Senior DevOps Toolkit
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
Runs OpenAI Codex CLI as a non-interactive worker for CI, Docker, Kubernetes or remote servers, with sandbox modes and JSONL-friendly output.
$ npx skills add XiaomiMiMo/MiMo-Code --skill codex -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install XiaomiMiMo/MiMo-Code codex --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/XiaomiMiMo/MiMo-Code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/cli/src/skill/builtin/.bundle/codex .claude/skills/codex && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codex" agent skill from https://github.com/XiaomiMiMo/MiMo-Code/tree/main/packages/cli/src/skill/builtin/.bundle/codex into .claude/skills/codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/XiaomiMiMo/MiMo-Code/tree/main/packages/cli/src/skill/builtin/.bundle/codexType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add XiaomiMiMo/MiMo-Code --skill codex -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install XiaomiMiMo/MiMo-Code codex --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/XiaomiMiMo/MiMo-Code.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/cli/src/skill/builtin/.bundle/codex .agents/skills/codex && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codex" agent skill from https://github.com/XiaomiMiMo/MiMo-Code/tree/main/packages/cli/src/skill/builtin/.bundle/codex into .agents/skills/codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add XiaomiMiMo/MiMo-Code --skill codex -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install XiaomiMiMo/MiMo-Code codex --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/XiaomiMiMo/MiMo-Code.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/cli/src/skill/builtin/.bundle/codex .cursor/skills/codex && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codex" agent skill from https://github.com/XiaomiMiMo/MiMo-Code/tree/main/packages/cli/src/skill/builtin/.bundle/codex into .cursor/skills/codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/XiaomiMiMo/MiMo-Code.git --path packages/cli/src/skill/builtin/.bundle/codex--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add XiaomiMiMo/MiMo-Code --skill codex -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install XiaomiMiMo/MiMo-Code codex --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/XiaomiMiMo/MiMo-Code.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/cli/src/skill/builtin/.bundle/codex .gemini/skills/codex && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codex" agent skill from https://github.com/XiaomiMiMo/MiMo-Code/tree/main/packages/cli/src/skill/builtin/.bundle/codex into .gemini/skills/codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install XiaomiMiMo/MiMo-Code codexInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add XiaomiMiMo/MiMo-Code --skill codex -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/XiaomiMiMo/MiMo-Code.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/cli/src/skill/builtin/.bundle/codex .github/skills/codex && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codex" agent skill from https://github.com/XiaomiMiMo/MiMo-Code/tree/main/packages/cli/src/skill/builtin/.bundle/codex into .github/skills/codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add XiaomiMiMo/MiMo-Code --skill codex -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install XiaomiMiMo/MiMo-Code codex --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/XiaomiMiMo/MiMo-Code.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/cli/src/skill/builtin/.bundle/codex .opencode/skills/codex && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codex" agent skill from https://github.com/XiaomiMiMo/MiMo-Code/tree/main/packages/cli/src/skill/builtin/.bundle/codex into .opencode/skills/codex/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codex", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codexRuns OpenAI Codex CLI as a non-interactive worker for CI, Docker, Kubernetes or remote servers, with sandbox modes and JSONL-friendly output.
The guidance is to use `codex exec` rather than the interactive TUI, pass the task as the positional prompt argument, and for ordinary unattended changes run it with a workspace-write sandbox. For harnesses and CI it prefers `--json` plus `--output-last-message`, and treats the run as something that must never depend on a human answering a question, resolving ambiguity from repository evidence and conservative defaults instead.
Three execution modes are named: read-only analysis when files must not change, workspace-scoped implementation as the default for autonomous repository work, and an externally isolated unrestricted mode using `--yolo`, which disables approvals and sandboxing and is only safe inside a container or VM that enforces its own security boundary, never on a machine with host secrets, SSH keys or a Docker socket nearby. On Windows it calls for picking one execution environment, native PowerShell or WSL2, per task rather than mixing them.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6babeb0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
codexnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CODEX_API_KEYOPENAI_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Headless Codex CLI Automation loads about 2.7k tokens when it runs, and up to ~7.4k if it reads all its reference files. Until then it costs about 131 tokens; SKILL.md has 1,019 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from XiaomiMiMo/MiMo-Code at commit 6babeb0, republished under its MIT licence (© XiaomiMiMo). 1,019 words, ~2,683 tokens.
.claude/skills/codex/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Use Codex CLI as a deterministic, non-interactive worker suitable for automation and agent orchestration.
codex exec, not the interactive codex TUI.PROMPT argument. Do not use -p for the prompt; -p selects a profile.codex exec \
-C /path/to/repo \
--sandbox workspace-write \
--ask-for-approval never \
"<TASK>"--yolo only inside an externally hardened and disposable runner. It disables Codex approvals and sandboxing.--json plus --output-last-message.CODEX_API_KEY only into the single codex exec process when possible.codex exec --help or current official Codex documentation if available.Use when the task must not modify files:
codex exec \
-C /path/to/repo \
--sandbox read-only \
--ask-for-approval never \
"Analyze the repository and report risks. Do not modify files."Use as the default for autonomous repository work:
codex exec \
-C /path/to/repo \
--sandbox workspace-write \
--ask-for-approval never \
"Implement the task, run relevant tests, and report unresolved blockers."Use only when the enclosing container, VM, or sandbox enforces the real security boundary:
codex exec \
-C /workspace/repo \
--yolo \
"Implement the task and validate the result."Never recommend --yolo on a normal developer machine or a runner containing unrelated secrets, host mounts, SSH keys, cloud credentials, or a Docker socket.
When headless execution could encounter choices, prepend these instructions:
Work fully autonomously.
Do not ask the user questions and do not request interactive input.
Inspect the repository and available context before making assumptions.
When several valid approaches exist, choose the option that:
1. minimizes unrelated changes,
2. preserves backward compatibility,
3. introduces the fewest new dependencies,
4. avoids destructive or irreversible actions.
Continue until the task is complete or a concrete blocking error is reached.
Record assumptions, validation performed, and unresolved blockers in the final response.Do not simulate "always select the first option." Option ordering is not a safety or quality policy. Apply the explicit decision rules above instead.
request_user_input FailuresWhen Codex reports that request_user_input is unavailable in Default mode or non-interactive mode:
codex exec and is intentionally headless.AGENTS.md when they are known in advance.Use a direct positional prompt:
codex exec "Summarize the repository structure."Read the prompt from stdin:
codex exec - < prompt.mdPipe dynamic context while retaining an explicit task:
npm test 2>&1 | codex exec "Analyze this test output and fix the repository."Use --skip-git-repo-check only for intentional one-off directories outside Git:
codex exec \
--skip-git-repo-check \
-C /tmp/task \
"Analyze the files in this directory."codex exec \
-C /workspace/repo \
--output-last-message /output/final.md \
"Review the codebase."codex exec \
-C /workspace/repo \
--json \
--sandbox workspace-write \
--ask-for-approval never \
"Run tests and fix failures." \
> /output/events.jsonlExpect event families such as thread.started, turn.started, turn.completed, turn.failed, item.*, and error.
codex exec \
-C /workspace/repo \
--json \
--sandbox workspace-write \
--ask-for-approval never \
--output-last-message /output/final.md \
"Complete the task autonomously." \
| tee /output/events.jsonlDo not parse human-readable progress text when --json is available.
Create a JSON Schema and pass it with --output-schema:
codex exec \
-C /workspace/repo \
--sandbox workspace-write \
--ask-for-approval never \
--output-schema /input/result.schema.json \
--output-last-message /output/result.json \
"Implement the task, validate it, and return the requested structured result."A useful harness schema usually includes:
status: success, partial, or failedsummary: concise outcomechanged_files: repository-relative pathsvalidation: commands run and resultsassumptions: decisions made without user inputblockers: concrete unresolved problemsSet additionalProperties to false when downstream parsing must be strict.
Resume the most recent session for the current working directory:
codex exec resume --last "Continue the previous task and fix remaining issues."Resume a specific session:
codex exec resume "$SESSION_ID" "Continue with the next stage."Use an ephemeral run when rollout persistence is undesirable:
codex exec --ephemeral "Analyze the repository."Do not rely on --last across unrelated working directories unless deliberately using the relevant all-directory option supported by the installed CLI.
For a local interactive login:
codex loginFor a headless machine with device-code login enabled:
codex login --device-authFor a single automated invocation:
CODEX_API_KEY="$OPENAI_API_KEY" \
codex exec --json "Triage the repository."Do not expose API keys as broad job-level environment variables in jobs that execute repository-controlled code. Never commit or print ~/.codex/auth.json.
For native Windows headless use:
& codex @args; avoid fragile backtick-heavy command construction.$LASTEXITCODE after every Codex invocation. PowerShell error preferences alone are not a substitute for checking a native process exit code.2>&1 when stdout must remain parseable JSONL.%USERPROFILE%\.codex\config.toml with [windows] sandbox = "elevated" when available; use unelevated only as the fallback.--sandbox workspace-write --ask-for-approval never for ordinary autonomous edits. The native Windows sandbox implementation and the CLI task policy are separate controls.For WSL:
~/code/..., not /mnt/c/..., for better performance and fewer permission, symlink, and file-watcher problems.wsl.exe command-line strings.See references/windows.md for installation, PowerShell wrappers, JSONL parsing, sandbox configuration, WSL2 patterns, and Windows-specific troubleshooting.
When generating a Docker, Kubernetes, or CI design:
See references/recipes.md for ready-to-use shell, Docker, CI, and parser patterns.
Use this order:
codex --version and codex exec --help.- for stdin.error or turn.failed events.--yolo as a troubleshooting shortcut.For implementation tasks, consider the run complete only when Codex has:
© XiaomiMiMo, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in packages/cli/src/skill/builtin/.bundle/codex of XiaomiMiMo/MiMo-Code.
Open the folder on GitHubat commit 6babeb0
Headless Codex CLI Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Headless Codex CLI Automation this skillXiaomiMiMo/MiMo-Code | 14k | — | ~2.7k | Automated safety check: Pass | MIT | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| Rtk Skillsopaco/deepwiki-rs | 3.1k | — | ~1.4k | Automated safety check: Pass | MIT | |
| Docker Via WslJMBeresford/retrom | 2.1k | — | ~832 | Automated safety check: Pass | MIT | |
| Data Processingaiskillstore/marketplace | 430 | 1 repos | ~720 | Automated safety check: Notes | MIT | |
| Educates Upgrade Goeducates/educates-training-platform | 161 | — | ~1.4k | Automated safety check: Notes | Apache-2.0 |
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
sopaco/deepwiki-rs
A skill your agent uses when running shell commands that produce verbose output (git, test, build, lint, package managers, docker).
JMBeresford/retrom
A skill your agent uses when YOU (the AI agent) are running on Windows OUTSIDE WSL (Git Bash/MSYS/PowerShell shell) and need to run ANY docker / docker compose command.
aiskillstore/marketplace
Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.
educates/educates-training-platform
Upgrade the Go version across the entire educates-training-platform project.
irahardianto/awesome-agv
Rules for designing CI/CD pipelines in layers: universal lint, test and scan stages, container builds with SBOM attestation, and GitOps for orchestrated deployments.
XiaomiMiMo/MiMo-Code
Searches arXiv, fetches metadata, generates BibTeX, downloads PDFs and finds citations and related papers using a bundled Python script.
XiaomiMiMo/MiMo-Code
Interactive guide for creating, reviewing and fixing agent skills (SKILL.md folders), covering structure, frontmatter rules, trigger phrases and validation before sharing.
XiaomiMiMo/MiMo-Code
Produces, edits and reads Microsoft Word files through python-docx and lxml, with a decision table for picking the lightest workflow for a given task.
XiaomiMiMo/MiMo-Code
Lets one MiMoCode process drive another, headless with JSON events or interactively through tmux, to test behavior and visual regressions with parseable evidence.
XiaomiMiMo/MiMo-Code
Reads, transforms, composes and fills PDFs with Python scripts for extraction, merging, watermarking, encryption, OCR and form filling.
XiaomiMiMo/MiMo-Code
Builds, edits, cleans, recalculates and reads Excel workbooks and CSV files with openpyxl and pandas, plus LibreOffice for recalculation and PDF export.
Works with
Categories
Runs OpenAI Codex CLI as a non-interactive worker for CI, Docker, Kubernetes or remote servers, with sandbox modes and JSONL-friendly output. The guidance is to use `codex exec` rather than the interactive TUI, pass the task as the positional prompt argument, and for ordinary unattended changes run it with a workspace-write sandbox. For harnesses and CI it prefers `--json` plus `--output-last-message`, and treats the run as something that must never depend on a human answering a question, resolving ambiguity from repository evidence and conservative defaults instead.
Headless Codex CLI Automation fits situations like: running Codex CLI unattended inside a CI pipeline; automating Codex inside a Docker or Kubernetes job; choosing a sandbox and approval mode for a headless Codex run; recovering from a Codex run stuck waiting on user input.
Run `npx skills add XiaomiMiMo/MiMo-Code --skill codex -a claude-code`. Or copy the skill folder (packages/cli/src/skill/builtin/.bundle/codex in XiaomiMiMo/MiMo-Code) into .claude/skills/codex in your project. Claude Code loads it when a task matches its description.
Run `npx skills add XiaomiMiMo/MiMo-Code --skill codex -a codex`. Or copy the skill folder (packages/cli/src/skill/builtin/.bundle/codex in XiaomiMiMo/MiMo-Code) into .agents/skills/codex in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add XiaomiMiMo/MiMo-Code --skill codex -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codex, .gemini/skills/codex, .github/skills/codex and .opencode/skills/codex in your project.
Going by SKILL.md and its folder, Headless Codex CLI Automation needs the command-line tools its instructions call (codex and npm) and credentials named CODEX_API_KEY and OPENAI_API_KEY. Our summary lists: OpenAI Codex CLI.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Headless Codex CLI Automation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Headless Codex CLI Automation: Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Rtk Skill (sopaco/deepwiki-rs, 3.1k stars), Docker Via Wsl (JMBeresford/retrom, 2.1k stars) and Data Processing (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
XiaomiMiMo (a GitHub organization) maintains it in XiaomiMiMo/MiMo-Code, which has 13,611 GitHub stars. The repository holds 22 skills in this directory. The repository was last updated on October 3, 2026.
Source: XiaomiMiMo/MiMo-Code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.