Getting it into your agent
This one installs as part of its plugin. Adding the marketplace and installing the plugin brings it with everything else the plugin ships.
/plugin marketplace add andreidavid/codex-review/plugin install codex-reviewWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/andreidavid/codex-review/codex-review-sandbox-mode)<a href="https://agentmods.dev/commands/andreidavid/codex-review/codex-review-sandbox-mode"><img src="https://agentmods.dev/badge/commands/andreidavid/codex-review/codex-review-sandbox-mode.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00009 | $0.00115 |
| Opus 5 | $0.00005 | $0.00057 |
| Sonnet 5 | $0.00002 | $0.00023 |
| Haiku 4.5 | $0.00001 | $0.00012 |
Grade A, and why
codex-review-sandbox-mode scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
The user invoked this command with: $ARGUMENTS
Use status when no argument was given. Accept only workspace-write, danger-full-access, bypass, or status.
Run ${CLAUDE_PLUGIN_ROOT}/scripts/configure-sandbox-mode.sh with the selected value as its only argument. Report its output. Do not change any other setting.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 12 lines · 9 tokens per session scan A 15081c421f59
codex-review-sandbox-mode is a command published in the GitHub repository andreidavid/codex-review (2 stars, last pushed 1mo ago), licensed MIT. It adds 9 tokens to every session and 115 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
sm-sail
Command "sm-sail" from ScienceIsNeato/slop-mop, covering /sm-sail — drive a pr to green, autonomously, the loop, when sail parks on review threads, when to stop before "pr ready" — only two reasons and expect convergence, not one pass.
sm-buff
You usually don't run buff directly — run sm sail. sm sail drives the whole PR to green and calls buff watch / triage for you, stopping only when it needs you to act (see /sm-sail). Reach for sm buff here only for surgical work: inspecting a specific failure, or resolving a single review thread when sail has parked on…
sm-wake-angry-drunk-captain
The last-resort verb. Use it ONLY when the loop is genuinely exhausted: barnacles filed, gates green or truly unfixable, and the single remaining move is a human judgment call no sm verb can make for you.
sm-barnacle
Use when sm itself gives invalid guidance, blocks valid work, produces confusing output, or breaks install/upgrade/refit flow. Do not use this for real target-repo failures; fix those through the normal rail.
sm-init
Run when you find a repo with sm installed but no .sbconfig.json — or after upgrading slopmop to pick up new gates.
sm-refit
Run slop-mop's one-time onboarding remediation rail for this repository.