codex-host: Instructions file for Codex

AGENTS.md

codex-host AGENTS.md is an instructions file for Codex, OpenCode from BytePioneer-AI/codex-host. It costs 1,080 tokens per session, scanned A, original, MIT.

Repository instructions for BytePioneer-AI/codex-host, a project combining native Rust code with a TypeScript workspace. They describe its folders, ownership boundaries, and build and release rules.

In plain words
What is it for?
Use them when changing the host, process launching, update installation, platform support, harness integrations, shared types, or release tooling.
Why use it?
They give coding agents the project context needed to place changes correctly and avoid crossing boundaries between Rust, TypeScript, browser code, and platform integration.

Instructions file for CodexOpenCode

Written for Codex and OpenCode: the file is AGENTS.md. Also seen: mentions Claude Code; mentions Codex.

This is BytePioneer-AI/codex-host's own configuration. It tells Codex and OpenCode how to work on codex-host itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything codex-host configures →

About the project

CodexHost is a desktop application that lets users run coding-agent harnesses such as Pi and Claude Code inside Codex Desktop. It is for people who want to choose among multiple agents and have them delegate tasks to one another while staying in one workspace.

BytePioneer-AI/codex-host · 2,026 stars · on GitHub

Reuse

Borrowing it

Nothing to install: this file belongs to BytePioneer-AI/codex-host. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/BytePioneer-AI/codex-host/main/AGENTS.md
Clone the repo
git clone --depth 1 https://github.com/BytePioneer-AI/codex-host

Made for: Codex, OpenCode.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for codex-host AGENTS.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/bytepioneer-ai/codex-host/agents-md/github.svg)](https://agentmods.dev/instructions/bytepioneer-ai/codex-host/agents-md)
Your own site
<a href="https://agentmods.dev/instructions/bytepioneer-ai/codex-host/agents-md"><img src="https://agentmods.dev/badge/instructions/bytepioneer-ai/codex-host/agents-md/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for codex-host AGENTS.md

Your own site · 80×15
<a href="https://agentmods.dev/instructions/bytepioneer-ai/codex-host/agents-md"><img src="https://agentmods.dev/badge/instructions/bytepioneer-ai/codex-host/agents-md.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 1,080 This file is loaded in full into every session.
When invoked 1,080 The same file — it is already loaded in full.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.01080 $0.01080
Opus 5 $0.00540 $0.00540
Sonnet 5 $0.00216 $0.00216
Haiku 4.5 $0.00108 $0.00108

Measured 2d ago against content hash 47ac5f94a6d6, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

codex-host AGENTS.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

AGENTS.md · 79 lines

How it starts

The opening of the file, as written. The whole thing — 79 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Repository Guidelines

Product Intent

codexhost runs external Agent Harnesses as independent Threads inside Codex Desktop, preserving the official shell and native Codex path. Integrate each Harness through its native interface; preserve its actual capabilities and semantics rather than inventing equivalent-looking Host behavior.

Code Layout

Native Rust

  • crates/
    • launcher/: native application launch
    • shim/: process proxying
    • updater/: update installation
    • platform/: cross-platform native integration

TypeScript Workspace

  • packages/
    • protocol-core/: Host protocol routing and projection
    • mapping-store/: external Thread metadata persistence
    • harness-adapter/: public Harness session and plugin contracts
    • harness-discovery/: Harness executable discovery and invocation helpers
    • harness-broker/: native Broker communication; currently retains Claude Code-specific semantics
    • adapters/: Harness-specific implementations and plugin entry points
    • desktop-control/: CDP / Electron Inspector-driven Desktop interaction
    • host-runtime/: Host composition and installed plugin loading
    • update-manager/: background update preparation
    • shared-contracts/: browser-safe types and runtime schemas
    • renderer-extension/: browser JavaScript extension

Build and Release

  • scripts/release/: release preparation, packaging, and publishing
  • tools/: development utilities and technical Gates

Boundary Rules

  • Rust owns native launch, process management, update installation, and platform integration. It must not own Host protocol or Harness semantics.
  • shared-contracts must remain browser-safe and independent of other Workspace packages.
  • renderer-extension must not import Node.js built-ins, Electron private APIs, or Harness SDKs.
  • Harness-specific protocol details must remain inside the corresponding Adapter.
  • Host Runtime loads installed plugins through public contracts, not direct imports of concrete Adapter packages. The preinstalled set belongs to scripts/release/harness-plugins.json, not Host registration code.
  • Use package public exports for cross-package dependencies. Read tools/check-boundaries.mjs before changing dependency directions; it is the executable boundary check run by npm run lint.

Read the full file on GitHub · 79 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago Changed · +6 lines · +251 tokens per session 47ac5f94a6d6
  2. 9d ago First seen · 73 lines · 829 tokens per session scan A eb96a395e41f

Subscribe to this mod's changes

codex-host AGENTS.md is an instructions file published in the GitHub repository BytePioneer-AI/codex-host (2,026 stars, last pushed today), licensed MIT. It adds 1,080 tokens to every session, about $0.0054 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,153 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens