Skip to content
Back to skills

Claude Code

ASecurity

Use a locally installed Claude Code CLI from Codex for a read-only second opinion, a resumable conversation, a summarized handoff, or an exact explicitly requested native Claude command. Trigger when the user asks Codex to ask, consult, invoke, or use Claude or Claude Code.

  • 8 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentsjavascriptrustgojavashellnodeapi

Works with

  • claude code
  • cli
  • api
  • mcp

Security analysis

A100/100

Pro scans all 8 files and shows the line behind each finding

Scanned September 30, 2026

npx -y skills add sanchitmonga22/cc-for-codex --skill claude-code --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Claude Code?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Claude Code
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/sanchitmonga22-claude-code/badge)](https://www.skillsdirectory.com/skills/sanchitmonga22-claude-code)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: claude-code
description: "Use a locally installed Claude Code CLI from Codex for a read-only second opinion, a resumable conversation, a summarized handoff, or an exact explicitly requested native Claude command. Trigger when the user asks Codex to ask, consult, invoke, or use Claude or Claude Code."
---

# Claude Code

Use the bundled bridge instead of assembling a raw `claude` shell command.

## Locate the runner

Resolve this skill's absolute directory from the loaded skill path, then use:

```text
<skill-directory>/scripts/cc-for-codex
```

Invoke that absolute launcher path directly. It resolves a Node executable outside the current repository before loading JavaScript. Never replace it with a bare `node` command, and never interpolate user text into shell syntax. Prefer `--prompt-file` for long or untrusted prompts; otherwise use stdin or a safely quoted argument.

## Default workflow

1. Tell the user that this skill is about to invoke their local Claude Code installation and that Claude usage may count against their Anthropic plan or API billing.
2. If readiness has not been established in this task, run `doctor --json`. This is a local, non-model check.
3. Use `ask` for a read-only second opinion. The bridge disables local Claude customizations, MCP, Chrome, network-capable tools, shell execution, edits, and permission prompts by default.
4. Return Claude's answer as attributed second-opinion output. Do not present it as Codex's own verified conclusion. Independently verify claims before taking consequential action.
5. If `--persist` was requested, preserve the returned Claude session UUID so a later `resume` can use it.

`doctor --json` establishes local binary/auth/capability readiness only; it does
not prove that the selected model is currently available or that the provider
has quota. Provider rate-limit and weekly-limit failures are reported as safe categories. Stop
there: do not loop retries or silently switch models. Retry after the provider
window clears, or use an explicit `--fallback-model` only when the user accepts
that model change.

## Model defaults

- The bridge defaults to Claude Opus 5.5 (`claude-opus-5-5`) at `high` effort
  for ordinary consultation, handoff, and delegation. Pass `--model` or
  `--effort` to override the respective default.
- Claude Sonnet 5.5 (`claude-sonnet-5-5`) is an explicit alternative at
  `high` effort.
- Full write delegation requests ultracode dynamic workflows with `Workflow`
  available and high effort. Read-only and file-only profiles never enable
  Workflow. Use `--no-ultracode` on full delegation to opt out; verify actual
  Workflow tool calls before claiming orchestration ran.
- Do not recommend Fable 5.1 as a routine alternative. Use it only when the
  user specifically requests that model; the bridge then leaves effort to
  Claude Code unless `--effort` is provided.
- `$claude-verify` intentionally uses a small smoke-test model when it probes
  the installation. That cost-saving probe does not change the production
  default above.

## Routing

- Use `$claude-review` for normal, adversarial, or ultrareview code review.
- Use `$claude-delegate` for foreground/background delegation or isolated edits.
- Use `$claude-sessions` for background status, logs, stop, respawn, removal, or attach.
- Use `$claude-import` to bring a known Claude session into Codex with a private archive of the full local transcript and a concise summary.
- Use `$claude-setup` for installation/auth/version diagnosis.
- Use this skill's `ask`, `handoff`, and `resume` commands for general consultation.

## Hard boundaries

- Never call Claude merely because a second opinion might be interesting. The user must ask to use Claude or approve the delegation.
- Never use `--profile native`, `native`, bypass-permissions flags, Claude plugins, MCP, Chrome, remote control, cloud sessions, or configuration mutations without an exact user request and the matching bridge confirmation. `$claude-delegate` owns the separately confirmed dangerous-write workflow; ordinary read calls never activate it.
- `handoff` creates a fresh persisted Claude session from a Codex-authored brief. It does not copy hidden Codex context, tool calls, approvals, or the complete transcript.
- `import-session --session <uuid>` archives the full local JSONL transcript
  and same-session sidecars privately before resuming Claude read-only for a
  Codex-ready index summary. The prompt references the archive; Codex can read
  it on demand. It does not inject the entire transcript into the current
  context or create a new Codex task.
- Do not place secrets in prompts, especially background prompts, which can be visible in a local process listing.
- Do not use native passthrough as a workaround for a rejected guarded command.

Read [references/commands.md](references/commands.md) for the complete command surface and [references/safety.md](references/safety.md) before using any opt-in mode.

Files in this skill

  • SKILL.md4.1 KB
  • agents/openai.yaml201 B
  • references/commands.md5.7 KB
  • references/safety.md4 KB
  • scripts/cc-for-codex4.3 KB
  • scripts/cc-for-codex.mjs26.7 KB
  • scripts/lib/runtime.mjs21.5 KB
  • scripts/lib/transcript-archive.mjs9.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…