code-oz-run

A command that advances an active code-oz run by one phase, or by one task during a multi-task build.

In plain words
What is it for?
It runs the next phase or task and returns the engine's output, stopping when the engine creates an intervention, pause, or stop record.
Why use it?
It moves a managed run forward while the code-oz engine handles provider calls, budgets, and checkpoints.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/omerakben/code-oz/code-oz-run
Clone the repo
git clone --depth 1 https://github.com/omerakben/code-oz
Per session 20 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 403 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00020 $0.00403
Opus 5 $0.00010 $0.00201
Sonnet 5 $0.00004 $0.00081
Haiku 4.5 $0.00002 $0.00040

Measured yesterday against content hash fc8d4b54a2be, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code-oz-run scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/code-oz/commands/code-oz-run.md · 36 lines

What it actually says

This command only invokes the code-oz engine. Do not write .code-oz/, do not decide pass/fail, do not simulate review, and do not summarize gate/review status beyond engine output.

What it does

code-oz run advances exactly one phase (or one task within a multi-task BUILD cycle) of the active run. The engine owns provider invocation, budget enforcement, and gate writes.

Cost notice

This command spawns providers, may cost money, and changes files in the worktree. Because you explicitly invoked it, you may proceed — state this in one line before running. If invoked ambiguously (not a clear user request), ask for one explicit confirmation first.

How to run it

bash "${CLAUDE_PLUGIN_ROOT}/scripts/resolve-code-oz.sh" run "$ARGUMENTS"

The resolver finds the engine via PATH binary, then npx fallback, then stops with install guidance. If it stops, surface that guidance verbatim; do not work around it.

Surface results

Relay the engine's stdout and stderr verbatim. If the engine writes a NEEDS_INTERVENTION.json, a PAUSE.json, or a STOP.json, surface the file path verbatim and stop. Do not open the file and do not decide pass/fail or summarize a verdict.

Boundaries

  • Do not write under .code-oz/ for any reason.
  • Do not declare or emit gate state (GATE_*); the engine is the only gate writer.
  • Do not decide pass/fail from engine output.
  • Do not simulate or claim to perform cross-family review; the engine owns that.
  • If the engine exits non-zero, show the stderr to the user without paraphrasing.
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 36 lines · 20 tokens per session scan A fc8d4b54a2be

Subscribe to this mod's changes

code-oz-run is a command published in the GitHub repository omerakben/code-oz (2 stars, last pushed 2mo ago), licensed MIT. It adds 20 tokens to every session and 403 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.