Skip to content

feat(codex): add portable subagent pack - #2

Open
craigknott wants to merge 9 commits into
mainfrom
agent/share-codex-agents
Open

feat(codex): add portable subagent pack#2
craigknott wants to merge 9 commits into
mainfrom
agent/share-codex-agents

Conversation

@craigknott

@craigknott craigknott commented Aug 6, 2026

Copy link
Copy Markdown
Owner

Intent

Share and maintain a minimal portable Codex subagent pack in the ~/.agents repository. The portable codex/AGENTS.md must mirror the shareable structure of the user current ~/.codex/AGENTS.md by beginning with explicit references to ~/.agents/AGENTS.md, portable Codex RTK guidance, shared Context7 research guidance, and shared subagent guidance, followed by Codex-specific role routing, model/effort mapping, task-capsule policy, and fork_turns guidance. Do not ship a machine-local path or any credentials. The installer must preserve Codex AGENTS.override.md precedence, existing content, unrelated agents, and config.toml; install the five named roles; remain repeatable; and keep multi_agent_v2=false.

What Changed

  • Add a portable Codex instruction pack with RTK and research guidance plus five role definitions and bounded-context routing.
  • Add an idempotent $CODEX_HOME installer that preserves instruction precedence, existing content, unrelated agents, and config.toml.
  • Document setup and multi_agent_v2 = false, with end-to-end coverage for portability, repeat installs, and preserved user configuration.

Risk Assessment

✅ Low: The portable Codex pack and installer are well-bounded and satisfy the source-verifiable requirements for instruction ordering, role installation, preservation, repeatability, portability, and multi_agent_v2=false guidance.

Testing

Inspected the base-to-target scope, ran the focused installer test across default, fallback, and override homes, verified preservation, repeatability, portability and feature settings, confirmed both loader paths through Codex’s resolved prompt input, captured reviewer evidence, and confirmed the worktree remained unchanged at the target commit; all checks passed.

Evidence: Focused installer test

Installer checks passed for the default home, AGENTS.md fallback, and AGENTS.override.md precedence.

Installer checks passed for the default home, AGENTS.md fallback, and AGENTS.override.md precedence.
Evidence: End-user installation transcript
Portable Codex pack end-user evidence
Portable instruction header:
@~/.agents/AGENTS.md
@~/.agents/codex/RTK.md
@~/.agents/instructions/research.md
@~/.agents/instructions/subagents.md
Fallback install output:
Installed five Codex agents in /var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/fallback-home/agents
Updated Codex instruction directives in /var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/fallback-home/AGENTS.md
Fallback AGENTS.md after install:
# Keep this fallback instruction.

Read and follow `~/.agents/codex/AGENTS.md` for Codex-specific subagent routing and context rules.
Override install output:
Installed five Codex agents in /var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/override-home/agents
Updated Codex instruction directives in /var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/override-home/AGENTS.override.md
Active AGENTS.override.md after install:
# Keep this active override.

Read and follow `~/.agents/codex/AGENTS.md` for Codex-specific subagent routing and context rules.
Preserved inactive AGENTS.md:
# Keep this inactive instruction.
Preserved config.toml and unrelated role:
model = "override-sentinel"
name = "unrelated-override"
Five installed default-home roles:
bulk_scout.toml
docs_researcher.toml
explorer.toml
reviewer.toml
worker.toml
Repeat install output:
Installed five Codex agents in /var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/fallback-home/agents
Updated Codex instruction directives in /var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/fallback-home/AGENTS.md
repeat_install_content_unchanged=yes
portable_machine_local_path_scan=clean
portable_credential_pattern_scan=clean
Documented feature setting:
multi_agent_v2 = false
Evidence: Codex default-loader prompt resolution
[
  {
    "type": "message",
    "id": "msg_019fd9e1-ed5e-79d3-ac7d-59dfca5613c4",
    "role": "developer",
    "content": [
      {
        "type": "input_text",
        "text": "<skills_instructions>\n## Skills\nA skill is a set of instructions provided through a `SKILL.md` source. Below is the list of skills that can be used. Each entry includes a name, description, and source locator. `file` locators are on the host filesystem, `environment resource` locators are owned by an execution environment, `orchestrator resource` locators are opaque non-filesystem resources, and `custom resource` locators use their provider's access mechanism.\n### Available skills\n- imagegen: Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output should be a bitmap asset rather than repo-native code or vector. Do not use when the task is better handled by editing existing SVG/vector/code-native assets, extending an established icon or logo system, or building the visual directly in HTML/CSS/canvas. (file: /private/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/default-user-home/.codex/skills/.system/imagegen/SKILL.md)\n- openai-docs: Use when the user asks how to build with OpenAI products or APIs, asks about Codex itself or choosing Codex surfaces, needs up-to-date official documentation with citations, help choosing the latest model for a use case, latest/current/default-model prompting guidance, or model upgrade and prompt-upgrade guidance; use OpenAI docs MCP tools for non-Codex docs questions, use the Codex manual helper first for broad Codex self-knowledge, and restrict fallback browsing to official OpenAI domains. (file: /private/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/default-user-home/.codex/skills/.system/openai-docs/SKILL.md)\n- plugin-creator: Create and scaffold plugin directories for Codex with a required `.codex-plugin/plugin.json`, optional plugin folders/files, valid manifest defaults, and personal-marketplace entries by default. Use when Codex needs to create a new personal plugin, add optional plugin structure, generate or update marketplace entries for plugin ordering and availability metadata, or update an existing local plugin during development with the CLI-driven cachebuster and reinstall flow. (file: /private/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/default-user-home/.codex/skills/.system/plugin-creator/SKILL.md)\n- skill-creator: Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Codex's capabilities with specialized knowledge, workflows, or tool integrations. (file: /private/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/default-user-home/.codex/skills/.system/skill-creator/SKILL.md)\n- skill-installer: Install Codex skills into $CODEX_HOME/skills from a curated list or a GitHub repo path. Use when a user asks to list installable skills, install a curated skill, or install a skill from another repo (including private repos). (file: /private/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/default-user-home/.codex/skills/.system/skill-installer/SKILL.md)\n- context7-mcp: This skill should be used when the user asks about libraries, frameworks, API references, or needs code examples. Activates for setup questions, code generation involving libraries, or mentions of specific frameworks like React, Vue, Next.js, Prisma, Supabase, etc. (file: /Users/cortana/.agents/skills/context7-mcp/SKILL.md)\n- no-mistakes: Validate your code changes through the no-mistakes pipeline - automated code review, tests, lint, docs, push, PR, and CI - before they reach the configured push target. Use when the user asks to run no-mistakes, gate or ship or validate their changes, push safely, asks you to do a task and then validate it, or invokes /no-mistakes. (file: /Users/cortana/.agents/skills/no-mistakes/SKILL.md)\n</skills_instructions>"
      },
      {
        "type": "input_text",
        "text": "<permissions instructions>\nFilesystem sandboxing defines which files can be read or written. `sandbox_mode` is `read-only`: The sandbox only permits reading files. Network access is restricted.\n# Escalation Requests\n\nCommands are run outside the sandbox if they are approved by the user, or match an existing rule that allows it to run unrestricted. The command string is split into independent command segments at shell control operators, including but not limited to:\n\n- Pipes: |\n- Logical operators: &&, ||\n- Command separators: ;\n- Subshell boundaries: (...), $(...)\n\nEach resulting segment is evaluated independently for sandbox restrictions and approval requirements.\n\nExample:\n\ngit pull | tee output.txt\n\nThis is treated as two command segments:\n\n[\"git\", \"pull\"]\n\n[\"tee\", \"output.txt\"]\n\nCommands that use more advanced shell features like redirection (>, >>, <), substitutions ($(...), ...), environment variables (FOO=bar), or wildcard patterns (*, ?) will not be evaluated against rules, to limit the scope of what an approved rule allows.\n\n## How to request escalation\n\nIMPORTANT: To request approval to execute a command that will require escalated privileges:\n\n- Provide the `sandbox_permissions` parameter with the value `\"require_escalated\"`\n- Include a short question asking the user if they want to allow the action in `justification` parameter. e.g. \"Do you want to download and install dependencies for this project?\"\n- Optionally suggest a `prefix_rule` - this will be shown to the user with an option to persist the rule approval for future sessions.\n\nIf you run a command that is important to solving the user's query, but it fails because of sandboxing or with a likely sandbox-related network error (for example DNS/host resolution, registry/index access, or dependency download failure), rerun the command with \"require_escalated\". ALWAYS proceed to use the `justification` parameter - do not message the user before requesting approval for the command.\n\n## When to request escalation\n\nWhile commands are running inside the sandbox, here are some scenarios that will require escalation outside the sandbox:\n\n- You need to run a command that writes to a directory that requires it (e.g. running tests that write to /var)\n- You need to run a GUI app (e.g., open/xdg-open/osascript) to open browsers or files.\n- If you run a command that is important to solving the user's query, but it fails because of sandboxing or with a likely sandbox-related network error (for example DNS/host resolution, registry/index access, or dependency download failure), rerun the command with `require_escalated`. ALWAYS proceed to use the `sandbox_permissions` and `justification` parameters. do not message the user before requesting approval for the command.\n- You are about to take a potentially destructive action such as an `rm` or `git reset` that the user did not explicitly ask for.\n- Be judicious with escalating, but if completing the user's request requires it, you should do so - don't try and circumvent approvals by using other tools.\n\n## prefix_rule guidance\n\nWhen choosing a `prefix_rule`, request one that will allow you to fulfill similar requests from the user in the future without re-requesting escalation. It should be categorical and reasonably scoped to similar capabilities. You should rarely pass the entire command into `prefix_rule`.\n\n### Banned prefix_rules \nAvoid requesting overly broad prefixes that the user would be ill-advised to approve. For example, do not request [\"python3\"], [\"python\", \"-\"], or other similar prefixes that would allow arbitrary scripting.\nNEVER provide a prefix_rule argument for destructive commands like rm.\nNEVER provide a prefix_rule if your command uses a heredoc or herestring. \n\n### Examples\nGood examples of prefixes:\n- [\"npm\", \"run\", \"dev\"]\n- [\"gh\", \"pr\", \"check\"]\n- [\"cargo\", \"test\"]\n</permissions instructions>"
      }
    ],
    "internal_chat_message_metadata_passthrough": {
      "turn_id": "auto-compact-0"
    }
  },
  {
    "type": "message",
    "id": "msg_019fd9e1-ed5e-79d3-ac7d-59e109f43d09",
    "role": "developer",
    "content": [
      {
        "type": "input_text",
        "text": "You are `/root`, the primary agent in a team of agents collaborating to fulfill the user's goals.\n\nAt the start of your turn, you are the active agent.\nYou can spawn sub-agents to handle subtasks, and those sub-agents can spawn their own sub-agents.\nAll agents in the team, including the agents that you can assign tasks to, are equally intelligent and capable, and have access to the same set of tools.\n\nYou can use `spawn_agent` to create a new agent, `followup_task` to give an existing agent a new task and trigger a turn, and `send_message` to pass a message to a running agent without triggering a turn.\nChild agents can also spawn their own sub-agents.\nYou can decide how much context you want to propagate to your sub-agents with the `fork_turns` parameter.\n\nYou will receive messages in the analysis channel in the form:\n`` `\nMessage Type: MESSAGE | FINAL_ANSWER\nTask name: <recipient>\nSender: <author>\nPayload:\n<payload text>\n`` `\nThey may be addressed as to=/root\n\nNote that collaboration tools cannot be called from inside `functions.exec`. Call `spawn_agent`, `send_message`, `followup_task`, `wait_agent`, `interrupt_agent`, and `list_agents` only as direct tool calls using the recipient shown in their tool definitions, such as `to=functions.collaboration.spawn_agent`, since they are intentionally absent from the `functions.exec` `tools.*` namespace. Available tools in `functions.exec` are explicitly described with a `tools` namespace in the developer message.\n\nAll agents share the same directory. In detail:\n- All agents have access to the same container and filesystem as you.\n- All agents use the same current working directory.\n- As a result, edits made by one agent are immediately visible to all other agents.\n\nThere are 4 available concurrency slots, meaning that up to 4 agents can be active at once, including you.\n\nFull-history forks (`fork_turns` omitted or `\"all\"`) inherit the parent model and reasoning effort and do not accept overrides. Only set `model` or `reasoning_effort` when explicitly requested by the user, applicable `AGENTS.md` instructions, or skill instructions; when doing so, set `fork_turns` to `\"none\"` or a positive integer string."
      }
    ],
    "internal_chat_message_metadata_passthrough": {
      "turn_id": "auto-compact-0"
    }
  },
  {
    "type": "message",
    "id": "msg_019fd9e1-ed5e-79d3-ac7d-59fee38d0d6c",
    "role": "developer",
    "content": [
      {
        "type": "input_text",
        "text": "<multi_agent_mode>Any earlier instruction enabling proactive multi-agent delegation no longer applies. Do not spawn sub-agents unless the user or applicable AGENTS.md/skill instructions explicitly ask for sub-agents, delegation, or parallel agent work.</multi_agent_mode>"
      }
    ],
    "internal_chat_message_metadata_passthrough": {
      "turn_id": "auto-compact-0"
    }
  },
  {
    "type": "message",
    "id": "msg_019fd9e1-ed5e-79d3-ac7d-5a09845e9b6f",
    "role": "user",
    "content": [
      {
        "type": "input_text",
        "text": "# AGENTS.md instructions for /Users/cortana/.no-mistakes/worktrees/024dd2779621/01KZCXKB1GZVETPHX55VCGGQD5\n\n<INSTRUCTIONS>\nRead and follow `~/.agents/codex/AGENTS.md` for Codex-specific subagent routing and context rules.\n\n--- project-doc ---\n\n# Global Agent Defaults\n\nThis repository contains cross-repository preferences for coding agents. Keep these instructions focused on outcomes and\nproject conventions; defer safety, permissions, tool mechanics, and communication behavior to the active harness.\n\nWithin this instruction layer, repository-specific guidance and checked-in workflows take precedence. Read only the\ntopic files relevant to the current task.\n\n## Topics\n\n- `instructions/workflow.md` — Repository discovery, implementation design, reuse, coding style, and validation.\n- `instructions/subagents.md` — Read before delegating: permission, decision criteria, routing, scoping, and\n  integration.\n- `instructions/package-managers.md` — Package-manager selection and dependency changes.\n- `instructions/code-review.md` — Reviews, findings, and risk classification.\n- `instructions/git-and-pr.md` — Branches, commits, pushes, pull requests, and `no-mistakes`.\n- `instructions/reliability.md` — Async, distributed, migration, and operational changes.\n- `instructions/frontend.md` — UI implementation, design preferences, and visual verification.\n- `instructions/research.md` — Third-party and OpenAI documentation.\n- `instructions/artifacts.md` — Documents, notebooks, PDFs, slides, and generated media.\n\n</INSTRUCTIONS>"
      },
      {
        "type": "input_text",
        "text": "<environment_context>\n  <cwd>/Users/cortana/.no-mistakes/worktrees/024dd2779621/01KZCXKB1GZVETPHX55VCGGQD5</cwd>\n  <shell>zsh</shell>\n  <current_date>2026-08-06</current_date>\n  <timezone>America/Chicago</timezone>\n  <filesystem><workspace_roots><root>/Users/cortana/.no-mistakes/worktrees/024dd2779621/01KZCXKB1GZVETPHX55VCGGQD5</root></workspace_roots><permission_profile type=\"managed\"><file_system type=\"restricted\"><entry access=\"read\"><special>:root</special></entry></file_system></permission_profile></filesystem>\n</environment_context>"
      }
    ],
    "internal_chat_message_metadata_passthrough": {
      "turn_id": "auto-compact-0"
    }
  },
  {
    "type": "message",
    "id": "msg_019fd9e1-ed5e-79d3-ac7d-5a1685847096",
    "role": "user",
    "content": [
      {
        "type": "input_text",
        "text": "Verify installed Codex loader."
      }
    ],
    "internal_chat_message_metadata_passthrough": {
      "turn_id": "auto-compact-0"
    }
  }
]
Evidence: Codex override-precedence prompt resolution
[
  {
    "type": "message",
    "id": "msg_019fd9e2-ad16-7bd0-ac5d-a015633e2141",
    "role": "developer",
    "content": [
      {
        "type": "input_text",
        "text": "<skills_instructions>\n## Skills\nA skill is a set of instructions provided through a `SKILL.md` source. Below is the list of skills that can be used. Each entry includes a name, description, and source locator. `file` locators are on the host filesystem, `environment resource` locators are owned by an execution environment, `orchestrator resource` locators are opaque non-filesystem resources, and `custom resource` locators use their provider's access mechanism.\n### Available skills\n- imagegen: Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output should be a bitmap asset rather than repo-native code or vector. Do not use when the task is better handled by editing existing SVG/vector/code-native assets, extending an established icon or logo system, or building the visual directly in HTML/CSS/canvas. (file: /private/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/override-home/skills/.system/imagegen/SKILL.md)\n- openai-docs: Use when the user asks how to build with OpenAI products or APIs, asks about Codex itself or choosing Codex surfaces, needs up-to-date official documentation with citations, help choosing the latest model for a use case, latest/current/default-model prompting guidance, or model upgrade and prompt-upgrade guidance; use OpenAI docs MCP tools for non-Codex docs questions, use the Codex manual helper first for broad Codex self-knowledge, and restrict fallback browsing to official OpenAI domains. (file: /private/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/override-home/skills/.system/openai-docs/SKILL.md)\n- plugin-creator: Create and scaffold plugin directories for Codex with a required `.codex-plugin/plugin.json`, optional plugin folders/files, valid manifest defaults, and personal-marketplace entries by default. Use when Codex needs to create a new personal plugin, add optional plugin structure, generate or update marketplace entries for plugin ordering and availability metadata, or update an existing local plugin during development with the CLI-driven cachebuster and reinstall flow. (file: /private/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/override-home/skills/.system/plugin-creator/SKILL.md)\n- skill-creator: Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Codex's capabilities with specialized knowledge, workflows, or tool integrations. (file: /private/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/override-home/skills/.system/skill-creator/SKILL.md)\n- skill-installer: Install Codex skills into $CODEX_HOME/skills from a curated list or a GitHub repo path. Use when a user asks to list installable skills, install a curated skill, or install a skill from another repo (including private repos). (file: /private/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e/override-home/skills/.system/skill-installer/SKILL.md)\n- context7-mcp: This skill should be used when the user asks about libraries, frameworks, API references, or needs code examples. Activates for setup questions, code generation involving libraries, or mentions of specific frameworks like React, Vue, Next.js, Prisma, Supabase, etc. (file: /Users/cortana/.agents/skills/context7-mcp/SKILL.md)\n- no-mistakes: Validate your code changes through the no-mistakes pipeline - automated code review, tests, lint, docs, push, PR, and CI - before they reach the configured push target. Use when the user asks to run no-mistakes, gate or ship or validate their changes, push safely, asks you to do a task and then validate it, or invokes /no-mistakes. (file: /Users/cortana/.agents/skills/no-mistakes/SKILL.md)\n</skills_instructions>"
      },
      {
        "type": "input_text",
        "text": "<permissions instructions>\nFilesystem sandboxing defines which files can be read or written. `sandbox_mode` is `read-only`: The sandbox only permits reading files. Network access is restricted.\n# Escalation Requests\n\nCommands are run outside the sandbox if they are approved by the user, or match an existing rule that allows it to run unrestricted. The command string is split into independent command segments at shell control operators, including but not limited to:\n\n- Pipes: |\n- Logical operators: &&, ||\n- Command separators: ;\n- Subshell boundaries: (...), $(...)\n\nEach resulting segment is evaluated independently for sandbox restrictions and approval requirements.\n\nExample:\n\ngit pull | tee output.txt\n\nThis is treated as two command segments:\n\n[\"git\", \"pull\"]\n\n[\"tee\", \"output.txt\"]\n\nCommands that use more advanced shell features like redirection (>, >>, <), substitutions ($(...), ...), environment variables (FOO=bar), or wildcard patterns (*, ?) will not be evaluated against rules, to limit the scope of what an approved rule allows.\n\n## How to request escalation\n\nIMPORTANT: To request approval to execute a command that will require escalated privileges:\n\n- Provide the `sandbox_permissions` parameter with the value `\"require_escalated\"`\n- Include a short question asking the user if they want to allow the action in `justification` parameter. e.g. \"Do you want to download and install dependencies for this project?\"\n- Optionally suggest a `prefix_rule` - this will be shown to the user with an option to persist the rule approval for future sessions.\n\nIf you run a command that is important to solving the user's query, but it fails because of sandboxing or with a likely sandbox-related network error (for example DNS/host resolution, registry/index access, or dependency download failure), rerun the command with \"require_escalated\". ALWAYS proceed to use the `justification` parameter - do not message the user before requesting approval for the command.\n\n## When to request escalation\n\nWhile commands are running inside the sandbox, here are some scenarios that will require escalation outside the sandbox:\n\n- You need to run a command that writes to a directory that requires it (e.g. running tests that write to /var)\n- You need to run a GUI app (e.g., open/xdg-open/osascript) to open browsers or files.\n- If you run a command that is important to solving the user's query, but it fails because of sandboxing or with a likely sandbox-related network error (for example DNS/host resolution, registry/index access, or dependency download failure), rerun the command with `require_escalated`. ALWAYS proceed to use the `sandbox_permissions` and `justification` parameters. do not message the user before requesting approval for the command.\n- You are about to take a potentially destructive action such as an `rm` or `git reset` that the user did not explicitly ask for.\n- Be judicious with escalating, but if completing the user's request requires it, you should do so - don't try and circumvent approvals by using other tools.\n\n## prefix_rule guidance\n\nWhen choosing a `prefix_rule`, request one that will allow you to fulfill similar requests from the user in the future without re-requesting escalation. It should be categorical and reasonably scoped to similar capabilities. You should rarely pass the entire command into `prefix_rule`.\n\n### Banned prefix_rules \nAvoid requesting overly broad prefixes that the user would be ill-advised to approve. For example, do not request [\"python3\"], [\"python\", \"-\"], or other similar prefixes that would allow arbitrary scripting.\nNEVER provide a prefix_rule argument for destructive commands like rm.\nNEVER provide a prefix_rule if your command uses a heredoc or herestring. \n\n### Examples\nGood examples of prefixes:\n- [\"npm\", \"run\", \"dev\"]\n- [\"gh\", \"pr\", \"check\"]\n- [\"cargo\", \"test\"]\n</permissions instructions>"
      }
    ],
    "internal_chat_message_metadata_passthrough": {
      "turn_id": "auto-compact-0"
    }
  },
  {
    "type": "message",
    "id": "msg_019fd9e2-ad16-7bd0-ac5d-a029e7fe6b13",
    "role": "user",
    "content": [
      {
        "type": "input_text",
        "text": "# AGENTS.md instructions for /Users/cortana/.no-mistakes/worktrees/024dd2779621/01KZCXKB1GZVETPHX55VCGGQD5\n\n<INSTRUCTIONS>\n# Keep this active override.\n\nRead and follow `~/.agents/codex/AGENTS.md` for Codex-specific subagent routing and context rules.\n\n--- project-doc ---\n\n# Global Agent Defaults\n\nThis repository contains cross-repository preferences for coding agents. Keep these instructions focused on outcomes and\nproject conventions; defer safety, permissions, tool mechanics, and communication behavior to the active harness.\n\nWithin this instruction layer, repository-specific guidance and checked-in workflows take precedence. Read only the\ntopic files relevant to the current task.\n\n## Topics\n\n- `instructions/workflow.md` — Repository discovery, implementation design, reuse, coding style, and validation.\n- `instructions/subagents.md` — Read before delegating: permission, decision criteria, routing, scoping, and\n  integration.\n- `instructions/package-managers.md` — Package-manager selection and dependency changes.\n- `instructions/code-review.md` — Reviews, findings, and risk classification.\n- `instructions/git-and-pr.md` — Branches, commits, pushes, pull requests, and `no-mistakes`.\n- `instructions/reliability.md` — Async, distributed, migration, and operational changes.\n- `instructions/frontend.md` — UI implementation, design preferences, and visual verification.\n- `instructions/research.md` — Third-party and OpenAI documentation.\n- `instructions/artifacts.md` — Documents, notebooks, PDFs, slides, and generated media.\n\n</INSTRUCTIONS>"
      },
      {
        "type": "input_text",
        "text": "<environment_context>\n  <cwd>/Users/cortana/.no-mistakes/worktrees/024dd2779621/01KZCXKB1GZVETPHX55VCGGQD5</cwd>\n  <shell>zsh</shell>\n  <current_date>2026-08-06</current_date>\n  <timezone>America/Chicago</timezone>\n  <filesystem><workspace_roots><root>/Users/cortana/.no-mistakes/worktrees/024dd2779621/01KZCXKB1GZVETPHX55VCGGQD5</root></workspace_roots><permission_profile type=\"managed\"><file_system type=\"restricted\"><entry access=\"read\"><special>:root</special></entry></file_system></permission_profile></filesystem>\n</environment_context>"
      }
    ],
    "internal_chat_message_metadata_passthrough": {
      "turn_id": "auto-compact-0"
    }
  },
  {
    "type": "message",
    "id": "msg_019fd9e2-ad16-7bd0-ac5d-a03b1a7285ac",
    "role": "user",
    "content": [
      {
        "type": "input_text",
        "text": "Verify override loader precedence."
      }
    ],
    "internal_chat_message_metadata_passthrough": {
      "turn_id": "auto-compact-0"
    }
  }
]

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

✅ **Review** - passed

✅ No issues found.

✅ **Test** - passed

✅ No issues found.

  • Inspected rtk git diff --stat --name-status 22f37d8e069719b974846438dd1a559359536025..f4eb8b8d63571c2d3206c7a35beea919d50ea6b4 and compared the portable instruction header with the current Codex forwarder.
  • TEST_ROOT=/var/folders/8p/_7px54vn4tg3qzt8w9gnc30h0000gn/T/no-mistakes-evidence/01KZCXKB1GZVETPHX55VCGGQD5/install-codex-e2e rtk sh tests/install-codex.sh
  • Repeated scripts/install-codex.sh against the isolated fallback home and compared complete file checksums before and after; inspected preserved instructions, config, unrelated agents, installed roles, portability scans, and feature guidance.
  • CODEX_HOME=…/default-user-home/.codex rtk codex debug prompt-input 'Verify installed Codex loader.'
  • CODEX_HOME=…/override-home rtk codex debug prompt-input 'Verify override loader precedence.'
  • rtk git diff --check 22f37d8e069719b974846438dd1a559359536025..f4eb8b8d63571c2d3206c7a35beea919d50ea6b4
  • rtk git status --short --untracked-files=all and rtk git rev-parse HEAD
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

Signed-off-by: Craig Knott <craig.knott92@gmail.com>
Signed-off-by: Craig Knott <craig.knott92@gmail.com>
Signed-off-by: Craig Knott <craig.knott92@gmail.com>
@craigknott
craigknott force-pushed the agent/share-codex-agents branch from 51d405c to 49d2d92 Compare August 6, 2026 19:14
Signed-off-by: Craig Knott <craig.knott92@gmail.com>
Signed-off-by: Craig Knott <craig.knott92@gmail.com>
Signed-off-by: Craig Knott <craig.knott92@gmail.com>
@craigknott
craigknott force-pushed the agent/share-codex-agents branch from 625ff76 to 6bb7dbe Compare August 6, 2026 19:58
Signed-off-by: Craig Knott <craig.knott92@gmail.com>
@craigknott
craigknott force-pushed the agent/share-codex-agents branch from 6bb7dbe to a742119 Compare August 6, 2026 20:02
Signed-off-by: Craig Knott <craig.knott92@gmail.com>
Signed-off-by: Craig Knott <craig.knott92@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant