OpenAI Codex CLI wrapper: one-shot exec, repo review and session resume with a default read-only sandbox.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:WODE25500/dsh-codex
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
OpenAI Codex CLI integration for DeepSeek Harness (dsh) — exposes your
locally installed Codex CLI to the dsh agent as native tools: one-shot
tasks, repository code reviews and session resumes, all via non-interactive
codex exec with a read-only sandbox by default. Codex talks to whatever
provider is configured in ~/.codex/config.toml (on this machine: DeepSeek —
no OpenAI login required) and shares the same provider quota as this session.
Independent community project, not official. The CLI itself comes from OpenAI Codex (Apache-2.0); this plugin only wires
codex execinto dsh's tool/skill system, following the same adapter style asdsh-skillopt(Schemastery config +defineTool+ shell executor +SKILL.md+ bundle patch layer).
Features
- 4 native dsh tools:
codex_status/codex_exec/codex_review/codex_resume - Bundled
SKILL.mdteaching the agent when and how to use them - Schemastery config (model / sandbox / cd / profile / timeoutMs …)
- Bundle patch layer (
cordis.patch.yml) — drop into any profile - Default
read-onlysandbox; writing files requires an explicitworkspace-write/danger-full-accessescalation - Sessions are persisted by default, so
codex_resumeworks;outputFileechoes the agent's final message back into the tool result codex_statusprints a masked provider summary — never any credentials
Prerequisites
- DeepSeek Harness (dsh) installed
- Codex CLI:
npm install -g @openai/codex
codex --version
- A provider configured in
~/.codex/config.toml(e.g. DeepSeek:model_provider,base_url,model) orcodex login. The plugin never reads or displays credentials.
Install
As a bundle in a profile
Add dsh-codex to the profile's bundles, or in the profile cordis.patch.yml:
- insert:
- id: codex
name: './src/index.js'
config:
model: deepseek-v4-flash # empty = use ~/.codex/config.toml
sandbox: read-only # read-only | workspace-write | danger-full-access
cd: /path/to/workspace
Local patch for development
pnpm dsh web --patch ./dsh-codex/cordis.patch.yml
Then ask the agent: "use codex_status to check the Codex setup".
Usage
| Tool | Behavior |
|---|---|
codex_status |
CLI version, config path, masked provider summary |
codex_exec |
One-shot task: self-contained prompt + directory + sandbox level |
codex_review |
Code review of the repo / a diff / a commit (read-only by nature) |
codex_resume |
Resume a session by id or with last=true |
Typical flow:
codex_status
codex_exec prompt="Review F:\8.15.6\src\app.ts and report bugs and optimizations" cd="F:\8.15.6"
codex_review uncommitted=true
codex_resume last=true prompt="Finish the remaining work"
Config (Schemastery)
| Key | Default | Description |
|---|---|---|
codexPath |
codex |
Path to the codex CLI |
model |
— | Default model override (empty = config.toml) |
sandbox |
read-only |
read-only|workspace-write|danger-full-access |
cd |
— | Default working root |
profile |
— | Config profile to layer |
skipGitRepoCheck |
true |
Always pass --skip-git-repo-check |
ephemeral |
false |
Persist sessions (needed for resume) |
json |
false |
JSONL event output |
approveForMe |
false |
Automatic approval review (needs a writable sandbox) |
color |
never |
auto|always|never |
timeoutMs |
600000 |
Per-call timeout (default 10 min) |
Data boundaries & safety
- Default
read-only: codex may inspect but not modify files; escalation is explicit per call. codex_statusmasks the provider config — nothing from the[auth]section is ever printed.- Every
codex_exec/codex_reviewsends your prompt and repository excerpts to the configured provider and spends its quota — validate on a small sample before large batches. - Session files are written to disk (
~/.codex/sessions) by default; useephemeral=truewhen you don't want traces.
Verification (minimal smoke)
codex --version
codex_status # no model spend
codex_exec prompt="Reply with exactly: OK" # tiny spend
Directory layout
dsh-codex/
src/index.js # plugin entry: 4 tools + Schemastery config
skills/codex/SKILL.md
docs/ # Chinese & English docs
cordis.patch.yml # bundle patch layer
License
MIT. The CLI itself is copyright OpenAI Codex (Apache-2.0).
Links
More in this category
yjh051108/dsh-routing-suite★ 7000
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3678
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 324
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 212
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
Fishquito7/dsh-skill-mcp-panel★ 175
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
lire1131/dsh-undo-savepoint★ 172
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.