Codex SDK + Codex CLI (master skill)
Build reliable, auditable, multi-step coding workflows that scale from a single run to multi-agent orchestration.
ExecPlans (durable planning)
For multi-hour work, keep intent durable across compaction/restarts using an ExecPlan:
- Contract:
references/execplans.md
- Template + rules:
.agent/PLANS.md (use scripts/init_agent_workspace.py to bootstrap a repo)
- ExecPlan skeleton:
assets/templates/execplan.md (or generate a file with scripts/new_execplan.py)
Workflow decision tree
- Need a scriptable one-shot in CI or cron? → use
codex exec (references/codex-cli-exec.md)
- Need a server-side app controlling Codex programmatically? → use
@openai/codex-sdk (references/codex-sdk-typescript.md)
- Need multi-agent orchestration or dynamic tools? → run
codex mcp-server and orchestrate via OpenAI Agents SDK (references/mcp-and-agents-sdk.md)
- Need durability across runs (memory, caching, resumable state)? → persist run metadata and event logs in SQLite (
references/state-memory-sqlite.md)
Default workflow (safe + production-friendly)
- Inventory inputs (repo root, diffs, failing commands, constraints).
- Choose sandbox + approvals (least privilege; default to read-only).
- Plan in explicit steps (short, verifiable; include stop conditions).
- Use structured outputs (JSON Schema) and validate before acting.
- Record an audit trail (JSONL events → SQLite).
- Verify (re-run tests/lint/format; stop).
Durable state and “memory” (SQLite)
SQLite is the simplest reliable substrate for:
- recording every
codex exec --json event as an immutable audit log
- indexing runs by repo, branch, and purpose
- storing
threadId so runs can resume deterministically
- caching expensive analysis artifacts (diff summaries, inventories, dependency graphs)
Use the bundled scripts
- Initialize a DB:
python3 scripts/codex_jsonl_to_sqlite.py --db codex-runs.sqlite --init
- Ingest a JSONL run:
codex exec --json "<prompt>" | python3 scripts/codex_jsonl_to_sqlite.py --db codex-runs.sqlite --run-label "ci-autofix"
- Summarize runs:
python3 scripts/codex_sqlite_report.py --db codex-runs.sqlite --latest
Multi-agent orchestration (recommended shape)
Use:
- a single orchestrator responsible for gating and artifact checks
- multiple scoped worker agents with strict deliverables
- structured outputs at boundaries (handoff payloads, review findings, test results)
- traces/telemetry to debug and tune
Details: references/mcp-and-agents-sdk.md
Safety and policy
Prefer:
- analysis-only:
sandbox: read-only, approval-policy: never
- controlled edits:
sandbox: workspace-write, approval-policy: on-request / on-failure
- block risky commands with
execpolicy rules (references/safety-and-execpolicy.md)
Resources
references/
references/codex-sdk-typescript.md – SDK patterns (threads, streaming, schemas)
references/codex-cli-exec.md – CLI patterns (JSONL, schema files, resume)
references/mcp-and-agents-sdk.md – Codex as MCP server + multi-agent orchestration
references/agents-sdk-consistent-workflows.md – gated handoffs + traces with Codex MCP + Agents SDK
references/execplans.md – ExecPlans for long-running work across compaction
references/state-memory-sqlite.md – SQLite schema + memory/caching patterns
references/safety-and-execpolicy.md – sandboxing, approvals, prompt-injection defenses
references/codex-config-knobs.md – config keys and feature flags that matter
references/orchestration-patterns.md – planner/executor/verifier and orchestrator/worker patterns
references/rag-and-memory.md – SQLite-first shared memory and RAG guidance
references/context-personalization.md – state + memory notes personalization patterns (Agents SDK)
scripts/
scripts/codex_jsonl_to_sqlite.py – ingest Codex JSONL into SQLite
scripts/codex_sqlite_report.py – summarize runs from SQLite
scripts/init_agent_workspace.py – create .agent/AGENTS.md + .agent/PLANS.md from templates
scripts/new_execplan.py – generate execplans/execplan-*.md from the ExecPlan template
assets/
assets/templates/ – copy/paste templates (ExecPlan, prompts, schemas)
assets/templates/agents-sdk/ – Agents SDK starter snippets (MCP stdio, sessions, personalization)
1---2name: codex-sdk3description: Architect-level guidance, workflows, and scripts for building agentic coding systems with OpenAI Codex. Use for Codex SDK (@openai/codex-sdk) threads + streaming JSONL events; Codex CLI automation (codex exec, output schema, JSONL, resume); MCP server usage (codex mcp-server) and dynamic tool integration; multi-agent orchestration with OpenAI Agents SDK (handoffs, gating, tracing); durable state, caching, and memory using SQLite; safe-by-default sandbox/approval patterns and execpolicy rules.4---5
6# Codex SDK + Codex CLI (master skill)
7
8Build reliable, auditable, multi-step coding workflows that scale from a single run to multi-agent orchestration.
9
10## ExecPlans (durable planning)
11
12For multi-hour work, keep intent durable across compaction/restarts using an **ExecPlan**:
13
14- Contract: `references/execplans.md`
15- Template + rules: `.agent/PLANS.md` (use `scripts/init_agent_workspace.py` to bootstrap a repo)
16- ExecPlan skeleton: `assets/templates/execplan.md` (or generate a file with `scripts/new_execplan.py`)
17
18## Workflow decision tree
19
201. **Need a scriptable one-shot in CI or cron?** → use `codex exec` (`references/codex-cli-exec.md`)
212. **Need a server-side app controlling Codex programmatically?** → use `@openai/codex-sdk` (`references/codex-sdk-typescript.md`)
223. **Need multi-agent orchestration or dynamic tools?** → run `codex mcp-server` and orchestrate via OpenAI Agents SDK (`references/mcp-and-agents-sdk.md`)
234. **Need durability across runs (memory, caching, resumable state)?** → persist run metadata and event logs in SQLite (`references/state-memory-sqlite.md`)
24
25## Default workflow (safe + production-friendly)
26
271. Inventory inputs (repo root, diffs, failing commands, constraints).
282. Choose sandbox + approvals (least privilege; default to read-only).
293. Plan in explicit steps (short, verifiable; include stop conditions).
304. Use structured outputs (JSON Schema) and validate before acting.
315. Record an audit trail (JSONL events → SQLite).
326. Verify (re-run tests/lint/format; stop).
33
34## Durable state and “memory” (SQLite)
35
36SQLite is the simplest reliable substrate for:
37
38- recording every `codex exec --json` event as an immutable audit log
39- indexing runs by repo, branch, and purpose
40- storing `threadId` so runs can resume deterministically
41- caching expensive analysis artifacts (diff summaries, inventories, dependency graphs)
42
43### Use the bundled scripts
44
45- Initialize a DB:
46 - `python3 scripts/codex_jsonl_to_sqlite.py --db codex-runs.sqlite --init`
47- Ingest a JSONL run:
48 - `codex exec --json "<prompt>" | python3 scripts/codex_jsonl_to_sqlite.py --db codex-runs.sqlite --run-label "ci-autofix"`
49- Summarize runs:
50 - `python3 scripts/codex_sqlite_report.py --db codex-runs.sqlite --latest`
51
52## Multi-agent orchestration (recommended shape)
53
54Use:
55
56- a single **orchestrator** responsible for gating and artifact checks
57- multiple **scoped worker agents** with strict deliverables
58- structured outputs at boundaries (handoff payloads, review findings, test results)
59- traces/telemetry to debug and tune
60
61Details: `references/mcp-and-agents-sdk.md`
62
63## Safety and policy
64
65Prefer:
66
67- analysis-only: `sandbox: read-only`, `approval-policy: never`
68- controlled edits: `sandbox: workspace-write`, `approval-policy: on-request` / `on-failure`
69- block risky commands with `execpolicy` rules (`references/safety-and-execpolicy.md`)
70
71## Resources
72
73### references/
74- `references/codex-sdk-typescript.md` – SDK patterns (threads, streaming, schemas)
75- `references/codex-cli-exec.md` – CLI patterns (JSONL, schema files, resume)
76- `references/mcp-and-agents-sdk.md` – Codex as MCP server + multi-agent orchestration
77- `references/agents-sdk-consistent-workflows.md` – gated handoffs + traces with Codex MCP + Agents SDK
78- `references/execplans.md` – ExecPlans for long-running work across compaction
79- `references/state-memory-sqlite.md` – SQLite schema + memory/caching patterns
80- `references/safety-and-execpolicy.md` – sandboxing, approvals, prompt-injection defenses
81- `references/codex-config-knobs.md` – config keys and feature flags that matter
82- `references/orchestration-patterns.md` – planner/executor/verifier and orchestrator/worker patterns
83- `references/rag-and-memory.md` – SQLite-first shared memory and RAG guidance
84- `references/context-personalization.md` – state + memory notes personalization patterns (Agents SDK)
85
86### scripts/
87- `scripts/codex_jsonl_to_sqlite.py` – ingest Codex JSONL into SQLite
88- `scripts/codex_sqlite_report.py` – summarize runs from SQLite
89- `scripts/init_agent_workspace.py` – create `.agent/AGENTS.md` + `.agent/PLANS.md` from templates
90- `scripts/new_execplan.py` – generate `execplans/execplan-*.md` from the ExecPlan template
91
92### assets/
93- `assets/templates/` – copy/paste templates (ExecPlan, prompts, schemas)
94- `assets/templates/agents-sdk/` – Agents SDK starter snippets (MCP stdio, sessions, personalization)