Install, inspect, update or remove native Model Guard for Codex CLI. Use for its status line, model-routing diagnostics (effective-model header and response body label), the stop it applies to a downgraded thread, its refusal of Codex's automatic model switches, passive 516 reasoning anomalies and account display.
Installs into .claude/skills of the current project.
Are you the author of Codex Model Guard?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/ventusff-codex-model-guard)
---
name: codex-model-guard
description: Install, inspect, update or remove native Model Guard for Codex CLI. Use for its status line, model-routing diagnostics (effective-model header and response body label), the stop it applies to a downgraded thread, its refusal of Codex's automatic model switches, passive 516 reasoning anomalies and account display.
---
Model Guard extends the native Codex status line. It uses a pinned custom build of official Codex with auditable source patches. Do not add a terminal wrapper, tmux server, separate live app-server adapter or shell PATH override.
The default footer is quiet: selected/requested model, request effort and the known account. The guard holds the model the user selected (the configured default or the last `/model` choice; a configured `review_model` is the one other model a request may name). Codex's automatic switches — the Luna Reserve fallback to the hidden `gpt-reserve` model when ordinary usage is exhausted, and banner-announced fallbacks — are declined with a warning and an amber footer line; the Reserve-only picker is disabled so a thread stuck on `gpt-reserve` can be moved back by hand. Three things stop the thread: a request for a model other than the selection, a disclosed different effective model (red), and a response body whose `model` label names another family or a size tier than the request (orange; a same-family label with a date or suffix stays quiet). A stop interrupts the running turn, writes a red error, keeps a bold red `STOPPED` line under the footer and holds every further turn (the typed prompt returns to the composer) until the user selects a model with `/model`; it is remembered per thread for the life of the process, survives thread switches and side conversations, interrupts any turn that still starts on the thread, and threads running in the background are judged and interrupted too. A thread restored on a different model than the configured one stops before its first turn, and `gpt-reserve` is flagged in red whenever it is active. Codex's switch back from Reserve is allowed only to the selection and never lifts a stop. A repeated reasoning anomaly (amber) warns, and stops only with `halt_on_reasoning_anomaly` in `config.json`. Missing disclosure and single 516 hits belong in `/status`; never add permanent question marks or yellow unknown banners. At high/xhigh/max/ultra, at least three of the last five measured responses with exactly 516 reasoning tokens produce the heuristic warning. That threshold has no calibrated false-positive rate and does not identify a replacement model. Never infer recovery from answer quality; the guard itself never retries or changes models.
For setup/update, run `python3 scripts/install.py` from this plugin's root (two directories above this skill). Use `--language zh` or `--language en`. The prebuilt runtime requires Linux x86_64, glibc 2.36+, Python 3.12+, and official standalone Codex 0.158.0 with its existing executable symlink. An installation that already exists is moved to the plugin's current release with `model-guard-codex update`, which also brings the official standalone package to the tracked Codex version; a Model Guard build does this by itself in the background when Codex's startup update check finds a newer plugin release (`auto_update` in `config.json`, on by default; log in `update.log` under the installation root); `codex update` inside a Model Guard build runs the same command, and a bare official installer run replaces the entry (`doctor` reports that and names the command). The installer verifies `native/release.json`, prepares versioned files, then atomically switches the Codex symlink; it removes earlier versioned packages no session still uses. It preserves model/provider defaults and login files. Native builds must be updated together with the plugin; do not silently substitute a different upstream version. See `native/README.md` for source builds.
A running Codex process keeps the executable it started with, so an open session never gains Model Guard by installation alone. The installer and `model-guard-codex doctor` list such sessions with their directories; tell the user to finish or `/quit` each one and start `codex resume` there. Do not say that already running sessions were upgraded, and never terminate user sessions to finish installation, removal or validation.
Run `model-guard-codex doctor` after installation. Then `codex`, `cx`, `resume` and `fork` work through the same native executable in the current shell. Normal input handling, terminal scrolling, paste, profile loading and directory selection remain Codex's own. Remote app-servers need the metadata extension for complete disclosures.
Use `/status` inside the relevant Codex conversation for live routing evidence, the body label and reasoning details. Selected model, effort setting, the body label, assistant self-identification, benchmark answers and a 516 hit cannot prove backend identity. A provider may omit or rewrite effective-model headers. Explain absent evidence when asked; do not claim an unknown route is verified. Never read login files, persist raw transport logs, or edit Codex session records to diagnose routing. Read `ROUTING.md` or `ROUTING.zh-CN.md` for researched community methods and limits.
`model-guard-codex probe --json` makes one separate ephemeral read-only model request through official authentication and consumes provider quota. Use it for an authorized active check; `-m MODEL -r EFFORT` affects only that probe. It cannot certify another conversation. Exit codes are 0 for matching effective-model disclosure, 2 for a disclosed difference, 3 for missing disclosure, 4 for failure/unavailability, and 5 for a body label that differs while nothing was disclosed. JSON omits account identifiers and conversation text. Old external `status` and `check` commands direct users to native `/status`.
For removal, run `model-guard-codex remove`. It restores the original Codex symlink only while the entry is still managed, and preserves running sessions, packages and preferences. The plugin may then be removed with Codex's plugin manager if requested.