简体中文 ·
Install ·
Architecture ·
Codex Collab is a local control plane for multi-agent coding. Give Codex a repository and an outcome; it can ask Claude to challenge the plan, route bounded work to Grok and DeepSeek Harness, and accept only what the controller has actually verified.
Built on Claude Codex Bridge (CCB) and DSH Crew. CCB provides project-scoped Claude/Grok transport. DSH Crew provides the native DeepSeek worker transport and host plugin. Both remain independently licensed and maintained.
git clone https://github.com/zane-gao/codex-collab.git
cd codex-collab
python3 scripts/install.py skill
python3 scripts/install.py doctorThen tell Codex what should happen:
Use $codex-collab on this repository. Ask Claude to audit the plan,
give the API work to Grok and the test harness to DSH,
then review the diff, run acceptance checks, and report the evidence.
Provider dependencies and the private DSH profile are explicit install steps; see Installation. The installer supports dry runs for its write operations.
| Codex Collab adds | Why it matters |
|---|---|
| Revision-pinned task contracts | Every work unit has one owner, allowed paths, a fixed input revision, and acceptance checks. |
| Isolated Git worktrees | Independent jobs can run in parallel without sharing a writable checkout. |
| Durable state and receipts | SQLite records provider identity, native sessions, provenance, and transitions. |
| Controller-side acceptance | delivered means an agent returned; accepted requires non-empty verification evidence. |
| Hashed memory and skill snapshots | Workers receive immutable inputs instead of silently reading whatever changed later. |
| Explicit handoffs | Stop evidence, successor acknowledgement, and a single owner make long work recoverable. |
Codex owns decomposition, routing, integration, and the final decision. Claude is the independent reviewer. Grok and DeepSeek Harness execute bounded work. These are routing defaults, not claims that one model is universally better at a role.
Codex Collab can freeze selected skill instructions and supporting text files from its registered catalog into one hashed task package. Claude, Grok, and DSH receive the same materialized entry point; the receipt records what was actually packaged. Sources come from allowlisted, locally installed directories; third-party skill bodies are not bundled in this repository, and arbitrary target-project skills are not discovered. Omitting skills enables narrow keyword selection; "skills": [] disables automatic selection.
python3 scripts/collab.py skills list
python3 scripts/collab.py skills check lark-doc langfuse
python3 scripts/collab.py skills check scikit-learn matplotlibThe catalog includes a first set of operational skills plus eight ready-made tool skills: prompt optimization, scikit-learn, matplotlib, Mermaid writing, code-review handling, Transformers, Parallel web research, and paper search. Tool packages automatically include collab-tool-guide, which explains runtime checks and cross-harness behavior.
The boundary is deliberate: a task package accepts regular UTF-8 text files, up to 512 files, 512 KiB per file, and 2 MiB total. Hidden files and caches are ignored; unsupported files and nested links are rejected. Before materialization, /.collab-skills/ is added to the target repository's private Git exclude and tracked skill directories are refused, reducing accidental git add . commits without changing .gitignore. This is not an OS sandbox and does not block an explicit force-add. Skill sharing does not install a CLI, log into an account, copy credentials, or prove that every native child agent inherited the package. See Shared skills and Tool skills.
With explicit user authorization, Codex Collab can use its existing controller workflow to improve Codex Collab. Each round fixes the input SHA, file owner, allowed paths, acceptance checks, and stop condition. A worker implements; a separate reviewer challenges; the controller tests and decides whether the next revision is allowed to proceed.
This is bounded recursive improvement, not a new self-evolution engine or model training. Its workflow instructs workers not to recursively invoke the Codex Collab control plane, bypass native depth or concurrency guards, widen authorization, publish changes, or loop without controller acceptance. Read the exact workflow in Bounded self-improvement.
fixed revision -> bounded change -> independent review -> controller tests
^ |
+------------- next authorized revision <-----------+
queued -> running -> delivered -> accepted
|
+-> failed / unknown evidence is preserved
A provider's success response is not acceptance. Codex reads the output, checks the revision and path scope, runs the agreed checks, and attaches evidence. Default list and status output omit frozen snapshot bodies; use explicit --full only when the complete stored record is required.
- Codex Collab is a control plane, not an operating-system sandbox. Workers inherit the tools and credentials already available in their environment.
- Allowed-path checks cover the owned Git worktree; they cannot prove a process wrote nowhere else.
- Credential scanning is best effort. Accounts, tokens, MCP access, and paid model access are never promised by a shared skill package.
- Native child-agent inheritance is instruction-driven, not universally intercepted or enforced.
- Cancellation requests, handoff preparation, delivery, and acceptance are separate states and require separate evidence.
- Provider availability and model support change. Run
doctorand inspect current native receipts before relying on them.
Codex Collab's original adapter code, documentation, and artwork are MIT licensed. CCB is installed separately under AGPL-3.0; its source is not redistributed here. DSH Crew remains MIT licensed, and targeted adapter transformations preserve its notice. Details and pinned provenance are in Third-party notices and UPSTREAM_LOCK.json.
If this is the kind of multi-agent engineering you want to see become boringly reliable, star the repository and bring one concrete workflow to Issues.