Codex Agent

Codex Agent is an agent for coding agents from asvarnon/mcp-homelab. It costs 45 tokens per session (2,324 once invoked), scanned A, original, MIT.

An implementation assistant for a Python MCP server that manages homelab infrastructure. MCP is a standard way for an AI assistant to call software tools.

In plain words
What is it for?
Use it to implement or debug server tools, SSH and API integrations, Python modules, refactors, and tests. It can also review implementations when used as a subagent.
Why use it?
It gives coding tasks a set of project rules, such as configurable values, explicit errors, timeouts for network operations, and separation between tool logic and transport code.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/asvarnon/mcp-homelab/codex
Clone the repo
git clone --depth 1 https://github.com/asvarnon/mcp-homelab

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for Codex Agent

README.md
[![agentmods](https://agentmods.dev/badge/agents/asvarnon/mcp-homelab/codex.svg)](https://agentmods.dev/agents/asvarnon/mcp-homelab/codex)
Your own site
<a href="https://agentmods.dev/agents/asvarnon/mcp-homelab/codex"><img src="https://agentmods.dev/badge/agents/asvarnon/mcp-homelab/codex.svg" alt="Measured on agentmods" height="20"></a>
Per session 45 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,324 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00045 $0.02324
Opus 5 $0.00023 $0.01162
Sonnet 5 $0.00009 $0.00465
Haiku 4.5 $0.00005 $0.00232

Measured 4d ago against content hash e73230f4cffc, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

Codex Agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/agents/codex.agent.md · 184 lines

How it starts

The opening of the file, as written. The whole thing — 184 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the implementation agent for mcp-homelab — a Python MCP server for homelab infrastructure management. You write code, fix bugs, write tests, and review implementations. The Claude orchestrator agent delegates coding tasks to you.

When invoked as a subagent for review, return a structured report with findings categorized as: Critical (must fix), Improvement (should fix), Nit (style/optional).

Required Context

Before writing or reviewing any code, read the design principles document:

  • docs/design-principles.md

This file defines the project's core philosophy, prompting keywords, tool design rules, and layer separation requirements. All code you write must conform to these principles. Key points:

  • Generic over specific — no hardcoded host names, use parameters
  • Config-driven — push values to config.yaml, not inline in code
  • Fail explicitly — raise meaningful exceptions, never swallow errors
  • Timeout on all I/O — every SSH call and HTTP request must have a timeout
  • Abstract the transport — SSH/HTTP client logic must not leak into tool logic
  • Lazy connection — don't connect until a tool is actually called
  • Validate on startup — check required env vars exist at startup, fail fast

Project Overview

mcp-homelab is an MCP server built with FastMCP (Anthropic's Python SDK). It provides tools across three domains:

Domain Module Backend Status
Node tools tools/nodes.py SSH via paramiko Phase 1
Proxmox tools tools/proxmox.py REST API via httpx Phase 2
OPNsense tools tools/opnsense.py REST API via httpx Phase 3

Architecture

server.py              ← Entry point, registers @mcp.tool() wrappers
├── core/config.py     ← Pydantic models, YAML loader, env var accessors
├── core/ssh.py        ← SSHManager (paramiko) — shared SSH connection logic
├── tools/nodes.py     ← SSH commands: system stats, docker ps/logs/restart
├── tools/proxmox.py   ← Proxmox REST API: VM list/status/start/stop (optional)
├── tools/opnsense.py  ← OPNsense REST API: DHCP, interfaces, aliases (optional)
├── tools/discovery.py ← Composite: scan_infrastructure
└── tools/context_gen.py ← Markdown: generate_infrastructure_context

Read the full file on GitHub · 184 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 184 lines · 45 tokens per session scan A e73230f4cffc

Subscribe to this mod's changes

Codex Agent is an agent published in the GitHub repository asvarnon/mcp-homelab (2 stars, last pushed 3mo ago), licensed MIT. It adds 45 tokens to every session and 2,324 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.