code-oz-doctor

A read-only diagnostic command for checking a code-oz installation, provider sign-in, and the current run state.

In plain words
What is it for?
Use it to check whether code-oz is installed correctly and whether its authentication and current run state are healthy.
Why use it?
It helps identify setup or active-run problems without changing project files or making provider requests.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/omerakben/code-oz/code-oz-doctor
Clone the repo
git clone --depth 1 https://github.com/omerakben/code-oz
Per session 17 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 344 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00017 $0.00344
Opus 5 $0.00009 $0.00172
Sonnet 5 $0.00003 $0.00069
Haiku 4.5 $0.00002 $0.00034

Measured yesterday against content hash ab0b8ec6b658, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code-oz-doctor scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/code-oz/commands/code-oz-doctor.md · 34 lines

What it actually says

This command only invokes the code-oz engine. Do not write .code-oz/, do not decide pass/fail, do not simulate review, and do not summarize gate/review status beyond engine output.

What it does

code-oz doctor runs a read-only health check across the installation, provider auth, and active run state. It produces no provider calls and incurs no provider spend. A first run may download the engine via npx if the binary is absent.

How to run it

bash "${CLAUDE_PLUGIN_ROOT}/scripts/resolve-code-oz.sh" doctor "$ARGUMENTS"

The resolver finds the engine via PATH binary, then npx fallback, then stops with install guidance. If it stops, surface that guidance verbatim; do not work around it.

This command has no provider spend, so run it without asking for confirmation.

Surface results

Relay the engine's stdout and stderr verbatim. If the engine writes a NEEDS_INTERVENTION.json, surface the file path verbatim and stop. Do not open it and do not decide pass/fail.

Boundaries

  • Do not write under .code-oz/ for any reason.
  • Do not declare or emit gate state (GATE_*).
  • Do not decide pass/fail from engine output.
  • Do not simulate or claim to perform cross-family review; the engine owns that.
  • If the engine exits non-zero, show the stderr to the user without paraphrasing.
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 34 lines · 17 tokens per session scan A ab0b8ec6b658

Subscribe to this mod's changes

code-oz-doctor is a command published in the GitHub repository omerakben/code-oz (2 stars, last pushed 2mo ago), licensed MIT. It adds 17 tokens to every session and 344 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.