Install
$ agentstack add skill-ningzimu-codex-gpt-image-codex-gpt-image ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Codex GPT Image
Use this skill to generate or edit images through Codex OAuth instead of the OpenAI API-key path. The bundled CLI reads the local Codex auth file and calls the Codex Images backend endpoints.
When To Use
- The user asks to use
gpt-image-2or GPT Image through Codex auth/subscription. - The current agent supports
SKILL.mdbut does not have a native image tool. - The user explicitly does not want to use
OPENAI_API_KEY. - The user wants the same local image workflow across Codex, Claude Code, OpenClaw, Hermes Agent, or similar agents.
Do not use this skill when the user wants the official OpenAI Images API, an OpenAI-compatible gateway, or API-key billing. This skill is deliberately Codex-OAuth-only.
Core Workflow
All CLI commands below assume the working directory is this skill folder. Otherwise, resolve the absolute path to scripts/codex_gpt_image.py from this SKILL.md.
- Check local Codex auth:
``bash python3 scripts/codex_gpt_image.py auth-status ``
- If Codex auth is missing, run the device-code login flow:
``bash python3 scripts/codex_gpt_image.py login --open-browser ``
The CLI prints a browser URL and a short user code. The user must complete this step; never ask them to paste tokens.
- Generate an image with the user's actual prompt. Choose only the CLI flags required by the request, and do not reuse prompt wording from this skill.
- Edit or use reference images by passing one or more
--imageinputs. For edits, build the prompt from the user's requested changes and the invariants that must stay unchanged.
- Report the saved path(s), model, size, and whether Codex OAuth was used.
Defaults
- Auth file:
~/.codex/auth.json - Override auth file:
CODEX_AUTH_FILE=/path/to/auth.json - Login fallback:
loginuses OpenAI Codex device-code auth and writes the same auth file - Login client id:
--client-id,CODEX_APP_SERVER_LOGIN_CLIENT_ID, then the public Codex default - Images base URL:
https://chatgpt.com/backend-api/codex - Image model:
gpt-image-2 - Size:
auto - Quality:
auto - Background:
auto - Moderation:
auto - Output format:
png - Output compression:
100forjpegandwebp
For detailed parameter values, defaults, model-specific constraints, and CLI mapping, read references/openai-images-api-parameters.md.
Parameter Selection
Prefer the official API defaults unless the user request requires a specific option. Read the reference before choosing explicit model, size, quality, background, moderation, or output_format values.
Prompting
Keep prompts explicit and production-oriented:
- State the intended asset type.
- Quote any exact visible text.
- Specify composition, background, style, and constraints.
- For edits, repeat invariants: what must stay unchanged.
- Avoid adding logos, watermarks, or extra text unless requested.
Failure Handling
- Missing auth file: run
codex_gpt_image.py login --open-browser, or ask the user to runcodex login, then retry. - 401/403: the Codex OAuth token may be expired, the account may not have access, or the endpoint may reject the session. Ask the user to refresh Codex auth.
- Network failures: retry once if the request is idempotent and the user accepts possible duplicate image generation.
- Never print or paste tokens from
~/.codex/auth.json.
Implementation Notes
The CLI sends Codex Images requests with:
- generation endpoint:
POST https://chatgpt.com/backend-api/codex/images/generations - edit endpoint:
POST https://chatgpt.com/backend-api/codex/images/edits - auth:
Authorization: Bearer - model:
gpt-image-2
It parses the JSON Images response and writes returned base64 image payloads to local files.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ningzimu
- Source: ningzimu/codex-gpt-image
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.