Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/sd0xdev/sd0x-harness/codex-setupnpx skills add sd0xdev/sd0x-harness --skill codex-setupgit clone --depth 1 https://github.com/sd0xdev/sd0x-harnessWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00065 | $0.14203 |
| Opus 5 | $0.00032 | $0.07101 |
| Sonnet 5 | $0.00013 | $0.02841 |
| Haiku 4.5 | $0.00006 | $0.01420 |
Grade A, and why
codex-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 683 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Codex Setup
Trigger
- Keywords: codex setup, codex init, agents.md, setup codex, initialize codex, codex doctor, codex sync
- After:
npx skills add sd0xdev/sd0x-harness
Subcommands
| Command | Purpose |
|---|---|
init |
First-time setup: generate AGENTS.md + install the commit-msg hook + copy scripts |
doctor |
Verify installation integrity: files exist, AGENTS.md hash matches, and each recorded hook is active — hook bytes are sync's axis, not this one (§ doctor) |
sync |
Re-generate AGENTS.md + update installed hooks/scripts after skill update |
Default (no subcommand): init
Arguments
| Flag | Applies to | Effect |
|---|---|---|
--with-push-gate |
init, sync |
Install pre-push-gate.sh as the pre-push hook. Off by default |
The pre-push gate is the one hook that waits for a human — it reads /dev/tty,
so from a non-interactive context it stalls or fails on a terminal that is not there.
That is why it is opt-in, and why every path below reads that choice from state rather
than re-deciding it. commit-msg stays a default install because it never prompts:
it guards the attribution anchor (CLAUDE.md rule 3) by reading the message and
deciding, with no /dev/tty and no input. It does still reject — exit 1 on a
policy violation, exit 3 when the policy cannot be evaluated — and it rejects
interactive and non-interactive commits alike (scripts/commit-msg-guard.sh). The
distinction that makes it safe to install by default is prompts vs. rejects, not
blocks vs. does not block.
The flag is the opt-in interface — there is no prompt. init must not ask
interactively whether to install the gate: this skill runs under Codex sandboxes and
in non-interactive setup flows where an unanswered prompt would either hang or be
silently defaulted, and a silent default is exactly what opt-in exists to prevent.
init
Phase 1: Detect Host Context
- Find repo root:
git rev-parse --show-toplevel - Read
package.jsonif present → extractname,scripts.test - Read
.claude/CLAUDE.mdorCLAUDE.md→ extract test command pattern - Detect plugin root: find
scripts/build-codex-artifacts.jsrelative to this skill
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 683 lines · 65 tokens per session scan A 933b76964a46
codex-setup is a skill published in the GitHub repository sd0xdev/sd0x-harness (188 stars, last pushed 2d ago), licensed MIT. It adds 65 tokens to every session and 14,203 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
comet-safe-delivery
在保护无关脏改动、关联 worktree、子模块和用户明确边界的前提下,提交、推送、合并或完成范围明确的 Comet 变更。用户要求提交、推送、合并回目标分支、清理 worktree 或交付已准备好的改动时使用。.
git-workflow-and-versioning
Structures git workflow practices. Use when making any code change. Use when committing, branching, resolving conflicts, opening or reviewing a pull request (PR), pushing to a remote, or when you need to organize work across multiple parallel streams. Use when cutting a release, choosing a semantic version bump…
make-skill
Use this skill when sedimenting a session into a reusable workspace skill. Triggers when the user wants to turn the current conversation, workflow, or troubleshooting path into a SKILL.md. Phrases like 'turn this into a skill', 'remember how I did X', 'save this workflow', 'make a skill from this', and any /make-skill…
make-skill
用于把当前会话沉淀为可复用的 workspace skill。当用户希望把当前对话、工作流或排错路径写成 SKILL.md 时触发。触发表达包括「把这个变成 skill」「记住我是怎么做 X 的」「保存这个工作流」「make a skill from this」以及任何 /make-skill 调用。.
terraform-skill
Use when working with Terraform or OpenTofu - creating modules, writing tests (native test framework, Terratest), setting up CI/CD pipelines, reviewing configurations, choosing between testing approaches, debugging state issues, implementing security scanning (trivy, checkov), or making infrastructure-as-code…
docx
当用户需要创建、读取、编辑或处理 Word 文档(.docx)时,使用此技能。触发场景包括提到“Word 文档”、“.docx”,或要求生成带目录、标题、页码、信头等格式的专业文档;也包括提取或重组 .docx 内容、插入或替换图片、在 Word 文件中查找替换、处理修订或批注,以及将内容整理为正式 Word 文档。如果用户要求生成“报告”“备忘录”“信函”“模板”等 Word / .docx 交付物,也应使用此技能。不要用于 PDF、电子表格、Google Docs,或与文档生成无关的一般编程任务。.