Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/pivanov/agents-wire/codexgit clone --depth 1 https://github.com/pivanov/agents-wireWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00552 |
| Opus 5 | $0.00000 | $0.00276 |
| Sonnet 5 | $0.00000 | $0.00110 |
| Haiku 4.5 | $0.00000 | $0.00055 |
Grade A, and why
codex scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Codex CLI
Agent ID: codex
OpenAI's Codex CLI. Speaks ACP via the @zed-industries/codex-acp bridge, which is bundled with agents-wire (no peer install needed).
Install
Install the Codex CLI and set your API key:
npm install -g @openai/codex
export OPENAI_API_KEY="sk-..."
Quick Start
import { agents } from "@pivanov/agents-wire";
const result = await agents.ask(
"codex",
"Refactor src/auth.ts",
{
permission: "auto-allow",
},
);
console.log(result.text);
Model Selection
options.model becomes -c model="X" on the codex-acp CLI (verified via
codex-acp --help). This is the most reliable model selection path of all built-in agents.
options.effort becomes -c model_reasoning_effort="X". Valid values are "low",
"medium", and "high". Only applies to reasoning models (o3, o1).
await agents.ask(
"codex",
prompt,
{
model: "gpt-5",
},
);
await agents.ask(
"codex",
prompt,
{
model: "o3",
},
);
// Reasoning effort (o3, o1 only):
await agents.ask(
"codex",
prompt,
{
model: "o3",
effort: "low",
},
);
await agents.ask(
"codex",
prompt,
{
model: "o3",
effort: "high",
},
);
Capabilities
| Feature | Supported |
|---|---|
ask / stream / session |
✅ |
askJson |
✅ |
| MCP stdio | ✅ |
| MCP http/sse | ❌ |
Session listing (listSessions) |
✅ |
| Tool call interception | ✅ |
Cost Tracking
Codex reports per-turn costUsd. Full cost tracking and maxCostUsd budget enforcement work.
Auth Failure Detection
If OPENAI_API_KEY is missing or invalid, the SDK catches the authentication-failure pattern in stderr and throws AgentUnauthenticatedError.
Gotchas
- Requires a POSIX environment (macOS, Linux, WSL).
- The
OPENAI_API_KEYmust be set in the environment. Pass custom env vars viaoptions.envFilter.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 98 lines · 0 tokens per session scan A 26f1af94c392
codex is an agent published in the GitHub repository pivanov/agents-wire (5 stars, last pushed 3mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 552 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
codex-execute
Implement a SPECIFIC, well-defined plan or plan-step with Codex. Use ONLY when the user has a written plan, plan-step, named files, or acceptance criteria to execute ("execute this via codex", "implement this plan", "/codex:execute", or a --plan file is in context). Do NOT use when the user is stuck/exploring (use…
cursor-delegate
Delegate a SPECIFIC, well-defined implementation task or plan step to Cursor in agent mode on the Auto model. Cursor is the fast lane for mechanical writing — long file writes (200+ lines), pattern-following across many files, bulk refactors. Supports autonomous multi-step runs via --until-done. Pair with…
cursor-research
Delegate read-only EXTERNAL web/documentation research to Cursor. Use when the user wants current library/API/docs research, "what's the current way to…", or to compare approaches — and you'd rather not spend Claude's context on web reading. Cursor runs read-only (ask mode) with web search + fetch and returns findings…
opencode-research
Delegate read-only EXTERNAL web/documentation research to OpenCode. Use when the user wants current library/API/docs research, "what's the current way to…", or to compare approaches — and you'd rather not spend Claude's context on web reading. OpenCode runs read-only (ask mode) with web search + fetch and returns…
codex-rescue
Hand an OPEN-ENDED or stuck problem to Codex for independent investigation. Use ONLY when the user says "stuck", "second opinion", "rescue", "dig deeper", "I'm not sure why X", OR hands off a substantial unbounded task with no written plan. Do NOT use when a plan or plan-step file is in context (use codex-execute) or…
cursor-explore
Delegate quick read-only CODEBASE exploration to Cursor. Use to answer questions about the current repository ("where is X handled?", "how does Y flow?", "summarize the adapter layer") without spending Claude's tokens reading files. Cursor runs read-only (ask mode) using semantic search, grep, and its Explore…