code-oz-init

A setup command that creates the code-oz configuration directory and writes its default configuration for the current repository.

In plain words
What is it for?
Use it once when starting code-oz in a repository, after confirming that the current directory is the intended project.
Why use it?
It prepares a repository for a code-oz run without requiring the agent to create the configuration files manually.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/omerakben/code-oz/code-oz-init
Clone the repo
git clone --depth 1 https://github.com/omerakben/code-oz
Per session 20 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 375 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00020 $0.00375
Opus 5 $0.00010 $0.00187
Sonnet 5 $0.00004 $0.00075
Haiku 4.5 $0.00002 $0.00038

Measured yesterday against content hash ef3efe84f324, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code-oz-init scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/code-oz/commands/code-oz-init.md · 35 lines

What it actually says

This command only invokes the code-oz engine. Do not write .code-oz/, do not decide pass/fail, do not simulate review, and do not summarize gate/review status beyond engine output.

What it does

code-oz init creates the .code-oz/ directory, writes the default config.yaml, and prepares the repo for a code-oz run. The engine is the only writer; this command is a launcher.

How to run it

bash "${CLAUDE_PLUGIN_ROOT}/scripts/resolve-code-oz.sh" init "$ARGUMENTS"

The resolver finds the engine via PATH binary, then npx fallback, then stops with install guidance. If it stops, surface that guidance verbatim; do not work around it.

Confirm the working directory is the repo the user wants to scaffold, then run.

Surface results

Relay the engine's stdout and stderr verbatim. If the engine writes a NEEDS_INTERVENTION.json, surface the file path verbatim and stop. Do not open it and do not decide pass/fail.

Boundaries

  • Do not write under .code-oz/ for any reason; the engine is the only writer.
  • Do not declare or emit gate state (GATE_*).
  • Do not decide pass/fail from engine output.
  • Do not simulate or claim to perform cross-family review; the engine owns that.
  • Do not run init --force without explicit user approval — --force overwrites an existing run.
  • If the engine exits non-zero, show the stderr to the user without paraphrasing.
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 35 lines · 20 tokens per session scan A ef3efe84f324

Subscribe to this mod's changes

code-oz-init is a command published in the GitHub repository omerakben/code-oz (2 stars, last pushed 2mo ago), licensed MIT. It adds 20 tokens to every session and 375 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.