Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/omerakben/code-oz/code-oz-initgit clone --depth 1 https://github.com/omerakben/code-ozWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00020 | $0.00375 |
| Opus 5 | $0.00010 | $0.00187 |
| Sonnet 5 | $0.00004 | $0.00075 |
| Haiku 4.5 | $0.00002 | $0.00038 |
Grade A, and why
code-oz-init scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
This command only invokes the code-oz engine. Do not write .code-oz/, do not decide pass/fail, do not simulate review, and do not summarize gate/review status beyond engine output.
What it does
code-oz init creates the .code-oz/ directory, writes the default config.yaml, and prepares the repo for a code-oz run. The engine is the only writer; this command is a launcher.
How to run it
bash "${CLAUDE_PLUGIN_ROOT}/scripts/resolve-code-oz.sh" init "$ARGUMENTS"
The resolver finds the engine via PATH binary, then npx fallback, then stops with install guidance. If it stops, surface that guidance verbatim; do not work around it.
Confirm the working directory is the repo the user wants to scaffold, then run.
Surface results
Relay the engine's stdout and stderr verbatim. If the engine writes a NEEDS_INTERVENTION.json, surface the file path verbatim and stop. Do not open it and do not decide pass/fail.
Boundaries
- Do not write under
.code-oz/for any reason; the engine is the only writer. - Do not declare or emit gate state (
GATE_*). - Do not decide pass/fail from engine output.
- Do not simulate or claim to perform cross-family review; the engine owns that.
- Do not run
init --forcewithout explicit user approval —--forceoverwrites an existing run. - If the engine exits non-zero, show the stderr to the user without paraphrasing.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 35 lines · 20 tokens per session scan A ef3efe84f324
code-oz-init is a command published in the GitHub repository omerakben/code-oz (2 stars, last pushed 2mo ago), licensed MIT. It adds 20 tokens to every session and 375 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
annotate-plan
Draft a plan and open it in the annotator UI for user review.
docs
Command "docs" from tilework-tech/nori-skillsets, covering noridoc: commands, how it fits into the larger codebase, core implementation and things to know.
add
Register a plugin in the catalog — reference a remote repo or scaffold a template.
init
Scaffold a new plugin marketplace, or a standalone plugin.
build
Generate the Codex and Cursor registries from the catalog.
bump
Version a local plugin from its commits and sync everything downstream.