← Empire LLM for CodexCONTENT HISTORY

Update to Empire LLM for Codex

Snapshot Sep 30, 2026 · 23:13 UTC · version 1.7.2

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "description": "Configure, inspect, or remove Empire LLM credentials and project budget settings without exposing secret values. Use when the user asks to set up Empire, enter OpenRouter or Artificial Analysis credentials, check Empire credentials, change the review budget, or sign out.",
  "included_files": [
    {
      "relative_path": "agents/openai.yaml",
      "size_in_bytes": 363
    },
    {
      "relative_path": "assets/empire-llm-logo.png",
      "size_in_bytes": 68413
    },
    {
      "relative_path": "assets/empire-llm-logo.svg",
      "size_in_bytes": 32625
    },
    {
      "relative_path": "assets/openrouter.svg",
      "size_in_bytes": 912
    }
  ],
  "name": "empire-settings",
  "skill_md_contents": "---\nname: empire-settings\ndescription: Configure, inspect, or remove Empire LLM credentials and project budget settings without exposing secret values. Use when the user asks to set up Empire, enter OpenRouter or Artificial Analysis credentials, check Empire credentials, change the review budget, or sign out.\n---\n\n# Empire Settings\n\nManage Empire locally. Never ask the user to paste an API key into chat, a prompt, a project file, or a shell command.\n\nThe shared router keeps JSON as its default automation contract and accepts\n`--view compact|detailed` before or after a command for native-Codex Markdown.\nUse the compact view for ordinary redacted status and budget summaries, and the\ndetailed view for diagnosis or reconciliation. A view must never reveal fields\nthat the underlying redacted result omits.\n\n## Exposed-secret guard\n\nIf a user includes a credential-looking value in chat, never echo it, quote it, forward it to a tool, store it, test it, or treat it as usable configuration. Tell the user to revoke it and create a replacement. Resume setup only after the replacement is entered through the hidden terminal prompt. This guard applies even when the user explicitly asks Codex to store the pasted value.\n\nCodex does not provide a native secret-field schema for skill-only plugins. Do not imitate a settings form in chat. Do not add an MCP app merely to collect credentials. Use the local hidden prompt and system keyring on every supported platform.\n\n## Credential settings\n\n1. Resolve the sibling `../empire-review` directory from this `SKILL.md` as `EMPIRE_REVIEW_ROOT`.\n2. Run the redacted credential doctor before any setup prompt:\n\n   ```bash\n   python3 \"$EMPIRE_REVIEW_ROOT/scripts/empire_router.py\" doctor\n   ```\n\n   Treat its states as a finite-state contract:\n\n   - `present: true` — use the credential; never prompt again.\n   - `present: false`, `action: setup` — absence is verified; setup may be offered.\n   - `present: null`, `action: retry_with_keyring_access` — the operating-system keyring is inaccessible from the current sandbox. Retry this same redacted doctor command with narrowly scoped Keychain/keyring access. Do not run setup and do not ask the user for the key again.\n   - `present: null`, `action: install_secure_keyring` — no supported secure store is available. On Linux, install `secret-tool` and a compatible Secret Service; use environment variables only for CI/headless operation.\n\n3. For verified initial setup or an explicitly requested replacement, instruct the user to run this interactively in their local terminal, or open an interactive terminal session in which the user—not Codex—types the secret:\n\n   ```bash\n   python3 \"$EMPIRE_REVIEW_ROOT/scripts/empire_router.py\" setup\n   ```\n\n   The prompts use `getpass`, so entered characters are not echoed. OpenRouter is required and Artificial Analysis is optional; pressing Enter at the optional prompt preserves an existing Artificial Analysis credential. Store credentials under `empire-codex-router` in macOS Keychain, Windows Credential Manager, or Linux Secret Service. Secret values must never appear in output.\n   Setup reads each saved key back before reporting `configured`. A successful write whose readback is sandbox-blocked reports `configured_unverified`; rerun `doctor` with narrowly scoped keyring access instead of prompting again. A successful write followed by a verified missing result is an error.\n4. To inspect configuration, run `doctor`. Report only `present`, `source`, and `action`; never report a value.\n5. To remove credentials, run `logout` and preserve its confirmation prompt.\n\nOpenRouter is the default inference provider. Artificial Analysis supplies optional benchmark evidence and does not execute reviews.\n\nUse environment variables only for CI or headless systems. On Linux, if Secret Service is unavailable, explain that the user must install `secret-tool` and a compatible keyring service; never create a plaintext fallback.\n\n## Public web research\n\nThe web skill in 1.7.2 uses native Codex web tools and needs no provider key.\nThe legacy external web adapter is retired. Do not run its old setup, doctor,\nupload, or browser commands. Existing web-provider credentials are left untouched;\nthis release does not inspect, migrate, or delete them.\n\n## User-owned provider\n\nEmpire also supports one user-selected OpenAI-compatible HTTPS chat-completions provider. Gather only non-secret values in chat: provider slug, endpoint, native model ID, corresponding OpenRouter catalog model ID when available, input/output USD per million tokens, and context size. Then run:\n\n```bash\npython3 \"$EMPIRE_REVIEW_ROOT/scripts/empire_router.py\" provider setup \\\n  --name PROVIDER_SLUG \\\n  --endpoint \"HTTPS_CHAT_COMPLETIONS_ENDPOINT\" \\\n  --model \"NATIVE_MODEL_ID\" \\\n  --catalog-model \"OPENROUTER_CATALOG_MODEL_ID\" \\\n  --input-cost-per-mtok \"INPUT_USD\" \\\n  --output-cost-per-mtok \"OUTPUT_USD\" \\\n  --context-tokens CONTEXT_TOKENS\n```\n\nThe API key is entered only at the hidden prompt and stored in the system keyring. The non-secret settings file is mode `0600` where supported. Never infer direct-provider prices from OpenRouter; ask the user to obtain prices from their provider account.\n\nUse `provider status` for redacted status, `provider select openrouter|direct` to choose the default route, and `provider remove` to delete the direct credential and metadata. A single review can override the saved route with `review --provider openrouter|direct`.\n\n## Project budget\n\nSet or inspect a repository-local logical budget through the same router:\n\n```bash\npython3 \"$EMPIRE_REVIEW_ROOT/scripts/empire_router.py\" budget status --repo .\npython3 \"$EMPIRE_REVIEW_ROOT/scripts/empire_router.py\" budget set --repo . --limit-usd \"5.00\"\npython3 \"$EMPIRE_REVIEW_ROOT/scripts/empire_router.py\" budget pending --repo .\n```\n\nChanging a budget is allowed only when the user requests the new limit. Never perform a paid live review merely to test settings.\n\nAn ambiguous provider outcome remains reserved. Reconcile it from provider\nbilling evidence with `budget reconcile --reservation ID\n--observed-cost-usd USD`. Use `budget release-pending` only when the provider\nproves no billable request exists; it requires `--yes` and a recorded reason.\n"
}

SHA-256 of public snapshot: 88147ad1f4994be51d516617631eb3f9b5e27e57fd417bb53e7276e3bc7b8a98