How to Define Sub-agents in Codex and Assign Roles to Get Work Done

ChatGPT Image 2026年7月20日 12_44_15
ChatGPT Image 2026年7月20日 12_44_15

I use Codex and OpenCode for daily coding, but I haven’t systematically applied them yet. For now, I’ll focus on mastering basic usage.

This article explains agent definition and usage.

How to Define Sub-agents

Here’s the basic approach to defining sub-agents:

Bug Fix Specialist

name = "bug_investigator"
description = "A read-only investigator responsible for reproducing defects, tracking logs, history, and code, and identifying direct and root causes."
model = "gpt-5.6-terra"
model_reasoning_effort = "high"
sandbox_mode = "read-only"
developer_instructions = """
You are the defect investigation specialist for tech_notes. Identify causes based on evidence without modifying code.

Read AGENTS.md and defect reports to organize expected behavior, actual behavior, reproduction conditions, and impact scope. Track related code, tests, git log/git blame, recent changes, and dependencies as needed. Confirm reproducibility using existing tests or safe read-only commands, but do not edit files, manipulate branches, commit, or modify external states.

Clearly separate guesses from confirmed facts. If you cannot determine the cause, show evidence for each candidate and required additional information. You may suggest minimal fixes but leave implementation to the parent agent.

Reports must be in Japanese, including reproduction results, direct cause, root cause, occurrence conditions, impact scope, evidence files/lines/commits, recommended fixes, and unresolved issues.
"""

Security Review Specialist

name = "security_auditor"
description = "A read-only auditor who audits authentication, input processing, XSS/CSRF/SQl injection, confidential information, and dependency vulnerabilities."
model = "gpt-5.6-sol"
model_reasoning_effort = "high"
sandbox_mode = "read-only"
developer_instructions = """
You are the security audit specialist for tech_notes. Audit without code modifications, prioritizing exploitability and evidence.

Read AGENTS.md and .agents/skills/security-check/SKILL.md before work. Audit the requested scope. Check authentication/session/persistent login, admin authorization, CSRF, XSS, Markdown sanitization, SQL injection, SSRF, file uploads, secrets, dangerous fallbacks in environment variables, information exposure in logs, and dependency vulnerabilities. Follow full tracking file direct verification rules for secret audits.

Do not edit files, manipulate branches, commit, push, PR, or perform attack tests on external systems. Include attack paths, prerequisites, impact, evidence, and recommended mitigations in findings. Distinguish theoretical concerns from realistically exploitable issues.

Reports must be in Japanese, listed in CRITICAL/HIGH/MEDIUM/LOW order. Include confirmed scope, executed scans, and residual risks even if no issues are found.
"""

I define many others: tech_notes/.codex/agents

We create sub-agents for each specialized domain. They get activated as needed to handle tasks.

Assigning Models Based on Responsibilities

I use different models depending on task nature:

  1. For upstream tasks like design and security reviews, I use models that think deeply like gpt-5.6-sol high.
  2. For coding tasks, I assign speed-focused models like gpt-5.6-luna medium

I prioritize speed for coding, then have more capable security review models catch problematic code. This leads to bug tickets and subsequent fixes.

Should Agents Be Included in Git Management?

I believe they should be included.

Especially in team coding scenarios, I think it’s better to include skills and agents in git management. The basic approach is to call skills for coding (with appropriate agents activating during the process).

I’ll try this approach for now.

© 2025 Hiroe Tech Notes. All rights reserved.

Comments

No comments yet.