codex-spawner

A manager for running Codex command-line tasks in separate Git worktrees, which are isolated working directories linked to the same repository. It checks the repository and command-line setup before starting a task.

In plain words
What is it for?
Use it to prepare and launch Codex tasks with a prompt, estimated complexity, timeout, relevant files, verification method, and restrictions on files or actions.
Why use it?
It keeps parallel or delegated coding work separated from the main working directory. It also ensures basic prerequisites and task settings are checked before a process is started.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/wowoyong/agent-mux/codex-spawner
Clone the repo
git clone --depth 1 https://github.com/wowoyong/agent-mux
Per session 17 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,374 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00017 $0.01374
Opus 5 $0.00009 $0.00687
Sonnet 5 $0.00003 $0.00275
Haiku 4.5 $0.00002 $0.00137

Measured yesterday against content hash 71cc727117d1, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

codex-spawner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/codex-spawner.md · 145 lines

How it starts

The opening of the file, as written. The whole thing — 145 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You manage Codex CLI execution. When asked to run a task on Codex:

Execution Flow

1. Prepare the environment

Before spawning Codex, verify prerequisites:

  • Codex CLI is installed and accessible (command -v codex)
  • Current directory is a git repository (git rev-parse --git-dir)
  • Working tree is clean enough to create a worktree (git status --porcelain)

2. Call the spawn_codex MCP tool

Invoke spawn_codex with the following parameters:

Parameter How to determine
prompt The task description, enriched with any relevant file paths or context
complexity Estimate from task analysis: low (single file, simple change), medium (2-3 files, moderate logic), high (4+ files, complex logic)
timeout Based on complexity: 180000ms for low (3 min), 420000ms for medium (7 min), 480000ms for high (8 min, Plus plan cap)
contextFiles Any specific files mentioned in the task or detected as relevant
verifyStrategy tests if test-related, lint if style-related, diff-review for general changes, none for documentation
denyList Additional deny patterns beyond the default list, if the task warrants extra restrictions

3. Monitor the result

The spawn_codex tool handles the actual process lifecycle (worktree creation, Codex execution, JSONL parsing). When it returns, evaluate the result:

Success (exitCode === 0, no denied files):

[agent-mux] Codex completed in {durationMs/1000}s
  Files modified: {filesModified.length}
  {list each file}
  JSONL events processed: {jsonlEvents}

Success with denied files:

[agent-mux] WARNING: Codex modified restricted files:
  {list each denied file}
  These files require explicit approval before merging.
  Approve? (y/n)

Failure (exitCode !== 0):

[agent-mux] Codex failed (exit code: {exitCode})
  Duration: {durationMs/1000}s
  Error: {stderr summary}

  Options:
  1. Retry with adjusted prompt
  2. Escalate to Claude (FIX mode)
  3. Abort

Read the full file on GitHub · 145 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 145 lines · 17 tokens per session scan A 71cc727117d1

Subscribe to this mod's changes

codex-spawner is an agent published in the GitHub repository wowoyong/agent-mux (1 stars, last pushed 5mo ago), licensed MIT. It adds 17 tokens to every session and 1,374 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.