codex_assistant AGENTS.md

Repository instructions for using Codex as an assistant, including a process for handling email-related tasks.

In plain words
What is it for?
Scanning relevant inboxes, drafting replies for confirmation, sending approved emails, and recording handled messages in a log.
Why use it?
They help keep email work focused on messages needing action and prevent handled or generic messages from being surfaced again.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/boazbk/codex_assistant/agents-md
Clone the repo
git clone --depth 1 https://github.com/boazbk/codex_assistant

Made for: Codex, OpenCode.

Per session 547 This file is loaded in full into every session.
When invoked 547 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00547 $0.00547
Opus 5 $0.00273 $0.00273
Sonnet 5 $0.00109 $0.00109
Haiku 4.5 $0.00055 $0.00055

Measured 2d ago against content hash ac7ea16c42d9, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

codex_assistant AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 18 lines

What it actually says

Email Handling Instructions

  1. For any email task in this repo, first read and follow skills/email-attention-flow/SKILL.md. Also use email_templates.md and log.md when relevant.
  2. If the user asks you to scan for emails that are meant for them, be diligent about checking all relevant addresses and aliases. Surface messages that are personal to the user or clearly require action, and filter out marketing, list mail, and generic announcements unless the user asks for them.
  3. Do not surface generic emails that are not personal to the user or do not require action unless the user explicitly asks for them.
  4. Filter out emails that log.md shows were already handled. If the user tells you to mark off an email, record it in log.md and do not surface it again. If you send an email for the user, add it to log.md.
  5. By default, if the user asks you to respond, draft, or reply and has not explicitly authorized immediate sending, do this for each email:
    • show an EMAIL block with the relevant incoming email
    • show a DRAFT block with the proposed response
    • ask for confirmation before sending
    • instructions such as say, reply, respond, forward, decline, tell them, or come up with a response are drafting instructions only and are not permission to send
    • only explicit send authorization such as send, email them, forward it now, do it, or send all standard templates allows immediate sending
    • if a mixed request contains some items with explicit send authorization and others without it, send only the explicitly authorized subset and draft the rest
  6. If the initial scan finds emails that match one of the categories in email_templates.md, group them together and propose using the standard template. If the user tells you to do that, send those standard-template replies directly; for those cases you do not need to show drafts first.
  7. If you send emails, always include the Gmail link to each email you sent.
  8. For recall-sensitive scans such as "surface all emails requiring my attention from the last X days/weeks", do not rely on a single Gmail search. Use a recall-first process that checks all relevant addresses, covers the whole timeframe, verifies against log.md, and explicitly calls out encrypted or ambiguous personal emails instead of silently dropping them.
  9. If the user responds only about some of the surfaced emails, do not lose track of the others. Keep a visible residual queue of actionable emails until they are handled, deferred, or marked off.
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 18 lines · 547 tokens per session scan A ac7ea16c42d9

Subscribe to this mod's changes

codex_assistant AGENTS.md is an instructions file published in the GitHub repository boazbk/codex_assistant (5 stars, last pushed 4mo ago), licensed MIT. It adds 547 tokens to every session, about $0.0027 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens