Skip to content
Back to skills

260828 Ocx Agentic Control

ASecurity

Branch: `codex/ocx-agent-skill` off `codex/ocx-gui-parity`. Every prior phase widened what an agent *can* do. This phase makes it *discoverable* without reading the source.

  • 17,003 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added August 30, 2026
ai-agentsgogitapi

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 21 files and shows the line behind each finding

Scanned August 30, 2026

npx -y skills add lidge-jun/opencodex --skill 260828_ocx_agentic_control --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of 260828 Ocx Agentic Control?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for 260828 Ocx Agentic Control
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lidge-jun-260828-ocx-agentic-control/badge)](https://www.skillsdirectory.com/skills/lidge-jun-260828-ocx-agentic-control)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
# 070 — wp8: the `ocx` agent skill and docs-site reference

Branch: `codex/ocx-agent-skill` off `codex/ocx-gui-parity`.

Every prior phase widened what an agent *can* do. This phase makes it *discoverable*
without reading the source.

## 070.1 — where the skill lives

NEW `skills/ocx/SKILL.md` in this repository, plus `skills/ocx/references/`.

Repo-owned, not `$CODEX_HOME/skills`: the skill describes this repository's CLI
contract and must version with it. A user-directory copy goes stale the moment the
CLI changes, which is the same drift class as the 20 dead `USAGE` constants.

```
skills/ocx/
  SKILL.md                        entry point, routing, safety rules
  references/
    01_management_surface.md      capability -> route map, generated
    02_json_shapes.md             response envelopes and error shapes
    03_recipes.md                 copy-paste task recipes
    04_failure_semantics.md       exit codes, 503 classes, what to retry
```

## 070.2 — the generated half

`references/01_management_surface.md` is **generated from wp3's capability table**,
not hand-written, by a script under `scripts/`. A test asserts the committed file
matches regeneration.

Hand-writing it would recreate the exact defect this unit removed: a second
description of the surface, free to drift from the first. If the generator and the
committed file disagree, CI fails and someone regenerates.

## 070.3 — SKILL.md content

Front matter with `name: ocx` and a description naming real triggers (`ocx`,
opencodex, proxy control, account pool, provider routing, usage report, access key,
management API), so it activates on the tasks it covers.

Body sections:

**Orientation.** `ocx capabilities --json` first. It is the machine-readable index;
everything else in the skill explains how to act on what it returns.

**The three-step contract for any management call.**

1. `ocx ready --json` — is the proxy up and admitting requests?
2. `ocx status --json` — is this binary the same version as the running proxy?
   A version mismatch means the help and flags describe a different build (#2701).
3. Then the actual command with `--json`.

**Exit codes.** 0 ok · 2 usage error · 4 not found · 5 conflict · 64 bad args
(`ready` only) · 1 everything else, including transport and 503. Never treat a
printed error with exit 0 as success — that was #2697, and a source scan now prevents
its return.

**Reading failures.** A management failure prints up to three lines: message,
`reason:`, `hint:`. The `reason` is the machine-actionable part. Named 503 classes
worth branching on: `oauth_mutation_busy` and `catalog_busy` (both send
`Retry-After: 1` — retry once), `CONFIG_MUTATION_LOCK_UNAVAILABLE` (a config
mutation holds the lock; retry), and the credential-conflict reason (a broken
install; `ocx doctor` explains it, retrying will not help).

**What an agent must not do.** `POST /api/github/star` has no CLI verb and must not
be driven another way — starring spends the user's identity and needs their consent
(`AGENTS_INSTALL.md`). Same for the session-gated `/api/codex-prompt` writes.
Destructive storage verbs need explicit `--yes`; run the preview and report it first.

**Recipes** (`references/03_recipes.md`), each a real sequence with the JSON field to
read:

- audit the account pool and pause an exhausted account
- switch pool strategy and set a sticky limit
- trace one conversation end to end (`ocx logs --conversation`, then
  `ocx request-history <id> --route-decision`)
- attribute spend per account (`ocx usage --json`, read `accounts[]`)
- rotate an access key and confirm its usage went quiet
- add a provider, test connectivity, make it default
- diagnose "management API unavailable" (ready -> status -> doctor)
- preview and then run a storage cleanup

## 070.4 — docs-site

NEW/MODIFY under `docs-site/`: a CLI reference page generated from the same
capability table, and a changelog entry for the breaking changes this unit lands:

- `doctor` and `sync-cache` now exit non-zero on failure (wp3)
- `account` client error codes now map 404 -> 4 and 409 -> 5 (wp2)
- `--json` is accepted in any argv position, including `ocx restore back --json`
  which previously ignored it (wp3)

Translated locales must not contradict the English source. If a locale cannot be
updated in this phase, leave it untranslated rather than stale.

## 070.5 — AGENTS.md pointer

MODIFY `AGENTS.md`: one line under the commands section pointing at
`skills/ocx/SKILL.md` as the operating-the-proxy reference, distinct from
`AGENTS_INSTALL.md` (installing/operating consent) and this file
(developing the codebase).

## Tests

| File | Assertion |
|---|---|
| `tests/skill-ocx.test.ts` (NEW) | `references/01_management_surface.md` matches regeneration from the capability table; every command named in SKILL.md exists in the table; no recipe references a session-only route |
| `tests/repo-hygiene.test.ts` | the skill directory carries no credential-shaped strings |
| `bun run privacy:scan` | stays green over the new files |

## Accept criteria

1. `skills/ocx/SKILL.md` exists and routes to four references.
2. The surface reference is generated and a test enforces freshness.
3. Recipes cover the eight tasks above and name the JSON fields to read.
4. Failure semantics document exit codes and the named 503 classes.
5. Docs-site has a generated CLI reference and the breaking-change note.

Files in this skill

  • 000_plan.md6.9 KB
  • 001_api_route_inventory.md7.7 KB
  • 002_cli_surface_inventory.md6.6 KB
  • 003_gui_capability_map.md4.5 KB
  • 004_issue_root_cause.md13.7 KB
  • 005_audit_record.md6.2 KB
  • 010_phase_transport_honesty.md9.4 KB
  • 011_wp2_implementation_record.md6.6 KB
  • 020_phase_capability_registry.md10.9 KB
  • 021_wp3_stale_check_amendment.md22.3 KB
  • 025_phase_uniform_cli_contract.md3.1 KB
  • 026_wp3b_implementation_record.md3.6 KB
  • 030_phase_dto_fidelity.md7.3 KB
  • 031_wp4_implementation_record.md4.7 KB
  • 040_phase_new_verbs.md6.9 KB
  • 041_wp5_implementation_record.md8.1 KB
  • 050_phase_account_attribution.md9.7 KB
  • 051_wp6_implementation_record.md6.7 KB
  • 060_phase_gui_parity.md4.9 KB
  • 061_wp7_implementation_record.md7.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…