codex-bug

A process for diagnosing bug reports filed in the openai/codex GitHub repository, where developers report problems in the Codex project.

In plain words
What is it for?
It helps verify a report against the project, inspect its details and discussion, and recommend the next action.
Why use it?
It helps decide whether a report is reproducible, needs more information, or is not actually a bug.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/chemany/mente/codex-bug
Any agent
npx skills add chemany/Mente --skill codex-bug
Clone the repo
git clone --depth 1 https://github.com/chemany/Mente

Made for: Claude Code, Codex.

Per session 66 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 562 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00066 $0.00562
Opus 5 $0.00033 $0.00281
Sonnet 5 $0.00013 $0.00112
Haiku 4.5 $0.00007 $0.00056

Measured 2d ago against content hash cfdaae2defa5, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

codex-bug scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to codex-bug — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

kernel/codex/upstream/.codex/skills/codex-bug/SKILL.md · 49 lines

How it starts

The opening of the file, as written. The whole thing — 49 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Codex Bug

Overview

Diagnose a Codex GitHub bug report and decide the next action: verify against sources, request more info, or explain why it is not a bug.

Workflow

  1. Confirm the input
  • Require a GitHub issue URL that points to github.com/openai/codex/issues/….
  • If the URL is missing or not in the right repo, ask the user for the correct link.
  1. Network access
  • Always access the issue over the network immediately, even if you think access is blocked or unavailable.
  • Prefer the GitHub API over HTML pages because the HTML is noisy:
    • Issue: https://api.github.com/repos/openai/codex/issues/<number>
    • Comments: https://api.github.com/repos/openai/codex/issues/<number>/comments
  • If the environment requires explicit approval, request it on demand via the tool and continue without additional user prompting.
  • Only if the network attempt fails after requesting approval, explain what you can do offline (e.g., draft a response template) and ask how to proceed.
  1. Read the issue
  • Use the GitHub API responses (issue + comments) as the source of truth rather than scraping the HTML issue page.
  • Extract: title, body, repro steps, expected vs actual, environment, logs, and any attachments.
  • Note whether the report already includes logs or session details.
  • If the report includes a thread ID, mention it in the summary and use it to look up the logs and session details if you have access to them.
  1. Summarize the bug before investigating
  • Before inspecting code, docs, or logs in depth, write a short summary of the report in your own words.
  • Include the reported behavior, expected behavior, repro steps, environment, and what evidence is already attached or missing.
  1. Decide the course of action
  • Verify with sources when the report is specific and likely reproducible. Inspect relevant Codex files (or mention the files to inspect if access is unavailable).
  • Request more information when the report is vague, missing repro steps, or lacks logs/environment.
  • Explain not a bug when the report contradicts current behavior or documented constraints (cite the evidence from the issue and any local sources you checked).

Read the full file on GitHub · 49 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 49 lines · 66 tokens per session scan A cfdaae2defa5

Subscribe to this mod's changes

codex-bug is a skill published in the GitHub repository chemany/Mente (11 stars, last pushed 3mo ago), licensed MIT. It adds 66 tokens to every session and 562 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to codex-bug, differing in 0 lines, and is treated as a copy.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

next-cache-components-adoption

Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…

vercel/next.js · 95 tokens

babysit-pr

Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…

openai/codex · 114 tokens

imagegen

Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…

openai/codex · 113 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

next-cache-components-optimizer

Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…

vercel/next.js · 170 tokens