Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/ilysenko/codex-desktop-linux/repository-mapgit clone --depth 1 https://github.com/ilysenko/codex-desktop-linuxWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00794 |
| Opus 5 | $0.00000 | $0.00397 |
| Sonnet 5 | $0.00000 | $0.00159 |
| Haiku 4.5 | $0.00000 | $0.00079 |
Grade A, and why
repository-map scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 56 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Repository map
| Area | Source of truth |
|---|---|
| Signed upstream | scripts/lib/upstream-linux-package.js, .sh, pinned key under assets/ |
| Build orchestration | install.sh, scripts/lib/install-helpers.sh, build-info.* |
| Launcher | launcher/start.sh.template |
| ASAR engine | scripts/patches/, scripts/patch-linux-window-ui.js, patch-report.js |
| Linux features | linux-features/<id>/feature.json, adjacent README/resources/hooks |
| Shared packaging | scripts/lib/package-common.sh |
| Package formats | scripts/build-deb.sh, build-rpm.sh, build-pacman.sh, build-appimage.sh |
| Native runtime hooks | packaging/linux/ |
| AppImage runtime | packaging/appimage/ |
| Updater | updater/src/, packaging/update-builder/ |
| Release watchdog | scripts/automation/upstream-linux-package-watchdog/ |
| Nix | flake.nix, nix/upstream-linux-packages.json, nix/*.nix |
| CI | .github/workflows/, scripts/ci/, scripts/ci-local.sh |
| Computer Use | computer-use-linux/ and retained feature descriptors |
Common task routing
| Task | Start here | Also inspect |
|---|---|---|
| Change package verification | scripts/lib/upstream-linux-package.js |
verifier tests, pinned key, updater source path, Nix pins |
| Change staged app layout | install.sh, scripts/lib/install-helpers.sh |
all package formats, updater builder, baseline ASAR hash |
| Change launch behavior | launcher/start.sh.template |
AppImage runtime, desktop entries, feature hooks |
| Add or alter a feature | linux-features/<id>/feature.json |
adjacent README/test, Nix registry, watchdog config |
| Change ASAR matching | the feature's descriptor | patch runner/report policy, raw official-ASAR probe |
| Change package content | scripts/lib/package-common.sh |
deb/RPM/pacman/AppImage/Nix and updater bundle |
| Change update behavior | updater/src/ |
service files, notification/desktop actions, persisted-state migration |
| Refresh official pins | scripts/ci/update-official-linux-pins.sh |
both architectures and signed metadata |
| Change public commands | Makefile or CLI source |
README EN/ZH and relevant operations guide |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 56 lines · 0 tokens per session scan A 994ec9ccbbb6
repository-map is an agent published in the GitHub repository ilysenko/codex-desktop-linux (3,744 stars, last pushed yesterday), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 794 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
system-architect
Use this agent when making architectural decisions for RTK — adding new filter modules, evaluating command routing changes, designing cross-cutting features (config, tracking, tee), or assessing performance impact of structural changes. Examples: designing a new filter family, evaluating TOML DSL extensions, planning…
docs-specialist
Expert technical writer focused on clear, complete, and continuously accurate documentation. Audits, writes, and improves all project docs from README to API references.
ap-preflight-probe
L4 diagnostic/recovery probe - on an explicit cache miss, proves RUN/READ/WRITE and reports model/effort bindings; never the mandatory first spawn.
ijfw-assumptions-analyzer
Use when surfacing hidden assumptions in a brief or plan before execution begins -- what does the plan assume that the spec doesn't guarantee?
ijfw-accessibility-reviewer
Design-phase WCAG 2.1 AA review of UI artefacts: contrast, semantics, focus, ARIA. Trigger per design review pass.
ring:streaming-reviewer
Conditional Gate 8 specialist for lib-streaming, business events, outbox, event producers, broker publishing, CloudEvents, and event manifests/catalogs.