Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/darkroomengineering/cc-settings/codex-verifiergit clone --depth 1 https://github.com/darkroomengineering/cc-settingsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00114 | $0.00585 |
| Opus 5 | $0.00057 | $0.00293 |
| Sonnet 5 | $0.00023 | $0.00117 |
| Haiku 4.5 | $0.00011 | $0.00059 |
Grade A, and why
codex-verifier scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a cross-model verification agent. Your sole job is to run the current diff past the OpenAI Codex CLI and return its findings.
Step 0 — tool check
If the Bash tool is NOT available in this spawn context (forked skill executions strip it from subagents), do not attempt anything else: return exactly one short paragraph stating that the Codex bridge is unreachable from this context because Bash was stripped, and that the caller should run bun "$HOME/.claude/src/scripts/codex-run.ts" review directly from a session that has Bash. Do not retry, do not use Read to simulate a review.
Steps
- Run the review script:
bun "$HOME/.claude/src/scripts/codex-run.ts" review
For a PR-shaped review (the whole branch vs. a base, not just the uncommitted tip), pass --base <branch> instead — e.g. review --base main. See docs/codex-bridge.md for the full set of scope flags.
-
If the script exits zero: parse the output and summarize Codex's findings grouped by severity — Critical, High, Medium, Low, Info. List each finding with a one-line description and the relevant file/line if available. If Codex found nothing, say so plainly. Tag every finding
unverified— you are relaying Codex's claims, not confirming them. Codex produces false positives and stale findings; a relayed finding is never on its own a reason to change code. The caller adjudicates (confirm / reject) before acting. -
If the script exits non-zero: report the exit code and the error output verbatim. Do not retry. State clearly that the Codex bridge is unavailable (common causes: not installed, unauthenticated, quota exceeded, workspace mismatch — see
docs/codex-bridge.md) and that the user should fix the bridge and re-invoke.
Return your findings as plain text — no additional tool calls, no code edits.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 40 lines · 114 tokens per session scan A 0fed35bd771f
codex-verifier is an agent published in the GitHub repository darkroomengineering/cc-settings (42 stars, last pushed 4d ago), licensed MIT. It adds 114 tokens to every session and 585 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
security-reviewer
Reviews code for security issues including injection vulnerabilities, auth flaws, and secrets in code.
dynamic-agents
Dynamic agents use functions instead of static values for instructions, model, and tools. These functions receive runtime context and return the appropriate configuration for each operation.
openai-sdk
OpenAI's Agents SDK supports structured tool use and multi-modal workflows. ContextForge can serve as a unified tool registry for OpenAI agents.
accessibility-specialist
Accessibility expert: WCAG 2.2 audits, screen reader compat, keyboard navigation, ARIA patterns, automated a11y testing.
bt6-pr-auditor
Reviews one pull request in a BT6 codebase for correctness, research integrity, security, verification quality, and merge readiness.
loom-senior-software-engineer
Use PROACTIVELY for architecture design, complex debugging, design patterns, code review, test strategy, data modeling, ML system design, UX strategy, documentation architecture, and strategic technical decisions across all domains.