aevatar-codex-exec-node-setuplisted
Install: claude install-skill ChronoAIProject/NyxID
# Configure Aevatar codex_exec
## Invocation gate
Continue only when the user explicitly asks to configure, repair, or prove a `codex_exec` target,
or explicitly invokes this skill. If this skill was selected speculatively, stop before mutation:
route feasibility questions to `aevatar-feasibility-advisor` and failure attribution to
`aevatar-triage`.
Choose exactly one target before changing state:
- `managed_sandbox`: use for bounded one-shot work in an operator-selected, empty, ephemeral Git
workspace. Explicitly prepare the eligible native NyxID user's invocation credential before
normal execution; Aevatar then calls that user's exact `chrono-sandbox` UserService and receives
a structured terminal result. No personal node or local Codex login is needed.
- `private_ssh`: use when work must access a user-owned fixed Git workspace, host files, or host Codex configuration. The user owns the private NyxID node, SSH service, principal, forced-command wrapper, and Codex authentication.
Never mix fields between targets. Do not report either target as ready until its public Ornn sample succeeds through Aevatar with exact `CODEX_EXEC_READY`.
## Guardrails
- Never print, copy, or persist NyxID tokens, SSH private keys, Codex credentials, or `auth.json` into workflow input, logs, issue comments, or image layers.
- Never let a workflow choose an image, provider, model flag, shell fragment, approval policy, workspace path, or sandbox bypass.
- Never ask a caller to supply a