Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add instructions/codeprometheus/codex-buddy/claude-mdgit clone --depth 1 https://github.com/CodePrometheus/codex-buddyWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.01174 | $0.01174 |
| Opus 5 | $0.00587 | $0.00587 |
| Sonnet 5 | $0.00235 | $0.00235 |
| Haiku 4.5 | $0.00117 | $0.00117 |
Grade A, and why
codex-buddy CLAUDE.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 73 lines — stays where its author put it; the contents beside it link to each section on GitHub.
codex-buddy
A macOS CLI to switch between and run Codex CLI accounts in parallel. Logic lives in
crates/core; crates/cli is a thin shell. apps/tray is a SwiftUI menu-bar app (work in
progress) that reuses core through crates/ffi's uniffi bindings — same invariants, same
source of truth, no logic duplicated into Swift.
How it works (the invariant everything rests on)
Each account keeps one real auth.json in ~/.codex-buddy/<alias>/. ~/.codex/auth.json is a
symlink to the active account's file. Switching only repoints that symlink; auth files are never
copied. This sidesteps OAuth refresh-token rotation: a credential exists as exactly one file,
refreshed in place, so there is never a stale copy that would force a re-login.
- Switched (per account;
~/.codex/<entry>symlinks to the active account's copy):auth.json,sessions/,history.jsonl. - Isolated (per account, never shared or linked): all sqlite (
sqlite/dir,*.sqlite*). - Shared (symlinked back to
~/.codex): everything else — config.toml, AGENTS.md, rules, ... - Parallel = run codex with
CODEX_HOME=<account dir>; switch = repoint the switched symlinks.
Hard requirement: codex's cli_auth_credentials_store must be file (keyring / auto / ephemeral
move or delete auth.json and break the scheme). config_check enforces this.
Layout
crates/core— all logic, no CLI or interactive IO. Modules:paths,error,auth,registry,layout,config_check,init,ops,doctor,usage,history,recommend,transfer,remote,running. Unit tests live insrc/<module>/tests.rs.crates/cli— arg parsing (pico-args), prompts, output; delegates everything to core. New command families live undersrc/commands/, while reusable JSON/output DTOs live insrc/output.rs; keepmain.rsfocused on dispatch and shared presentation.crates/ffi— uniffi bindings overcorefor the Swift tray (list_accounts,switchAccount,addAccount, ...). Thin: no business logic, just type conversion.coreandclistay free of any FFI dependency.crates/ffi-bindgen— a separateuniffi-bindgenbinary crate that generates the Swift bindings from the builtcodex-buddy-ffilibrary. Split out so itsuniffi/clifeature (pulls inclap) never ends up in the shipped cdylib's dependency graph.apps/tray— the SwiftUI menu-bar app (Swift Package, not part of the Cargo workspace). Runapps/tray/Scripts/build-ffi.shfirst to build the xcframework + generate the Swift bindings (both gitignored, regenerated fromcrates/ffi), thenswift buildinsideapps/tray.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 73 lines · 1,174 tokens per session scan A f28c21539d2a
codex-buddy CLAUDE.md is an instructions file published in the GitHub repository CodePrometheus/codex-buddy (2 stars, last pushed 26d ago), licensed MIT. It adds 1,174 tokens to every session, about $0.0059 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other instructions, from other repositories
vibe AGENTS.md
Instructions for thewh1teagle/vibe, covering claude development notes, tooling, validation, skills and execution mindset.
vellum-assistant AGENTS.md
Instructions for vellum-ai/vellum-assistant, covering vellum assistant — agent instructions, project structure, intellectual honesty, development and dependencies.
warp AGENTS.md
AGENTS.md instructions for warpdotdev/warp, covering agents.md, development commands, build and run, running with local warp-server and connect to server on default port 8080.
terax-ai AGENTS.md
Instructions for crynta/terax-ai, a project described as: Lightweight (7MB) Terminal-first AI-native dev workspace.
diri AGENTS.md
Instructions for cristicretu/diri, covering diri repository instructions, scope, completed remote architecture baseline, rust workspace map and remote architecture invariants.
codex-profiles AGENTS.md
Instructions for Ducksss/codex-profiles, covering agents.md, what this project is, repository layout, setup, build, and test and how to run the tool.