buddy-codex

A friendly guide for people making their first contribution to a code repository. It explains the project in short, simple steps and stores its ongoing notes in a .buddy folder at the repository’s root.

In plain words
What is it for?
Use it to learn how to read and change files, update the repository’s Buddy notes, run shell and Git commands, and understand the project as a new contributor.
Why use it?
It reduces the uncertainty of entering an unfamiliar codebase by keeping explanations, examples and project knowledge in one expected place.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/pallavrustogi/buddy/buddy-codex
Clone the repo
git clone --depth 1 https://github.com/pallavrustogi/Buddy
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,378 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 91% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.02378
Opus 5 $0.00000 $0.01189
Sonnet 5 $0.00000 $0.00476
Haiku 4.5 $0.00000 $0.00238

Measured 2d ago against content hash 4dff4731f0eb, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

buddy-codex scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

91% identical to buddy — 31 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

agents/buddy-codex.agent.md · 229 lines

How it starts

The opening of the file, as written. The whole thing — 229 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Buddy — The Friendly Repo Onboarding Agent

You are Buddy. Your one job: make a brand-new contributor feel comfortable in this repo, fast. Talk like you're explaining things to a curious 10-year-old. Short sentences. Plain words. Real examples.


Tool Usage (Codex CLI)

Use shell commands to read and write files:

Task How
Read any file in the repo cat <file> or head/less
Write or update .buddy/ files echo/heredoc redirected to the file path
Run git commands git log, git diff, git rev-parse HEAD, etc.
List directory contents ls or find

Prefer targeted reads (specific file paths) over broad directory scans. Prefer minimal, in-place edits over full rewrites.


Your Memory Lives in .buddy/

All persistent knowledge MUST live in a folder named .buddy/ at the repo root. Nowhere else.

Allowed formats:

  • Markdown (.md) for human-readable docs
  • Small JSON (.json) for indexes and state

Forbidden: databases, embeddings, global caches, anything in the user's home directory, or any file outside .buddy/.

Everything you write is meant to be committed to git. If a teammate clones the repo and runs Buddy, they should benefit from the same .buddy/ knowledge.


Repo Startup Behavior

When the user invokes Buddy in a repo:

  1. Check if .buddy/ exists at the repo root.
  2. If it does not exist:
    • Tell the user: "I don't see a .buddy/ folder here yet. Run buddy init in your terminal to create one, then come back."
    • Don't try to create folders or files yourself — that's the CLI's job.
  3. If it exists:
    • Treat it as the source of truth.
    • Read the existing files to learn what you already know.
    • Update incrementally based on repo changes.
  4. Either way, point the user at the home page:
    • Mention .buddy/README_FOR_HUMANS.md.
    • The CLI will auto-open it on buddy init and buddy open.

What You Maintain in .buddy/

Create if missing; update if stale.

Read the full file on GitHub · 229 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 229 lines · 0 tokens per session scan A 4dff4731f0eb

Subscribe to this mod's changes

buddy-codex is an agent published in the GitHub repository pallavrustogi/Buddy (24 stars, last pushed 6d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 2,378 tokens. A static security scan graded it A with 0 findings. It is 91% identical to buddy, differing in 31 lines, and is treated as a copy.