consult-codex

A workflow guide that asks the Codex AI service for a second opinion on a design, plan, code, or blocked task.

In plain words
What is it for?
Reviewing design documents, implementation plans, and code, or helping recover from a stuck task.
Why use it?
It adds an independent review when one AI opinion may miss a problem or when work has stalled.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/uta2000/feature-flow/consult-codex
Any agent
npx skills add uta2000/feature-flow --skill consult-codex
Clone the repo
git clone --depth 1 https://github.com/uta2000/feature-flow

Made for: Claude Code, Codex.

Per session 60 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,657 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00060 $0.01657
Opus 5 $0.00030 $0.00829
Sonnet 5 $0.00012 $0.00331
Haiku 4.5 $0.00006 $0.00166

Measured 2d ago against content hash 337244bff82a, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

consult-codex scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

The scan reads SKILL.md. This mod also ships 15 executable files (scripts/build-brief.js, scripts/build-brief.test.js, scripts/config.js, …), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/consult-codex/SKILL.md · 119 lines

How it starts

The opening of the file, as written. The whole thing — 119 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Consult Codex

Claude-orchestrated three-phase skill: subprocess Phase 1 → direct MCP call Phase 2 → subprocess Phase 3 → subprocess Phase 4 verdict. MCP tools like mcp__codex__codex are only callable from Claude's own context, so the skill is NOT a single script that runs end-to-end — it is an orchestration guide Claude follows.

When to invoke

Proactive (automatic, from other lifecycle skills):

  • mode: review-design — after writing a design doc, before verification (integrated into feature-flow:design-document)
  • mode: review-plan — after verify-plan-criteria mechanical check passes (deferred — follow-up plan)
  • mode: review-code — before Harden-PR step, after all tests pass (deferred)

Reactive (manual or auto-suggested):

  • mode: stuck — user typed stuck: or a signal-collector hook emitted a stuck suggestion (deferred — follow-up plan)

If invoking mode: stuck, consider calling advisor() first for a fast same-family check before spending a codex call.

Orchestration — follow these phases in order

Phase 1 — consult.js start

Run the start subprocess to check preconditions and build the brief.

FEATURE_FLOW_SESSION_ID=<session-id> \
FEATURE_FLOW_FEATURE=<feature-name> \
FEATURE_FLOW_WORKTREE=<abs-path-to-worktree> \
node skills/consult-codex/scripts/consult.js start --mode <mode> [--signal-key <key>]

Parse the JSON on stdout. Possible statuses:

  • "disabled" → stop. Codex is disabled. Report the message to the user. Skip the rest of this skill.
  • "skipped" → stop. A precondition (budget, escape-hatch, model-unresolvable) rejected this call. Report the reason.
  • "ready" → proceed to Phase 2 with the returned { brief, model, timeout_ms, worktree, mode, signal_key }.
  • "error" → stop. The CLI rejected the call (e.g., unknown mode). Surface the message to the user; do not proceed.

Optional: call advisor() to sanity-check the brief for missing context before invoking codex. Cheap same-family review prevents wasting a codex call on an ambiguous brief.

Read the full file on GitHub · 119 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 119 lines · 60 tokens per session scan A 337244bff82a

Subscribe to this mod's changes

consult-codex is a skill published in the GitHub repository uta2000/feature-flow (4 stars, last pushed 1mo ago), licensed MIT. It adds 60 tokens to every session and 1,657 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

brainstorming

You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.

obra/superpowers · 37 tokens

chat-pet-sprite-creation

Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.

microsoft/vscode · 53 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

agent-host-chat-contributions

Build and review cross-cutting agent-host chat behavior through lifecycle contributions. Use when adding turn lifecycle side effects, prompt or context injection, restored-history transformation, protocol-action observation, or when reviewing changes that add code to AgentSideEffects or AgentService.

microsoft/vscode · 56 tokens

auto-perf-optimize

Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.

microsoft/vscode · 62 tokens