All skills
am-will avatar

/role-creator

@ab9235e
by am.willam-will/codex-skills1k stars
60

Create and update Codex custom agents using standalone custom-agent TOML files.

Use this Skill: https://skilld.dev/gh/am-will/codex-skills/role-creator

This session only. Nothing lands on disk.

referencesrole-config-reference.md

≈828 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Role Config Reference

Canonical Sources In This Repo

  • codex-rs/core/src/config/mod.rs
  • codex-rs/core/src/agent/role.rs
  • codex-rs/core/src/tools/handlers/multi_agents.rs
  • codex-rs/core/config.schema.json

Role Declaration Shape (~/.codex/config.toml)

[agents.researcher]
description = "Read-only researcher role"
config_file = "~/.codex/agents/researcher.toml"

Supported keys under [agents.<role>]

  • description
  • config_file

Anything else under [agents.<role>] is unsupported.

Role config_file Shape

Role config_file is parsed as a full ConfigToml layer. Top-level keys must be valid top-level keys from codex-rs/core/config.schema.json.

Minimum policy for this skill

Require these fields in every role config:

  • model
  • model_reasoning_effort
  • developer_instructions

Do not add optional keys (sandbox, web_search, mcp_servers, or others) unless explicitly requested by the user.

Recommended default profile (when user does not specify):

  • model = "gpt-5.3-codex"
  • model_reasoning_effort = "medium"

Useful enums

  • model_reasoning_effort: none|minimal|low|medium|high|xhigh
  • sandbox_mode: read-only|workspace-write|danger-full-access
  • web_search: disabled|cached|live

Runtime Merge Notes

  • Spawn starts from parent turn config.
  • Role config file is merged as a config layer.
  • Spawn then forces approval_policy = never.
  • Collab depth limits still apply.

Practical implication: role config can tune model/sandbox/tools/etc., but spawn-time enforced overrides still win.

Configuration Categories With Examples

These are common categories users ask for when building custom roles.

1) Minimal role (recommended default)

model = "gpt-5.3-codex"
model_reasoning_effort = "medium"
developer_instructions = """
You are a focused implementation assistant.
Work only in requested files, validate changes, and report exact evidence.
"""

2) Model/reasoning/style knobs

model = "gpt-5.3-codex"
model_reasoning_effort = "high"
model_reasoning_summary = "detailed"
model_verbosity = "high"
personality = "pragmatic"
developer_instructions = "..."

3) Sandboxing and workspace controls

sandbox_mode = "workspace-write"

[sandbox_workspace_write]
network_access = true
writable_roots = ["/path/to/repo"]

4) Search and feature toggles

web_search = "cached"

[features]
memory_tool = false
shell_tool = false

5) MCP server controls (basic and rich)

Basic enable/disable:

[mcp_servers.linear]
enabled = true
required = false

Rich server definition:

[mcp_servers.linear]
command = "npx"
args = ["-y", "@modelcontextprotocol/server-linear"]
env_vars = ["LINEAR_API_KEY"]
enabled = true
required = false

6) App connector toggles

[apps.notion]
enabled = true

[apps.monday]
enabled = false

7) Skill-aware role instructions

developer_instructions = """
Use the $frontend-design skill for UI/UX work.
Build mobile-first, accessible, and production-grade interfaces.
"""

Inheritance Rule Of Thumb

  • Configure only what must differ from parent.
  • Leave everything else omitted to inherit.
  • Prefer minimal role config unless user explicitly requests stronger constraints.

Source: SKILL.md on GitHub

1 alert13d5 checks · Risk HIGH
  • Gen Agent Trust Hub13d

    The skill contains a critical security flaw in its configuration script that allows for filter injection, potentially granting unauthorized access or disabling security features. Additionally, it provides a mechanism to read sensitive system files, which could lead to data theft.

  • Socket13d

    1 alert: gptAnomaly

  • Snyk13d

    Risk: LOW · No issues

  • Runlayer7mo

    9/9 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at ab9235e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago
  • codex
  • toml
  • agents
  • custom-agents
  • role-definition
  • configuration

README badge

README badge for am-will/codex-skills/role-creator

Manages creation and updates of Codex custom agents via standalone TOML configuration files in ~/.codex/agents/ or project/.codex/agents/. Collects required inputs (name, description, developer_instructions, model, reasoning_effort), validates them before writing, and generates ready-to-run agent spawn commands.

Generated from the current SKILL.md.

What scope should I use — global or project?
Global agents live in ~/.codex/agents/ and are available across all projects. Project agents live in <project>/.codex/agents/ and are scoped to that project only.
Do I need to register the agent in ~/.codex/config.toml?
No. The agent TOML file is the source of truth. config.toml is only for global runtime settings like thread limits, not per-role registration.
What model should I specify?
The skill recommends gpt-5.3-codex unless you have a specific request. You must explicitly provide the model name — it will not be inferred.
Can I add optional settings like sandbox_mode or web_search later?
Yes. The skill creates a minimal file with only required keys by default. You can edit the TOML to add optional settings like sandbox_mode, web_search, mcp_servers, or model_reasoning_effort after creation.
What characters are allowed in nickname_candidates?
Only ASCII letters, digits, spaces, hyphens, and underscores. Values must be unique and non-empty if the field is included.

Generated from the current SKILL.md. These answers refresh after source changes.