Directory → SKILL
SKILLbundledHermes Bundled Skills

Codex

Delegate coding to OpenAI Codex CLI (features, PRs)

Coding-AgentCodexOpenAICode-ReviewRefactoringBundledHermes skill
Last registry verification2026-08-18v1.0.1Hermes Agent
Plain meaning

What does it add to Hermes?

Delegate coding to OpenAI Codex CLI (features, PRs)

Codex is a skill related to extending the agent. It adds a capability or workflow to Hermes. The publisher description explains the intent, while granted permissions determine what it can actually do.

This plain-language explanation is based on the publisher description. The original text remains visible for verification.

Use it when

Use it when your goal in extending the agent is clear and you can limit it to the data and actions it actually needs.

Skip it when

Do not add it merely to experiment when Hermes already has a simpler path, or when you cannot review its source and permissions.

Who is it for?

Best for users who want a repeatable way of working inside Hermes.

Safe first test

Start with non-sensitive data and a small task whose result can be verified and reversed.

Original publisher description

Delegate coding to OpenAI Codex CLI (features, PRs)

✓
Data source

This entry was indexed from Hermes Bundled Skills. Our explanation interprets the type and domain without inventing a capability not present upstream.

!
Security review

The source is official or editorially reviewed, but you still need to review permissions and version compatibility.

Safe setup path

Inspect, install, then test.

  1. 01
    Open the source

    Match the publisher, license, and description to your need. Check the real update history.

  2. 02
    Review permissions and secrets

    Never paste a secret value into this site. Use environment-variable names and grant the smallest scope.

  3. 03
    Copy setup only after review

    The controls below copy text. They do not execute commands on your device.

  4. 04
    Test with a non-sensitive task

    Inspect the visible tools, then exclude write or delete tools you do not need.

Setup method

Already installed with Hermes.

This skill ships with Hermes and loads when the agent decides it is relevant. There is nothing to install; read the definition below so you know what it will do.

Open the official page ↗
The full skill definition

Exactly what Hermes loads when this skill runs.

Reproduced from the official documentation. Read it before enabling the skill: this text becomes the agent's instructions.

Delegate coding to OpenAI Codex CLI (features, PRs).

Skill metadata

A lookup table. Do not read it all; find the row that applies to you.

SourceBundled (installed by default)
Pathskills/autonomous-ai-agents/codex
Version1.0.1
AuthorHermes Agent
LicenseMIT
Platformslinux, macos, windows
TagsCoding-Agent, Codex, OpenAI, Code-Review, Refactoring
Related skillsclaude-code, hermes-agent

Reference: full SKILL.md

Explains the idea itself. Read it slowly; the later sections build on it.

Delegate coding tasks to Codex ↗ via the Hermes terminal. Codex is OpenAI's autonomous coding agent CLI.

When to use

Explains the idea itself. Read it slowly; the later sections build on it.

  • Building features
  • Refactoring
  • PR reviews
  • Batch issue fixing

Requires the codex CLI and a git repository.

Prerequisites

Settings you configure once. Change one at a time so you can see what each does. Commands here: hermes auth add openai-codex. Set OPENAI_API_KEY in your environment, not in the chat.

  • Codex installed: npm install -g @openai/codex
  • OpenAI auth configured: either OPENAI_API_KEY or Codex OAuth credentials from the Codex CLI login flow
  • Must run inside a git repository — Codex refuses to run outside one
  • Use pty=true in terminal calls — Codex is an interactive terminal app

For Hermes itself, model.provider: openai-codex uses Hermes-managed Codex OAuth from ~/.hermes/auth.json after hermes auth add openai-codex. For the standalone Codex CLI, a valid CLI OAuth session may live under ~/.codex/auth.json; do not treat a missing OPENAI_API_KEY alone as proof that Codex auth is missing.

One-Shot Tasks

Explains the idea itself. Read it slowly; the later sections build on it.

Text1 line
terminal(command="codex exec 'Add dark mode toggle to settings'", workdir="~/project", pty=true)

For scratch work (Codex needs a git repo):

Text1 line
terminal(command="cd $(mktemp -d) && git init && codex exec 'Build a snake game in Python'", pty=true)

Background Mode (Long Tasks)

Explains the idea itself. Read it slowly; the later sections build on it.

Text13 lines
# Start in background with PTY
terminal(command="codex exec --sandbox workspace-write 'Refactor the auth module'", workdir="~/project", background=true, pty=true)
# Returns session_id

# Monitor progress
process(action="poll", session_id="<id>")
process(action="log", session_id="<id>")

# Send input if Codex asks a question
process(action="submit", session_id="<id>", data="yes")

# Kill if needed
process(action="kill", session_id="<id>")

Key Flags

A lookup table. Do not read it all; find the row that applies to you.

FlagEffect
exec "prompt"One-shot execution, exits when done
--sandbox workspace-write (-s)Sandboxed but auto-approves file changes in the workspace (the recommended auto-build mode)
--dangerously-bypass-approvals-and-sandboxNo sandbox, no approvals (fastest, most dangerous; --yolo still works as a hidden alias)
--sandbox danger-full-accessNo Codex sandbox; useful when the host service context breaks bubblewrap
Deprecated: --full-auto still works but the live CLI warns to use --sandbox workspace-write instead.

Hermes Gateway Caveat

Explains the idea itself. Read it slowly; the later sections build on it.

When invoking the Codex CLI from a Hermes gateway/service context (for example, Telegram-driven agent sessions), Codex workspace-write sandboxing may fail even when the same command works in the user's interactive shell. A typical symptom is bubblewrap/user-namespace errors such as setting up uid map: Permission denied or loopback: Failed RTM_NEWADDR: Operation not permitted.

In that context, prefer:

Text1 line
codex exec --sandbox danger-full-access "<task>"

Use process boundaries as the safety layer instead: explicit workdir, clean git status before launch, narrow task prompts, git diff review, targeted tests, and human/agent confirmation before committing broad changes.

PR Reviews

Explains the idea itself. Read it slowly; the later sections build on it.

Clone to a temp directory for safe review:

Text1 line
terminal(command="REVIEW=$(mktemp -d) && git clone https://github.com/user/repo.git $REVIEW && cd $REVIEW && gh pr checkout 42 && codex review --base origin/main", pty=true)

Parallel Issue Fixing with Worktrees

Explains the idea itself. Read it slowly; the later sections build on it.

Text17 lines
# Create worktrees
terminal(command="git worktree add -b fix/issue-78 /tmp/issue-78 main", workdir="~/project")
terminal(command="git worktree add -b fix/issue-99 /tmp/issue-99 main", workdir="~/project")

# Launch Codex in each
terminal(command="codex --sandbox workspace-write exec 'Fix issue #78: <description>. Commit when done.'", workdir="/tmp/issue-78", background=true, pty=true)
terminal(command="codex --sandbox workspace-write exec 'Fix issue #99: <description>. Commit when done.'", workdir="/tmp/issue-99", background=true, pty=true)

# Monitor
process(action="list")

# After completion, push and create PRs
terminal(command="cd /tmp/issue-78 && git push -u origin fix/issue-78")
terminal(command="gh pr create --repo user/repo --head fix/issue-78 --title 'fix: ...' --body '...'")

# Cleanup
terminal(command="git worktree remove /tmp/issue-78", workdir="~/project")

Batch PR Reviews

Explains the idea itself. Read it slowly; the later sections build on it.

Text9 lines
# Fetch all PR refs
terminal(command="git fetch origin '+refs/pull/*/head:refs/remotes/origin/pr/*'", workdir="~/project")

# Review multiple PRs in parallel
terminal(command="codex exec 'Review PR #86. git diff origin/main...origin/pr/86'", workdir="~/project", background=true, pty=true)
terminal(command="codex exec 'Review PR #87. git diff origin/main...origin/pr/87'", workdir="~/project", background=true, pty=true)

# Post results
terminal(command="gh pr comment 86 --body '<review>'", workdir="~/project")

Rules

Explains the idea itself. Read it slowly; the later sections build on it.

  1. Always use pty=true — Codex is an interactive terminal app and hangs without a PTY
  2. Git repo required — Codex won't run outside a git directory. Use mktemp -d && git init for scratch
  3. Use exec for one-shots — codex exec "prompt" runs and exits cleanly
  4. --sandbox workspace-write for building — auto-approves changes within the sandbox (--full-auto is deprecated for this)
  5. Background for long tasks — use background=true and monitor with process tool
  6. Don't interfere — monitor with poll/log, be patient with long-running tasks
  7. Parallel is fine — run multiple Codex processes at once for batch work