Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/gatsby007max/codex-usage-heatmap/codex-usage-heatmapnpx skills add Gatsby007max/codex-usage-heatmap --skill codex-usage-heatmapgit clone --depth 1 https://github.com/Gatsby007max/codex-usage-heatmapWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/gatsby007max/codex-usage-heatmap/codex-usage-heatmap)<a href="https://agentmods.dev/skills/gatsby007max/codex-usage-heatmap/codex-usage-heatmap"><img src="https://agentmods.dev/badge/skills/gatsby007max/codex-usage-heatmap/codex-usage-heatmap.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00077 | $0.00523 |
| Opus 5 | $0.00039 | $0.00262 |
| Sonnet 5 | $0.00015 | $0.00105 |
| Haiku 4.5 | $0.00008 | $0.00052 |
Grade A, and why
codex-usage-heatmap scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Codex Usage Heatmap Skill
Purpose
Help maintain, debug, extend, release, and operate the codex-usage-heatmap project safely.
Non-negotiable Rules
- Never read or print auth.json, API keys, refresh tokens, access tokens, cookies, .env values, private keys, or credentials.
- Never include prompt text or model response text in generated reports.
- Never store raw logs.
- Treat Codex local log schemas as unstable.
- Prefer parser adapters and sanitized fixtures over hard-coded assumptions.
- Keep the tool local-only by default.
- Do not add network calls unless explicitly requested and documentation is updated.
- Keep all public repository content English-only.
- Before completing code changes, run:
pnpm lintpnpm typecheckpnpm testpnpm buildpnpm check:language
Common Workflows
Add Support for a New Codex Log Shape
- Add a sanitized fixture under
fixtures/. - Add or update a parser adapter in
src/parsers/. - Normalize into
NormalizedUsageEvent. - Add tests for:
- valid event
- missing timestamp
- malformed line
- no prompt or response leakage
- no credential leakage
- Run verification commands.
Debug Missing Usage
- Run
pnpm dev doctor. - Confirm discovered paths.
- Confirm readable JSONL count.
- Confirm usage event count.
- Inspect only keys and metadata, not message content.
- Add a sanitized fixture for the observed structure if safe.
Prepare a Release
- Run full checks.
- Generate sample report.
- Confirm README commands work.
- Confirm no generated report contains local absolute paths by default.
- Confirm npm package files are limited using package.json
files. - Update
CHANGELOG.mdif needed.
Output Format for Codex
When making changes to this project, summarize:
- changed files
- tests run
- privacy/security impact
- known limitations
- follow-up recommendations
What ships with it
6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 71 lines · 77 tokens per session scan A 00bf1142b2f8
codex-usage-heatmap is a skill published in the GitHub repository Gatsby007max/codex-usage-heatmap (1 stars, last pushed 3mo ago), licensed MIT. It adds 77 tokens to every session and 523 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
git-workflow
This skill should be used when the user asks to "create git commit", "manage branches", "follow git workflow", "use Conventional Commits", "handle merge conflicts", or asks about git branching strategies, version control best practices, pull request workflows. Provides comprehensive Git workflow guidance for team…
daily-paper-generator
Use when the user asks to generate daily paper digests on a general topic. This skill supports both arXiv and bioRxiv (or either one), then produces structured Chinese/English summaries for selected papers.
codex-autoresearch
Run autonomous, measurable experiments in a Git repository: change one hypothesis, verify a numeric metric, keep improvements, and revert failures. Use when the user wants Codex to keep iterating toward a numeric target in the foreground or as a detached background run. Do not use for ordinary one-shot coding…
map-wayfind
Decision-frontier wayfinding: build and work a durable map of open design decisions BEFORE planning, for large or foggy efforts where /map-plan would force premature decomposition. Use when a task is too big or too vague to decompose — many unknowns, tangled decisions, or "I'm not even sure what to build yet" — and…
map-fast
Minimal workflow for small, low-risk changes — no planning, no learning.
clipboard
Copy text to clipboard with optional rich formatting. Triggers on "copy to clipboard", "copy that", "pbcopy", "copy formatted", "copy rich text".