Casefile
Use Casefile to maintain durable security investigation state across Codex turns. Prefer the MCP tools from the casefile server when they are available.
Workflow
- Check existing cases before opening a new one with
casefile_listorcasefile_search. - Open new leads with
casefile_addashypothesisorinvestigating. - Promote cases with
casefile_updateonly after materially new evidence, proof, impact, blockers, remediation, or status changes. - Mark
confirmedonly when evidence and a PoC or repro are recorded. - Use
casefile_linkandcasefile_unlinkfor exploit chains. Do not edit linked case IDs directly. - Use
casefile_reportonly for confirmed or already reported cases. - Use
killedfor disproven, duplicate, or dead-end leads, and include evidence, blockers, next step, or assumptions explaining why.
Tool Map
casefile_add: create a new case.casefile_update: update an existing case.casefile_get: read one case by ID.casefile_list: list cases with filters and pagination.casefile_search: search all fields or a scoped field such asevidence,impact, orpoc.casefile_link: bidirectionally link two cases.casefile_unlink: remove a bidirectional case link.casefile_report: write a markdown report for a confirmed or reported case.
Storage
The Codex plugin uses project-scoped storage by default at .casefile/casefile.jsonl. Use CASEFILE_PATH to force a specific ledger path or CASEFILE_SCOPE=global to use ~/.casefile/casefile.jsonl.
Legacy pi environment variables remain supported for the pi extension.
Source: hashgraph-online/awesome-codex-plugins → plugins/x4cc3/casefile/skills/casefile/SKILL.md