /workspace/repo \
  --output-last-message /output/final.md \
  "Review the codebase."
Stream JSONL events
bash
codex exec \
  -C /workspace/repo \
  --json \
  --sandbox workspace-write \
  --ask-for-approval never \
  "Run tests and fix failures." \
  > /output/events.jsonl

Expect event families such as thread.started, turn.started, turn.completed, turn.failed, item.*, and error.

Capture events and the final answer together
bash
codex exec \
  -C /workspace/repo \
  --json \
  --sandbox workspace-write \
  --ask-for-approval never \
  --output-last-message /output/final.md \
  "Complete the task autonomously." \
  | tee /output/events.jsonl

Do not parse human-readable progress text when --json is available.

Require Structured Final Output

Create a JSON Schema and pass it with --output-schema:

bash
codex exec \
  -C /workspace/repo \
  --sandbox workspace-write \
  --ask-for-approval never \
  --output-schema /input/result.schema.json \
  --output-last-message /output/result.json \
  "Implement the task, validate it, and return the requested structured result."

A useful harness schema usually includes:

  • status: success, partial, or failed
  • summary: concise outcome
  • changed_files: repository-relative paths
  • validation: commands run and results
  • assumptions: decisions made without user input
  • blockers: concrete unresolved problems

Set additionalProperties to false when downstream parsing must be strict.

Resume or Avoid Persistence

Resume the most recent session for the current working directory:

bash
codex exec resume --last "Continue the previous task and fix remaining issues."

Resume a specific session:

bash
codex exec resume "$SESSION_ID" "Continue with the next stage."

Use an ephemeral run when rollout persistence is undesirable:

bash
codex exec --ephemeral "Analyze the repository."

Do not rely on --last across unrelated working directories unless deliberately using the relevant all-directory option supported by the installed CLI.

Authenticate Safely

For a local interactive login:

bash
codex login

For a headless machine with device-code login enabled:

bash
codex login --device-auth

For a single automated invocation:

bash
CODEX_API_KEY="$OPENAI_API_KEY" \
codex exec --json "Triage the repository."

Do not expose API keys as broad job-level environment variables in jobs that execute repository-controlled code. Never commit or print ~/.codex/auth.json.

Show full SKILL.md (431 more words)Show less

Windows, PowerShell, and WSL2

For native Windows headless use:

  • Install with the official PowerShell installer or npm.
  • Prefer PowerShell 7.4 or newer for JSONL redirection.
  • Build argument arrays and invoke them with & codex @args; avoid fragile backtick-heavy command construction.
  • Check $LASTEXITCODE after every Codex invocation. PowerShell error preferences alone are not a substitute for checking a native process exit code.
  • Keep stdout JSONL separate from stderr diagnostics. Do not use 2>&1 when stdout must remain parseable JSONL.
  • Configure %USERPROFILE%\.codex\config.toml with [windows] sandbox = "elevated" when available; use unelevated only as the fallback.
  • Preserve the task-level policy --sandbox workspace-write --ask-for-approval never for ordinary autonomous edits. The native Windows sandbox implementation and the CLI task policy are separate controls.

For WSL:

  • Use WSL2, not WSL1.
  • Install and authenticate Codex inside WSL as a Linux installation.
  • Keep repositories under ~/code/..., not /mnt/c/..., for better performance and fewer permission, symlink, and file-watcher problems.
  • Do not pass credentials through visible wsl.exe command-line strings.

See references/windows.md for installation, PowerShell wrappers, JSONL parsing, sandbox configuration, WSL2 patterns, and Windows-specific troubleshooting.

Container and CI Requirements

When generating a Docker, Kubernetes, or CI design:

  • Mount only the intended workspace and output directory.
  • Run as a non-root user when practical.
  • Do not mount the host Docker socket.
  • Do not mount home directories, SSH keys, or cloud credential directories.
  • Restrict network access unless the task explicitly needs it.
  • Apply CPU, memory, process, and execution-time limits outside Codex.
  • Preserve stdout, stderr, exit status, JSONL events, and the final message separately.
  • Validate repository diffs and test results before treating a run as successful.
  • Prefer a fresh worktree or disposable checkout per task.

See references/recipes.md for ready-to-use shell, Docker, CI, and parser patterns.

Diagnose Failures

Use this order:

  1. Run codex --version and codex exec --help.
  2. Verify the command uses a positional prompt or - for stdin.
  3. Verify the working directory and Git repository status.
  4. Verify authentication without printing secret material.
  5. Check whether sandbox policy blocks required reads, writes, commands, sockets, or network access.
  6. Check whether approval policy is causing an impossible prompt in headless mode.
  7. Inspect stderr and the JSONL error or turn.failed events.
  8. Re-run with a smaller, deterministic task that reproduces the failure.
  9. Do not silently switch to --yolo as a troubleshooting shortcut.

Completion Standard

For implementation tasks, consider the run complete only when Codex has:

  1. inspected the relevant repository context,
  2. made the requested changes,
  3. run the most relevant available validation,
  4. reviewed the resulting diff for unrelated changes,
  5. reported assumptions and unresolved blockers,
  6. produced machine-readable status when requested by the harness.

© XiaomiMiMo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in packages/cli/src/skill/builtin/.bundle/codex of XiaomiMiMo/MiMo-Code.

  • SKILL.md
  • agents/openai.yaml
  • references/recipes.md
  • references/windows.md

Open the folder on GitHubat commit 6babeb0

Compare with similar skills

Headless Codex CLI Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Headless Codex CLI Automation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Headless Codex CLI Automation this skillXiaomiMiMo/MiMo-Code14k—~2.7kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Rtk Skillsopaco/deepwiki-rs3.1k—~1.4kAutomated safety check: PassMIT
Docker Via WslJMBeresford/retrom2.1k—~832Automated safety check: PassMIT
Data Processingaiskillstore/marketplace4301 repos~720Automated safety check: NotesMIT
Educates Upgrade Goeducates/educates-training-platform161—~1.4kAutomated safety check: NotesApache-2.0

Similar skills

  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Rtk Skill

    sopaco/deepwiki-rs

    A skill your agent uses when running shell commands that produce verbose output (git, test, build, lint, package managers, docker).

    3.1k GitHub stars~1.4k tokensUpdated 23 days ago
    DevOps & CloudAuto-check passed
  • Docker Via Wsl

    JMBeresford/retrom

    A skill your agent uses when YOU (the AI agent) are running on Windows OUTSIDE WSL (Git Bash/MSYS/PowerShell shell) and need to run ANY docker / docker compose command.

    2.1k GitHub stars~832 tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    DevOps & CloudAuto-check: notes
  • Educates Upgrade Go

    educates/educates-training-platform

    Upgrade the Go version across the entire educates-training-platform project.

    161 GitHub stars~1.4k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • CI/CD Pipeline Principles

    irahardianto/awesome-agv

    Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.

    157 GitHub stars~2.7k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes

More from XiaomiMiMo/MiMo-Code

All 22 skills in this repo
  • Paper Research on arXiv

    XiaomiMiMo/MiMo-Code

    Searches arXiv, fetches metadata, generates BibTeX, downloads PDFs and finds citations and related papers using a bundled Python script.

    14k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Agent Skill Creator

    XiaomiMiMo/MiMo-Code

    Interactive guide for creating, reviewing and fixing agent skills (SKILL.md folders), covering structure, frontmatter rules, trigger phrases and validation before sharing.

    14k GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • DOCX Toolkit

    XiaomiMiMo/MiMo-Code

    Produces, edits and reads Microsoft Word files through python-docx and lxml, with a decision table for picking the lightest workflow for a given task.

    14k GitHub stars~2.4k tokensUpdated 4 days ago
    Auto-check passed
  • Drive MiMo Code

    XiaomiMiMo/MiMo-Code

    Lets one MiMoCode process drive another, headless with JSON events or interactively through tmux, to test behavior and visual regressions with parseable evidence.

    14k GitHub stars~3.9k tokensUpdated 4 days ago
    Auto-check passed
  • PDF Toolkit

    XiaomiMiMo/MiMo-Code

    Reads, transforms, composes and fills PDFs with Python scripts for extraction, merging, watermarking, encryption, OCR and form filling.

    14k GitHub stars~1.7k tokensUpdated 4 days ago
    Auto-check passed
  • XLSX Spreadsheet Toolkit

    XiaomiMiMo/MiMo-Code

    Builds, edits, cleans, recalculates and reads Excel workbooks and CSV files with openpyxl and pandas, plus LibreOffice for recalculation and PDF export.

    14k GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed

Questions about Headless Codex CLI Automation

What does Headless Codex CLI Automation do?

Runs OpenAI Codex CLI as a non-interactive worker for CI, Docker, Kubernetes or remote servers, with sandbox modes and JSONL-friendly output. The guidance is to use `codex exec` rather than the interactive TUI, pass the task as the positional prompt argument, and for ordinary unattended changes run it with a workspace-write sandbox. For harnesses and CI it prefers `--json` plus `--output-last-message`, and treats the run as something that must never depend on a human answering a question, resolving ambiguity from repository evidence and conservative defaults instead.

When should I use Headless Codex CLI Automation?

Headless Codex CLI Automation fits situations like: running Codex CLI unattended inside a CI pipeline; automating Codex inside a Docker or Kubernetes job; choosing a sandbox and approval mode for a headless Codex run; recovering from a Codex run stuck waiting on user input.

How do I install Headless Codex CLI Automation in Claude Code?

Run `npx skills add XiaomiMiMo/MiMo-Code --skill codex -a claude-code`. Or copy the skill folder (packages/cli/src/skill/builtin/.bundle/codex in XiaomiMiMo/MiMo-Code) into .claude/skills/codex in your project. Claude Code loads it when a task matches its description.

How do I install Headless Codex CLI Automation in Codex?

Run `npx skills add XiaomiMiMo/MiMo-Code --skill codex -a codex`. Or copy the skill folder (packages/cli/src/skill/builtin/.bundle/codex in XiaomiMiMo/MiMo-Code) into .agents/skills/codex in your project. Codex loads it when a task matches its description.

Can I use Headless Codex CLI Automation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add XiaomiMiMo/MiMo-Code --skill codex -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex, .gemini/skills/codex, .github/skills/codex and .opencode/skills/codex in your project.

What does Headless Codex CLI Automation need to run?

Going by SKILL.md and its folder, Headless Codex CLI Automation needs the command-line tools its instructions call (codex and npm) and credentials named CODEX_API_KEY and OPENAI_API_KEY. Our summary lists: OpenAI Codex CLI.

Does Headless Codex CLI Automation access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Headless Codex CLI Automation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Headless Codex CLI Automation use?

Headless Codex CLI Automation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Headless Codex CLI Automation use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.7k tokens, read only when the agent opens those files.

What are the alternatives to Headless Codex CLI Automation?

Skills that share tags, products or a category with Headless Codex CLI Automation: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Rtk Skill (sopaco/deepwiki-rs, 3.1k stars), Docker Via Wsl (JMBeresford/retrom, 2.1k stars) and Data Processing (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Headless Codex CLI Automation?

XiaomiMiMo (a GitHub organization) maintains it in XiaomiMiMo/MiMo-Code, which has 13,611 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 3, 2026.

Source: XiaomiMiMo/MiMo-Code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.