codexbox
Install, configure, or run Codex through the codexbox wrapper, or connect to its HTTP, MCP, Telegram, or cron surfaces.
Rank
62
Safety
84
Downloads
1.7k
Updated
Oct 10, 2026
Version
0.7.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.7K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.7.0release · observed Oct 7, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:codexbox- Install using `clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:codexbox` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/psyb0t/codexbox before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-codexbox/snapshot"
Documentation
CLAWHUB
148,496 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: codexbox
description: "Install, configure, or run Codex through the codexbox wrapper, or connect to its HTTP, MCP, Telegram, or cron surfaces."
homepage: https://github.com/psyb0t/docker-codexbox
user-invocable: true
metadata:
{ "openclaw": { "emoji": "🧑💻", "primaryEnv": "CODEXBOX_URL", "requires": { "bins": ["docker", "curl"] } } }
---
# codexbox
[OpenAI Codex CLI](https://github.com/openai/codex) inside an [aicodebox](https://github.com/psyb0t/docker-aicodebox) container, put on the network. codexbox is aicodebox's `codex` adapter — the HTTP/MCP/Telegram/cron surfaces are aicodebox's, the argv/JSON-event translation is codexbox's.
For installation and configuration, see [references/setup.md](references/setup.md).
## Agent execution
Use `codexbox` when it is on `PATH`. Run it from the workspace the user
named. Do not assemble a new `docker run` command for routine interactive or
one-shot work. The wrapper owns the workspace mount, `~/.codex`, SSH state,
image selection, and session lifecycle.
```bash
codexbox # interactive Codex TUI
codexbox exec "inspect this workspace" # one-shot work
printf '%s\n' "summarize README.md" | codexbox exec -
CODEXBOX_FULL=1 codexbox exec "run the full suite"
```
For a wrapper-started server, prefix container variables with
`CODEXBOX_ENV_`. For example,
`CODEXBOX_ENV_CODEXBOX_API_MODE=1 codexbox` passes
`CODEXBOX_API_MODE=1` into the container. Bare `CODEXBOX_API_MODE` is not
forwarded and does not start the server.
Start a local API and MCP server only when the user asks for one. Authenticate
Codex with `codexbox login --device-auth` or `CODEXBOX_ENV_OPENAI_API_KEY`,
then set the actual model identifiers and distinct bearer tokens:
```bash
CODEXBOX_ENV_CODEXBOX_API_MODE=1 \
CODEXBOX_ENV_CODEXBOX_MCP_MODE=1 \
CODEXBOX_ENV_CODEXBOX_AVAILABLE_MODELS=your-model-id \
CODEXBOX_ENV_CODEXBOX_API_MODE_TOKEN=your-api-token \
CODEXBOX_ENV_CODEXBOX_MCP_MODE_TOKEN=your-mcp-token \
codexbox
```
Use an HTTP or MCP endpoint only when the user asks for a service or provides
an already-running remote URL. MCP plugins connect to a server. They do not
replace the local wrapper.
If `codexbox`, `claudebox`, and `pibox` were installed in the same command
directory, a box can invoke a sibling command directly. The parent wrapper
passes the real host paths and the sibling wrapper file. Do not set
`AICODEBOX_HOST_*`, copy wrapper files, or manually mount another box's state
directory. If the sibling command is absent, ask the user to install it or to
choose another approach.
## Security & safety
- **Set the mode tokens before exposing a port.** `CODEXBOX_API_MODE_TOKEN` (REST) and `CODEXBOX_MCP_MODE_TOKEN` (MCP) each default to no auth when unset, leaving that surface open to anyone who can reach it — run-execution plus full workspace file access. The two are independent (the MCP token has no fallback to the API token), so set whichever mode(s) you enable, and bind to _meta.json
{
"ownerId": "kn79dhvmpjng4rp2jjk8k0v5xx80ccbk",
"slug": "codexbox",
"version": "0.7.0",
"publishedAt": 1791393761115
}references/setup.md
# codexbox setup See [SKILL.md](../SKILL.md#security--safety) for the full destructive-operation and unauthenticated-surface warnings before running any mode that binds a port. ## Requirements - Docker - Codex auth: `OPENAI_API_KEY` (pay-as-you-go) or a ChatGPT Plus/Pro/Team subscription (`codexbox login --device-auth`) - Optional: SSH key for git-over-SSH inside the container (the installer generates one) For ordinary agent work, use the installed `codexbox` command from the target workspace. Do not replace it with a hand-written Docker invocation. The wrapper handles the workspace, state, SSH, image, and nested launch context. ## Quick Install (wrapper) The one-liner installer pulls the image, creates persistent Codex/SSH dirs, and installs the `codexbox` wrapper on `PATH`. **Recommended: download, inspect, then run.** Piping a remote script straight into bash executes unreviewed remote code as you. Download it, read it, then run it: ```bash curl -fsSL -o install.sh https://raw.githubusercontent.com/psyb0t/docker-codexbox/master/install.sh less install.sh # read it before running anything bash install.sh # minimal image — default # CODEXBOX_FULL=1 bash install.sh # full image — every development tool pre-installed # bash install.sh codex # custom command name ``` `CODEXBOX_FULL=1` must be set before `install.sh` runs — the installer needs it in `bash`'s environment. The choice is baked into the installed wrapper; you don't need to set it again afterward. ### Install from a local checkout From this repository, build and install without pulling a published codexbox image: ```bash make install # minimal image make install-full # full image # wrapper only — no build or pull; select full when needed make install-wrapper CODEXBOX_FULL=1 make install-wrapper ``` The installer-only `CODEXBOX_SRC_LOCAL=true` flag skips `docker pull` and requires the selected local image to already exist. `make install-wrapper` uses that existing image without rebuilding it. **Verify:** `codexbox --version` should print the codex CLI version. ```bash codexbox # interactive codexbox exec "inspect this workspace" # one-shot CODEXBOX_FULL=1 codexbox exec "run tests" # temporary full image ``` For a wrapper-started server, use `CODEXBOX_ENV_` before every variable that must reach the container. For example, `CODEXBOX_ENV_CODEXBOX_API_MODE=1 codexbox` starts API mode. ### Sibling boxes Install `codexbox`, `claudebox`, and `pibox` in the same command directory, normally `/usr/local/bin`, to make the sibling commands available inside a box. The parent mounts only the wrapper files read-only. A sibling wrapper then runs through the host Docker daemon and mounts its own host data directory. ## Image Variants | Image | Tag | Contents | |---|---|---| | Minimal (default) | `psyb0t/codexbox:latest` | Codex, Node.js, Python, `uv`, Docker, Git, `jq`, `curl` | | Full | `psyb0t/codex
skill-card.md
## Description: Install, configure, or run Codex through the codexbox wrapper, or connect to its HTTP, MCP, Telegram, or cron surfaces. This skill is ready for commercial/non-commercial use. ## Publisher: [psyb0t](https://clawhub.ai/user/psyb0t) ### License/Terms of Use: MIT-0 ## Use Case: Developers and engineers use codexbox to run Codex in a container for interactive or automated workspace tasks, or to connect it to HTTP, MCP, Telegram, and scheduled workflows. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Exposed API or MCP endpoints may allow unauthenticated execution and workspace file access. Mitigation: Set separate API and MCP bearer tokens and bind services to loopback or use an authenticating proxy. Risk: File deletion can permanently remove workspace data. Mitigation: Review the target before deletion and only remove files the user has authorized. Risk: Remote installers and container images run code in the user's environment. Mitigation: Inspect or pin the installer and Docker image before use. ## Reference(s): - [codexbox on ClawHub](https://clawhub.ai/psyb0t/skills/codexbox) - [codexbox setup guide](references/setup.md) - [codexbox project documentation](https://github.com/psyb0t/docker-codexbox) ## Skill Output: **Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration instructions] **Output Format:** [Plain text, Markdown, code, shell commands, or structured API responses] **Output Parameters:** [1D] **Other Properties Related to Output:** [Output depends on the requested Codex task and interface.] ## Skill Version(s): 0.7.0 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/psyb0t/skills/codexbox",
"sourceUrl": "https://clawhub.ai/psyb0t/skills/codexbox",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T03:09:29.550Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-codexbox/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-codexbox/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T03:09:29.550Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.7K downloads",
"href": "https://clawhub.ai/psyb0t/codexbox",
"sourceUrl": "https://clawhub.ai/psyb0t/codexbox",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T03:09:29.550Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.7.0",
"href": "https://clawhub.ai/psyb0t/codexbox",
"sourceUrl": "https://clawhub.ai/psyb0t/codexbox",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-07T17:22:41.115Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-codexbox/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-codexbox/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.7.0",
"description": "codexbox 0.7.0 - Documentation updates in SKILL.md, including revised instructions and clarifications. - Minor corrections to server endpoint documentation (e.g., `/mcp/` endpoint path). - Removed obsolete file: skill-card.md. - No core functionality changes.",
"href": "https://clawhub.ai/psyb0t/codexbox",
"sourceUrl": "https://clawhub.ai/psyb0t/codexbox",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-07T17:22:41.115Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
