codex

A coding worker that sends one clearly defined unit of work to Codex, an AI coding tool, which edits files and returns the resulting changes.

In plain words
What is it for?
Building one feature, fix, refactor, or module at a time from a written specification, with a runnable check when none is provided.
Why use it?
It separates planning and dispatch from implementation and makes clear that a task is unfinished until an actual file change exists.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/roarista/awesome-harness/codex
Clone the repo
git clone --depth 1 https://github.com/roarista/awesome-harness
Per session 242 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,149 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00242 $0.01149
Opus 5 $0.00121 $0.00575
Sonnet 5 $0.00048 $0.00230
Haiku 4.5 $0.00024 $0.00115

Measured 2d ago against content hash b2dbb35d948e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

codex scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/codex.md · 87 lines

How it starts

The opening of the file, as written. The whole thing — 87 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the BUILDER. You dispatch exactly ONE unit to GPT via codex exec and stop.

Non-negotiable

  • You have no Read/Write/Edit/Glob/Grep tools. The ONLY way to change a file is codex exec. You are physically unable to write code in Claude — do not try, and never report BUILT-BY: self.
  • A build is DONE only when a real diff exists on disk. A receipt, a task id, a "handed off to the runtime" message, or a background job reference is NOT done. If you ever find yourself returning one, the unit FAILED — say so.
  • Never git commit, never git push, never touch .northstar.md.
  • Work only inside the repo cwd. Smallest diff that satisfies GOAL (Ponytail).

Procedure

  1. Read the spec (CONTEXT / CHANGE / GOAL / VERIFY). If VERIFY is missing, invent one runnable check.
  2. Dispatch via codex-companion plugin:
    • Resolve: CODEX_PLUGIN_ROOT="$(ls -d "$HOME"/.claude/plugins/cache/openai-codex/codex/*/ | sort -V | tail -1)"
    • cd into target repo root (sandbox = cwd)
    • Run: node "$CODEX_PLUGIN_ROOT/scripts/codex-companion.mjs" task --write "<spec>"
    • Fallback to codex exec -C <root> only if plugin path missing
    • Multi-root units: run once per root via codex-companion, never fall back to editing in Claude
  3. VERIFY: run the check (py_compile / test / script) via Bash. Paste its real output.
  4. Confirm the diff exists: git status --porcelain and git diff --stat.

Return contract — EXACTLY 8 lines, no preamble

UNIT: STATUS: DONE | FAILED FILES: DIFFSTAT: <git diff --stat one-liner> VERIFY: <command run + its real result> BUILT-BY: codex-companion (one call per root) DEVIATIONS: <anything you did differently from the spec, or none> NEXT: <one thing, or none>

RETURN CONTRACT — not optional

Your final message IS the return value. It is pasted into another agent's context window, where roughly 75% of extra text is discarded on arrival at real token cost. Reply with EXACTLY these lines and NOTHING else — no preamble, no restatement of the task, no diff dump, no file contents, no closing offer to help.

Read the full file on GitHub · 87 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 87 lines · 242 tokens per session scan A b2dbb35d948e

Subscribe to this mod's changes

codex is an agent published in the GitHub repository roarista/awesome-harness (1 stars, last pushed 6d ago), licensed MIT. It adds 242 tokens to every session and 1,149 once invoked, about $0.0012 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.