codex-delegate — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited codex-delegate (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are the orchestrator. This skill lets you hand a bounded coding task to a separate implementer — the OpenAI Codex CLI — then review what it produced and land it yourself. You write the brief and own the judgment; Codex does the typing in its own sandbox; you verify and commit.
Nothing here is specific to one orchestrating agent. The loop needs only the ability to run a shell command and read a file, so it works the same whether you are Claude Code, OpenCode with a selected model, or any comparable agent. (It is designed for and run on Claude Code; treat other orchestrators as designed-for, not yet proven.)
codex CLI is not installed or not authenticated (run codex login).review command).codex --version succeeds. If not, install (npm i -g @openai/codex) and codex login.a stale Homebrew one). command -v codex shows the active one and codex --version its version — an old binary predates flags this skill relies on (codex exec --json, -o, exec resume). The relay also records the version it ran into result.json, so a stale binary is visible after the fact.
--cd at) the target git repository.Run these five steps per task. Steps 1, 4, and 5 are your judgment; 2 and 3 are mechanical.
Codex sees only the text you send — no repo memory, no chat history, no shared context. Everything the task needs goes in the brief: the goal, the current state, what to change, what to leave untouched, the project's actual gate commands (discover them from the repo's CLAUDE.md/AGENTS.md/Makefile — do not assume), and a report contract. Tell Codex it will not commit (you will). Keep one task per brief. Full guidance and a template: references/writing-the-brief.md.
Send the brief to Codex with the bundled helper. It wraps codex exec, captures the run, and writes a structured result.json — so your only job is "run a command, read a file." (<skill-dir> below is this skill's installed directory — the folder containing this SKILL.md, i.e. the directory you loaded the skill from. Claude Code prints it as "Base directory for this skill" when the skill loads; on other orchestrators use that same directory — if unsure where it landed, run find ~ -name relay.mjs -path '*codex-delegate*' and substitute the directory above it.)
node "<skill-dir>/scripts/relay.mjs" --brief brief.txt --cd /path/to/repo
# read-only (review/diagnosis, no edits): add --read-only
# continue the previous Codex session: add --resume-last (send only the delta brief)
# see all options: node .../relay.mjs --helpThe helper defaults to a write-capable (workspace-write) sandbox and writes its artifacts to a temp dir, so the repo under review stays clean. It never commits — see step 5. Mechanics, flags, and the result.json shape: references/dispatch-and-poll.md.
The helper blocks until Codex finishes, so back it with whatever your orchestrator offers and resume when it returns:
run_in_background: true; you are notified on completion.the result file — … & in bash/zsh (including Git Bash/WSL), or your shell's equivalent (Start-Job in PowerShell, start /b in cmd). The run is done when result.json exists with a status. (A pre-run usage error — bad args or an empty brief — instead exits with code 2 and a stderr message and writes no result file, so check the exit code too. A missing codex binary exits 127 but does write a result.json with status codex_unavailable.)
Do not trust progress trackers over reality: a run is finished when result.json is written and the process has exited. Read the working tree, not a status line.
Codex's result.json includes its own summary and gate claims. Re-verify, don't accept:
"gates passed" on faith.
nothing less? touchedFiles in the result is your starting point.
test-guard, etc. from guard-skills) — this skill produces the work; those skills judge it.
Full checklist: references/review-and-land.md.
Because Codex's sandbox cannot reliably write .git (it varies by version, OS, and path), the orchestrator commits. Only after the gates pass and the diff holds:
--resume-last (don't restate the whole task) andreview again.
Delegation is something the human opts into. Once they have ("run this queue", "proceed"), committing verified, gate-passing work is the agreed contract — that is the whole point. Two limits on that mandate: surface, don't absorb (report Codex's design decisions, defensible-but-unasked turns, and non-blocking nitpicks rather than silently keeping them) and stop for scope changes (if correct completion needs going beyond the brief, ask — don't expand the mandate yourself). The full treatment is in references/review-and-land.md.
scripts/relay.mjs itself makes no network calls, reads or writes no credentials, and sends no telemetry; it has no dependencies (Node built-ins only) and shells out only to codex and git. The codex process it launches does authenticate — exactly as you do at the terminal. Read the script before you run it. It is the one executable in this package; everything else is Markdown.
execute blind: structure, XML blocks, the report contract, embedding the real gate commands.
relay.mjs flags, theresult.json contract, backgrounding per orchestrator, and recovery when a run misbehaves.
boundary, and the rework cycle via --resume-last.
carrying constraints forward, progress tracking, and the end-of-run coherence check.
review command or stop-review gate.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.