← ClaudeAtlas

aevatar-codex-exec-node-setuplisted

Configure and prove Aevatar codex_exec for one NyxID account, choosing operator-managed chrono-sandbox/gVisor for bounded empty-workspace work or private NyxID node-backed SSH for a fixed host workspace. Use for managed eligibility and UserService readiness, private node/SSH hardening, mandatory public-sample verification, or diagnosing typed managed and private-route failures.
ChronoAIProject/NyxID · ★ 36 · API & Backend · score 81
Install: claude install-skill ChronoAIProject/NyxID
# Configure Aevatar codex_exec ## Invocation gate Continue only when the user explicitly asks to configure, repair, or prove a `codex_exec` target, or explicitly invokes this skill. If this skill was selected speculatively, stop before mutation: route feasibility questions to `aevatar-feasibility-advisor` and failure attribution to `aevatar-triage`. Choose exactly one target before changing state: - `managed_sandbox`: use for bounded one-shot work in an operator-selected, empty, ephemeral Git workspace. Explicitly prepare the eligible native NyxID user's invocation credential before normal execution; Aevatar then calls that user's exact `chrono-sandbox` UserService and receives a structured terminal result. No personal node or local Codex login is needed. - `private_ssh`: use when work must access a user-owned fixed Git workspace, host files, or host Codex configuration. The user owns the private NyxID node, SSH service, principal, forced-command wrapper, and Codex authentication. Never mix fields between targets. Do not report either target as ready until its public Ornn sample succeeds through Aevatar with exact `CODEX_EXEC_READY`. ## Guardrails - Never print, copy, or persist NyxID tokens, SSH private keys, Codex credentials, or `auth.json` into workflow input, logs, issue comments, or image layers. - Never let a workflow choose an image, provider, model flag, shell fragment, approval policy, workspace path, or sandbox bypass. - Never ask a caller to supply a