Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/ilysenko/codex-desktop-linux/generated-and-runtime-notesgit clone --depth 1 https://github.com/ilysenko/codex-desktop-linuxWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00512 |
| Opus 5 | $0.00000 | $0.00256 |
| Sonnet 5 | $0.00000 | $0.00102 |
| Haiku 4.5 | $0.00000 | $0.00051 |
Grade A, and why
generated-and-runtime-notes scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Generated and runtime notes
Do not edit or commit generated application/package state:
codex-app/,codex-app-next/,codex-app.backup-*,.codex-app.candidate-*codex-*-app/,dist/,dist-next/,target/linux-features/features.json,linux-features/local/- staged feature manifests and build/patch reports
- updater config/state/cache/log directories under XDG paths
The local selection files are intentionally untracked:
linux-features/features.json
linux-features/local/<id>/
Do not replace them with committed defaults or include private local feature code in a pull request by accident.
The baseline staged tree is extracted from /usr/lib/chatgpt in the verified
official package. Its runtime, native modules, commands, libraries, locales, and
Owl metadata remain upstream-owned. start.sh and .codex-linux/ are generated
from repository templates and feature manifests.
With no ASAR features, compare the staged and package resources/app.asar
SHA-256 values. Any difference is a build bug. With features, consult the patch
report and staged feature manifest.
Expected generated metadata under codex-app/.codex-linux/ includes build-info
schema v2, the enabled feature snapshot, launcher hook directories, the
community icon, and patch/build reports where applicable. These are regenerated
from repository templates and manifests.
The official payload should continue to supply:
ChatGPTand its Electron libraries;resources/app.asar;- Linux native modules;
- bundled
codex,rg, and code-mode host; - bundled official plugins, locales, assets, and Owl metadata.
A generated tree containing a downloaded replacement Electron, an external CLI bundle, rebuilt upstream native modules, or a local webview HTTP server signals that retired architecture has been reintroduced.
Updater candidates are siblings of the active tree and are promoted atomically.
Do not manually rename an active/candidate pair or delete its recovery journal.
An old root-owned codex-app.backup-* is disposable only after verifying it is
not the active tree or the updater's recorded rollback artifact.
Package manager output under /opt/codex-desktop is installed state, not a
development source tree. Fix templates in the repository, rebuild a package,
and reinstall rather than modifying /opt in place.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 56 lines · 0 tokens per session scan A bfd1c062b3c9
generated-and-runtime-notes is an agent published in the GitHub repository ilysenko/codex-desktop-linux (3,737 stars, last pushed 2d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 512 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
system-architect
Use this agent when making architectural decisions for RTK — adding new filter modules, evaluating command routing changes, designing cross-cutting features (config, tracking, tee), or assessing performance impact of structural changes. Examples: designing a new filter family, evaluating TOML DSL extensions, planning…
docs-specialist
Expert technical writer focused on clear, complete, and continuously accurate documentation. Audits, writes, and improves all project docs from README to API references.
ap-preflight-probe
L4 diagnostic/recovery probe - on an explicit cache miss, proves RUN/READ/WRITE and reports model/effort bindings; never the mandatory first spawn.
ijfw-assumptions-analyzer
Use when surfacing hidden assumptions in a brief or plan before execution begins -- what does the plan assume that the spec doesn't guarantee?
ijfw-accessibility-reviewer
Design-phase WCAG 2.1 AA review of UI artefacts: contrast, semantics, focus, ARIA. Trigger per design review pass.
ring:qa
Senior QA Analyst for financial systems. Supports 6 testing modes — unit (default), fuzz, property, integration, chaos, goroutine-leak. Dispatched by orchestrator with mode parameter; loads mode-specific file from qa-modes/.