跳到主要内容
知仓学习社ZHICANG

local-codex

Launch and manage OpenAI Codex CLI (local agent) as a non-interactive coding sub-agent. Use when the user wants to delegate coding tasks to Codex, r…

执行命令严重 0 · 高危 4daymade/claude-code-skills

它会碰到什么

扫了多少3 个文本文件,14 KB
它会碰到什么执行命令
命中总数4 处
命中统计严重 0 · 高 4 · 中 0 · 低 0
逐条看命中(4 条严重或高危)
  • scripts/codex_wrapper.py:32exec-spawn
    result = subprocess.run(
  • scripts/codex_wrapper.py:49exec-spawn
    result = subprocess.run(
  • scripts/codex_wrapper.py:97exec-spawn
    result = subprocess.run(
  • scripts/codex_wrapper.py:165exec-spawn
    result = subprocess.run(

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Local Codex

Delegate coding tasks to the local OpenAI Codex CLI agent using your ChatGPT Pro subscription (OAuth, no API charges).

When to Use

  • User wants to generate, refactor, or review code via Codex
  • User wants to run codex exec for non-interactive tasks
  • User wants to use Codex's GPT-5.5 agent capabilities
  • User mentions "codex", "run codex", "delegate to codex"

Authentication (OAuth / ChatGPT Pro)

CRITICAL: This skill uses OAuth authentication from ~/.codex/auth.json (ChatGPT Pro flat-rate subscription). Do NOT set OPENAI_API_KEY or pass API keys — that would switch to pay-per-use billing.

  • Codex desktop app and CLI share the same auth cache
  • If auth fails, run codex login in terminal (browser OAuth flow)
  • For auth issues, see [references/oauth-guide.md](references/oauth-guide.md)

Codex CLI Path

The skill auto-detects Codex CLI in this order:

  1. /Applications/Codex.app/Contents/Resources/codex (desktop app)
  2. /usr/local/bin/codex (npm global)
  3. /opt/homebrew/bin/codex (Homebrew)
  4. ~/.npm-global/bin/codex
  5. which codex fallback

Usage Patterns

1. Basic exec (single task)

python3 scripts/codex_wrapper.py exec "<prompt>" [<workdir>] [<model>] [<sandbox>] [<timeout>]

Example:

python3 scripts/codex_wrapper.py exec \
  "Write a Python function to calculate fibonacci" \
  /tmp \
  gpt-5.5 \
  workspace-write \
  300

2. Code review

python3 scripts/codex_wrapper.py review [<workdir>] [<model>] [uncommitted:true] [<timeout>]

Example:

python3 scripts/codex_wrapper.py review \
  /path/to/repo \
  gpt-5.5 \
  true \
  300

3. Check status

python3 scripts/codex_wrapper.py status

Output Format

The wrapper returns JSON with:

  • success: bool
  • exit_code: int
  • elapsed_seconds: float
  • stdout: raw output
  • stderr: error stream (truncated)
  • parsed_jsonl: parsed JSONL events (if --json)
  • final_message: extracted assistant text (if available)

Parameters

| Parameter | Default | Options |

|-----------|---------|---------|

| model | gpt-5.5 | gpt-5.5, gpt-5.5-pro, o4-mini, etc. |

| sandbox | workspace-write | read-only, workspace-write, danger-full-access |

| timeout | 300 | seconds (increase for large tasks) |

| json_output | true | always true (wrapper parses JSONL) |

Safety Notes

  • sandbox=read-only for analysis/review tasks (no file writes)
  • sandbox=workspace-write for code generation (writes to working dir)
  • sandbox=danger-full-access only when explicitly needed (full system access)
  • Always use --skip-git-repo-check when running outside git repos
  • Use --ephemeral for one-off tasks (no session persistence)

Session Management

For multi-step tasks, Codex supports session resume:

# First step
codex exec --ephemeral "Step 1..."
# Later
codex exec resume --last "Step 2..."

The wrapper currently runs single-shot exec. For multi-step workflows, use raw codex exec commands.

Limitations

  • Desktop app must be running for OAuth token refresh (or token must be fresh)
  • codex doctor is buggy in current version (alpha), avoid using
  • Environment variables are NOT inherited into Codex's sandbox; pass via config or prompt
  • Large file operations may need increased timeout

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。