Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/omerakben/code-oz/code-oz-rungit clone --depth 1 https://github.com/omerakben/code-ozWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00020 | $0.00403 |
| Opus 5 | $0.00010 | $0.00201 |
| Sonnet 5 | $0.00004 | $0.00081 |
| Haiku 4.5 | $0.00002 | $0.00040 |
Grade A, and why
code-oz-run scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
This command only invokes the code-oz engine. Do not write .code-oz/, do not decide pass/fail, do not simulate review, and do not summarize gate/review status beyond engine output.
What it does
code-oz run advances exactly one phase (or one task within a multi-task BUILD cycle) of the active run. The engine owns provider invocation, budget enforcement, and gate writes.
Cost notice
This command spawns providers, may cost money, and changes files in the worktree. Because you explicitly invoked it, you may proceed — state this in one line before running. If invoked ambiguously (not a clear user request), ask for one explicit confirmation first.
How to run it
bash "${CLAUDE_PLUGIN_ROOT}/scripts/resolve-code-oz.sh" run "$ARGUMENTS"
The resolver finds the engine via PATH binary, then npx fallback, then stops with install guidance. If it stops, surface that guidance verbatim; do not work around it.
Surface results
Relay the engine's stdout and stderr verbatim. If the engine writes a NEEDS_INTERVENTION.json, a PAUSE.json, or a STOP.json, surface the file path verbatim and stop. Do not open the file and do not decide pass/fail or summarize a verdict.
Boundaries
- Do not write under
.code-oz/for any reason. - Do not declare or emit gate state (
GATE_*); the engine is the only gate writer. - Do not decide pass/fail from engine output.
- Do not simulate or claim to perform cross-family review; the engine owns that.
- If the engine exits non-zero, show the stderr to the user without paraphrasing.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 36 lines · 20 tokens per session scan A fc8d4b54a2be
code-oz-run is a command published in the GitHub repository omerakben/code-oz (2 stars, last pushed 2mo ago), licensed MIT. It adds 20 tokens to every session and 403 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other commands, from other repositories
annotate-plan
Draft a plan and open it in the annotator UI for user review.
docs
Command "docs" from tilework-tech/nori-skillsets, covering noridoc: commands, how it fits into the larger codebase, core implementation and things to know.
add
Register a plugin in the catalog — reference a remote repo or scaffold a template.
init
Scaffold a new plugin marketplace, or a standalone plugin.
build
Generate the Codex and Cursor registries from the catalog.
bump
Version a local plugin from its commits and sync everything downstream.