Codex CLI Integration
Rafter provides two skills for Codex CLI that add remote code analysis and local security.Skills Architecture
Backend Skill (rafter)
API-based security scanning
- Trigger remote SAST/SCA scans
- Retrieve scan results
- Check usage quota
- Read-only operations
Local Security Toolkit (rafter-agent-security)
Local security operations
- Secret scanning in files
- Policy enforcement
- Extension auditing
- Audit logging
Setup
1. Install Rafter CLI
2. Initialize Local Security
~/.codex and installs skills to ~/.agents/skills/rafter/.
To install all detected integrations at once:
3. Restart Codex CLI
Restart Codex CLI to load the newly installed skills.Skill Location
After initialization:Usage
Backend Scanning
Trigger a security scan of your repository:rafter scan alias:
Backend scanning requires a Rafter API key. Set it via
export RAFTER_API_KEY="your-key" or pass --api-key.Local Security
These commands work locally without an API key:
Note: rafter agent scan still works but is deprecated — it will be removed in a future major version.
Skill Auditing
Before installing any third-party skill, audit it:Configuration
Risk Levels
| Level | Behavior |
|---|---|
| Minimal | Basic guidance, most commands allowed |
| Moderate | Approval for high-risk commands, secrets always blocked (default) |
| Aggressive | Approval for most operations, maximum security |
View Configuration
Monitoring
View Agent Activity
Troubleshooting
Skills not loading in Codex CLI
Skills not loading in Codex CLI
- Verify skills are installed:
ls ~/.agents/skills/rafter/ - Re-run:
rafter agent init --with-codex - Restart Codex CLI
Codex CLI not detected during init
Codex CLI not detected during init
Ensure
~/.codex exists, then run: rafter agent init --with-codexWhat’s Next?
Secret Scanning
21+ secret patterns detected
Command Execution
Risk-assessed command validation
Command Reference
Full CLI reference

