Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/zts0hg/codexspec/codexspec-evolvenpx skills add Zts0hg/codexspec --skill codexspec-evolvegit clone --depth 1 https://github.com/Zts0hg/codexspecWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00025 | $0.01049 |
| Opus 5 | $0.00013 | $0.00524 |
| Sonnet 5 | $0.00005 | $0.00210 |
| Haiku 4.5 | $0.00003 | $0.00105 |
Grade A, and why
codexspec:evolve scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 77 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Evolve
Language Preference
Read .codexspec/config.yml. Two independent language controls apply (each falls back to language.output, then English):
- Interaction language (
language.interaction): language for all conversation with the user — questions, explanations, status messages, andcodexspecCLI terminal output. - Document language (
language.document): language for generated artifact files.
Converse in the interaction language. The compiled command/skill draft is a distributed template and MUST be authored in English (project i18n convention), regardless of language.document. PR title/body follow language.commit.
User Input
the text after the $codexspec:evolve skill mention
Operating Model
evolve turns vetted sediment in .codexspec/profile/ into a reusable capability and contributes it back to CodexSpec through a human-reviewed PR. It never merges unattended and never edits install artifacts.
Selecting what to promote
Promote only records that are both:
status: vetted(nevercandidateorconflict), and- general enough for the toolkit — the generality extension of distill's boundary test: "Is this useful to every CodexSpec user, or only to this project?"
Project-specific knowledge stays in the profile. Only generally-useful capability is promoted upstream. When nothing qualifies, stop and report — do not force a promotion.
This selection spans all six profile categories. strategies/ (metacognitive trigger → action rules) and runbooks/ (ordered multi-step procedures) are often the most promotable material — a vetted, general strategy or runbook compiles cleanly into a reusable skill/command — but they clear the same vetted gate as every other category; the gate is unchanged.
Compiling the draft
Compile the selected sediment into a SKILL.md / command-template draft that conforms to both:
- Anthropic Agent Skills (SKILL.md + progressive disclosure), and
- existing CodexSpec command-template conventions (YAML frontmatter + sections +
## Language Preference, English).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 77 lines · 25 tokens per session scan A eb3b48ebdeb8
codexspec:evolve is a skill published in the GitHub repository Zts0hg/codexspec (5 stars, last pushed 4d ago), licensed MIT. It adds 25 tokens to every session and 1,049 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
comet-classic
Comet Classic 工作流(OpenSpec + Superpowers)。当用户明确调用 /comet-classic、要求启动或恢复 Comet Classic,或 resume-probe 返回可无歧义恢复的 active Classic change 时使用。.
subagent-driven-development
Use when executing implementation plans with independent tasks in the current session.
comet-any
通过 Comet Creator 创建或升级 Comet Classic workflow Skill。不用于一般 Skill 的编写、整理或评审。.
observal-registry
Searches, recommends, bulk-submits, installs, edits, versions, archives, restores, transfers, and manages co-authors for Observal MCP servers, skills, hooks, prompts, and sandboxes. Use when the user wants to find components, publish one or many they control, install them into a harness, or manage their lifecycle.
agent-spec-tool-first
CRITICAL: Use for agent-spec CLI tool workflow. Triggers on: agent-spec, contract, lifecycle, guard, verify, explain, stamp, checkpoint, plan, requirements, work-units, knowledge requirements, KLL, docs vs knowledge, spec verification, task contract, spec quality, lint spec, run log, "how to verify", "how to use…
improve-harness
Run one explicitly authorized, evidence-backed improvement to a repository's agent guidance, tools, runbooks, or validation. Use only when the user invokes $improve-harness or explicitly asks to improve the Harness after observed reusable agent friction. Do not use for ordinary product changes, speculative cleanup…