← Chronos for CodexCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Chronos for Codex
Snapshot Sep 30, 2026 · 23:14 UTC · version 0.9.2
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "chronos",
"description": "Fully set up Chronos supervision and Heartbeats in one local Governor, or detect and mitigate Codex process, CPU, memory, handle, disk, diagnostic SQLite log, and token-quota degradation on Windows. Use for first-use setup, long-running task monitoring, Codex or PC lag, logs_2.sqlite growth, disproportionate token or quota use, and before or after long-running parallel work.",
"included_files": [
{
"relative_path": "scripts/chronos.cmd",
"size_in_bytes": 180
},
{
"relative_path": "scripts/chronos.ps1",
"size_in_bytes": 162761
},
{
"relative_path": "scripts/heartbeat.ps1",
"size_in_bytes": 181581
},
{
"relative_path": "scripts/hook-intake.ps1",
"size_in_bytes": 13467
},
{
"relative_path": "scripts/session-registry.ps1",
"size_in_bytes": 97541
}
],
"skill_md_contents": "---\nname: chronos\ndescription: Fully set up Chronos supervision and Heartbeats in one local Governor, or detect and mitigate Codex process, CPU, memory, handle, disk, diagnostic SQLite log, and token-quota degradation on Windows. Use for first-use setup, long-running task monitoring, Codex or PC lag, logs_2.sqlite growth, disproportionate token or quota use, and before or after long-running parallel work.\n---\n\n# Chronos\n\n## Installation preflight\n\nRun this lightweight check once when Chronos is first used in a task:\n\n```powershell\n\"<skill-root>\\scripts\\chronos.cmd\" -Action install-status\n```\n\n`sourceObservation=cache_inventory_not_enabled_state` means the result shows\nvalid cached package sources; cache presence alone does not prove that a source\nis enabled. `sourceConflict=CONFIRMED` requires the running Directory package\nand an enabled legacy Git configuration. If both cached sources exist but that\nproof is absent, report `POSSIBLE` and inspect the plugin manager before making\nchanges. Explain that Codex treats the Git marketplace and Plugins Directory as\nseparate sources. Prefer `openai-curated-remote`. For a confirmed conflict,\nwith narrow user approval,\nremove the legacy source through the Codex plugin manager, never by editing\nconfiguration or cache files directly:\n\n```powershell\ncodex.cmd plugin remove chronos@chronos\ncodex.cmd plugin marketplace remove chronos\n```\n\nThen fully quit and reopen Codex before starting a fresh task. An existing\nprocess or task's loaded skill catalog cannot be hot-swapped. Do not remove the\nlegacy source when the Directory source is\nabsent, and do not imply that Chronos changed the active task catalog.\n\nKeep inspection and Heartbeat evaluation lean and on-demand. Do not create an\noperating-system scheduler, daemon, service, telemetry file, or persistent log.\nWhen trusted and dispatched by Codex, the plugin's five monitoring hooks write\nprotected task, subagent, and completed-turn events to a bounded local inbox.\nThe next status or Governor cycle merges them into the supervision registry\nunder its mutex. It validates DPAPI identities inside the per-file boundary and\npersists bounded slot-and-content receipts before deletion. It scans both\nbounded inboxes before pruning receipts and defers temporarily unreadable files,\nso one bad, locked, or queued file cannot block or replay supervision. Four request\nasynchronous execution where supported; `SessionEnd` remains synchronous. They do not run on tools, commands, approvals, or prompts and\nreturn no model context. Direct diagnostic hooks use the same protected event\nformat if registry contention prevents an immediate write. On Windows, each\ndefinition uses a quote-free encoded launcher\nbecause Codex passes the configured command through `cmd.exe`; the decoded\npayload only resolves the installed plugin root and invokes the small intake\nscript. Do not rewrite it as a quoted `-File` command or route configured hooks\nthrough the full supervision engine.\n\n## Full setup request\n\nWhen the user asks to set up Chronos fully, treat the request as an explicit\nrequest to verify the installed source, run compact native status, and apply the\n`chronos-governor` skill's Automatic Supervision Bootstrap. That bootstrap must\nreuse or create one dedicated Governor, enable one host recurrence for\nsupervision and due Heartbeat evaluation, and verify zero worker recurrences.\nThis is a hard gate, not a best-effort sequence: the host must create or enable\nno recurrence until initialization succeeds, supervision and Heartbeat status\nare readable, one complete caller-aware inventory accounts for the selected\nGovernor exactly once, and the cycle returns `recurrenceEligible=true`. Any\nearlier failure must end with zero active current-key recurrences and no recovery\nrecurrence.\nDo not stop after an inspection or return setup instructions for the user to\nrelay. Never bypass or auto-approve Codex hook trust. If hooks remain untrusted,\ncomplete setup through authoritative host inventory without asking the user to\nregister tasks; state only that optional hook acceleration is pending trust. An installed, active, or\ntrusted `/hooks` entry is configuration evidence, not proof that the command\nexecuted. Read `hookExecutionObservation`, `hookRuns`, and `lastHookUtc` from\nnative supervision status. Report `not_observed` until a fresh post-trust\nlifecycle or completed-turn event advances those fields. Keep one complete host\ninventory per Governor cycle as the task-discovery and liveness authority\nwhether hooks execute or not. Hooks are an optional accelerator only.\n`hookRequiredForAutonomy=false` must remain true, and a non-dispatching host\nmust not make setup fail after complete inventory and topology postconditions\npass.\n\nTreat a nonempty `CODEX_HOME` as the installation boundary. Otherwise use the\ncurrent user's `.codex` directory. The native modules canonicalize and hash this\nvalue; they never return the raw path. Invalid or inaccessible overrides fail\nclosed before state, claim, or recurrence eligibility can exist. Reject a\nreparse point in any path component, including an ancestor junction. Consider\nunscoped state from older releases only for the default `.codex` home; an\nexplicit or environment-provided home must not import it.\n## Complete status request\n\nWhen the user asks for a complete Chronos status, run the Inspector, supervision\nstatus, and Heartbeat status. Present machine health separately from workflow,\nquota, approval, rule, SQLite, and supervision conditions. A numeric zero is\nnot evidence of absence when coverage is partial, unsupported, outside the\nwindow, or discontinuous; preserve those coverage labels. Report hook trust and\nobserved hook execution separately. This status-only request must not create a\nGovernor task, recurrence, worker, Heartbeat event, or task wake.\nHeartbeat status without an input snapshot is prior-state inspection. Report its\n`statusMode=prior_state` and its `evaluation` field as `observed`, `partial`, or\n`unsupported`; do not call unsupported coverage healthy. A new partial or\nunsupported family label replaces prior observed coverage and breaks continuity.\n\n## Supervision\n\n`-Action supervise` exposes compact status and discovery for one host-managed\nGovernor task. Worker tasks do not invoke Chronos, run a recurrence, or receive\nroutine wakes. Their model choice is independent of Governor. The host should\nreconcile an existing matching host recurrence, reuse a verified Governor, or\ncreate one fresh task with no inherited history; never automatically fork a\nworking task. The default is at most one Governor turn per active hour or one\nper six idle hours, with a 336-cycle or 14-day rotation bound. Host reconciliation\nuses the complete scoped equivalence key returned by status, deterministic immutable-ID winner\nordering, at most three attempts, and the exact postcondition one live Governor,\none active recurrence, and zero active duplicates. Only Governor cycles zero and\none repeat the installation-scoped host convergence check; normal cycles do not rescan host\nautomations.\n\n```powershell\n\"<skill-root>\\scripts\\chronos.cmd\" -Action supervise -SupervisionAction status\n```\n\nOnly the Governor task runs `-SupervisionAction initialize`, `cycle`,\n`reconcile-host`, and `discover`. Every Governor recurrence must use `cycle`\nwith one fresh complete host inventory. Schema v1 requires the Governor in the\nraw list. Schema v2 may declare `callerVisibility=excluded_by_host`, omit only\nthe current Governor, and let the same cycle account for that registry-verified\ncaller without a second host query. Passive `discover` does not increment\nthe Governor cycle counter. The `.cmd` launcher always applies the required noninteractive\nWindows PowerShell 5.1 execution-policy flags.\nHost task tools remain the authority for whether a task is live. The registry\nis a privacy-bounded discovery hint, not a task transport or security boundary.\nSee the public [supervision contract](https://github.com/FaxanFM/chronos/blob/main/docs/SUPERVISION.md).\n\n## Heartbeats\n\nHeartbeat evaluation is an opt-in action of this installed Chronos skill, not a\nseparate product. A host-side collector supplies a privacy-safe normalized JSON\nsnapshot; Chronos persists compact transition and dedupe state, then routes only\nmeaningful changes to one Governor inbox. Monitored tasks can use any model and\ndo not run Heartbeats. The recommended host configuration is one Governor task\nusing `gpt-5.6-terra` with Medium reasoning. The host selects that model; Chronos\ncannot change a task's model setting.\n\n`OwningSolThread` is always `governor`. `Owner` and `Subject` are compact routing\nhints, not authority by themselves. The native script never sends a message or\nstarts another task. The Codex-host Governor may use `send_message_to_thread`\nfor one fixed-template intervention after it verifies exactly one live affected\ntask. It never broadcasts or gives monitored tasks a recurrence. The host supplies collector coverage\nand chooses when to invoke the action. The engine enforces its registered\nminimum cadence for each observed family. Supply a stable\n`sourceEpoch` and increasing `sourceSequence`; without continuity proof, Chronos\ncan open a condition but will not resolve one. Governor-generated snapshots use\nschema v2 and include all eight public family coverage labels. Every accepted\nschema-v2 snapshot advances the source watermark before family cadence is\nchecked, including partial, unsupported, and cadence-skipped snapshots. Host inventory is\nthe liveness authority, but it is not a substitute for this collector snapshot.\n\n```powershell\n\"<skill-root>\\scripts\\chronos.cmd\" -Action heartbeat -HeartbeatInputPath snapshot.json\n```\n\nUse `-HeartbeatStatePath` only for controlled test or host-managed state. The\ndefault state is\n`%TEMP%\\Chronos\\Heartbeat-v2\\<scope-sha256>\\heartbeat-state.json`.\nExplicit state paths are accepted only beneath that versioned TEMP root or the\nLocalAppData Heartbeat root.\nChronos imports readable prior state without modifying its source directory. If\nthe prior sandbox-owned directory is inaccessible, it starts safely in the new\nnamespace and reports that migration result in compact status.\n`priorStateDisposition=unavailable_preserved` and\n`priorStateWriteAttempted=false` mean Chronos made no write or ownership-change\nattempt against that prior state; they do not claim access to protected data.\nRun the same action without an input path to show compact Heartbeat status.\nAfter the host deduplicates and successfully delivers an event, pass its stable\nID with `-HeartbeatAcknowledgeEventId <event-id>`. Unacknowledged events remain\nin a bounded local outbox and receive at most one retry after 15 minutes with the\nsame ID. `plan` and `fail-closed` consume actionable events atomically.\nUse `-HeartbeatInspectorOutputPath` only with captured compact `CHRONOS` and\n`CHRONOS EFFICIENCY` lines from a policy-authorized Inspector run. Pass\n`-HeartbeatInspectorAuthorized` with the schema-v2 companion snapshot. The\nadapter rejects missing, incompatible, or stale provenance. See the public\n[Heartbeat contract](https://github.com/FaxanFM/chronos/blob/main/docs/HEARTBEATS.md)\nfor the strict normalized input contract and coverage limits. Complete Guardian\ncoverage also requires every required Inspector metric to parse and pass its\nrange check. Malformed complete evidence fails closed; it is never converted to\nan observed result or a zero.\n\nOnly the dedicated Governor uses `-HeartbeatInterventionAction`. It must plan\nall events before sending, keep one active intervention per target generation, recheck the\ntarget generation before claiming a send, and use fixed returned instructions.\nTransport acceptance is not task acknowledgement. A task response is not proof\nof recovery; a later observed Heartbeat cycle or allowed independent host check\nmust verify the postcondition. Unknown delivery never retries. Definite failure\ngets one retry. Governor/self-origin events never target the Governor.\n\nToken volume is not price. Do not infer cost, quota impact, or efficiency from a\nmodel name. Governor-origin `USAGE_BURN` remains Governor-local unless a second\nsame-subject, same-window event independently shows stall, review amplification,\nor machine degradation. When it returns `GovernorLocalAction`, update only the\nGovernor recurrence, verify one active recurrence at the returned cadence, and\nacknowledge the event only after that postcondition holds. Do not message a\nmonitored task or turn routine findings into user chores.\n\nBefore running Chronos, resolve `<skill-root>` to the directory containing this `SKILL.md`. Do not assume the user's workspace is the skill directory and do not search the whole disk.\n\n## Run an inspection\n\nInspect only when lag is reported, before extending an already long-running session, or when long-running parallel work finishes:\n\n```powershell\n\"<skill-root>\\scripts\\chronos.cmd\" -Action inspect\n```\n\nReturn only the compact `CHRONOS` summary unless details are requested. Do not paste raw process tables into the conversation.\n\nThe inspection opens only the exact Codex `logs_2.sqlite` database in logical\nread-only mode. It does not change rows or schemas. SQLite can create or update\n`-wal` or `-shm` coordination sidecars while opening a WAL-mode database, so\nread `sqliteOpenMode`, `sqliteJournalMode`,\n`sqliteSidecarMutationPossible`, and `sqliteSidecarMutationObserved`. It reports\ndatabase size, reclaimable freelist space, WAL activity, sequence movement, and\nthe aggregate TRACE percentage from up to 2,000 recent rows. It never reads log\nbodies.\n\nIt also scans only the tail of recent, known Codex `sandbox*.log` files for two\nexact filesystem-helper failure markers. It returns aggregate booleans and\nnever returns log text or paths.\n\nFor quota diagnostics, it streams at most 20,000 session inventory entries\nunder a three-second target, then reads at most 2 MiB from each of up to eight\nrollout files modified in the last six hours. One filesystem call can exceed\nthe target. It retains only structured token-count,\nturn-context, compaction, approval-state, and worker-call fields. It counts an\nautomatic review only when a `turn_context` record reports\n`model=codex-auto-review`; similarly named bookkeeping records do not count as\nreviews. It never returns raw rollout lines, prompts, responses, tool arguments,\ntool output, identifiers, or paths. It reports aggregate parser-integrity,\nreviewer, safe categorical approval, lineage, fork-context, and exact\ncross-rollout duplication counters. Structured proposed-prefix arrays and\napproval identifiers may be hashed in memory for repetition and state-transition\nanalysis. The inspector never returns prefixes, hashes, rule text, identifiers,\nor credential-shaped values. Ephemeral hashes are discarded when the process\nexits. Those counters do not alter health thresholds or scoring.\n\nThe same on-demand inspection reads up to 32 supported files only from the known\nCodex rules directory. It returns aggregate rule structure and secret-shape\ncounts, never rules, commands, assignments, paths, hashes, or values. It does not\nedit a rule.\n\nUse `machineHealth` and the leading `CHRONOS` level for process, memory, handle,\nCPU, disk, and filesystem-helper operability. Read `resourceDiagnosticLevel`\nfor the separate diagnostic-database condition and `overallDiagnosticLevel`\nfor the most severe observed diagnostic domain. Do not present storage or rule\nhygiene as current machine failure when `machineHealth=HEALTHY`.\n\nRead `tokenCoverageWindowHours`, eligible and selected file counts,\n`tokenCoverageCapped`, truncated tails, and `tokenCoverageContinuity` before\ninterpreting numeric totals. `tokenSpawnObservation` and\n`tokenCompactionObservation` distinguish observed events, a complete\nnot-observed result, partial coverage, unsupported event formats, and\nunavailable data. A zero with `partial`, `unsupported`, or `unavailable` is not\nevidence that the event never occurred.\n\n`approvalReviewTurnsObserved`, `approvalReviewerSessionsObserved`, review rate,\ninterval, burst, confidence, parent-link, source, repeat-class, allowed/denied,\ninspection-shaped, boundary-cause, and persistence fields\nare bounded observations, not account-wide billing totals. Check\n`approvalReviewObservation`, `approvalReviewCoverage`, and\n`approvalRequestObservation` before interpreting them. `unsupported_schema` or\n`observed_insufficient_structure` means the rollout did not expose enough safe\ncategorical data; do not infer a cause from model names or unstructured text.\nCurrent structured escalation calls are counted without returning commands,\njustifications, tool output, call IDs, prefixes, or hashes. Read\n`approvalRequestSchemas`, resolved/unresolved request counts,\n`approvalResolutionObservation`, and latency sample fields together. A function\ncall output proves only that a request reached a terminal tool result; it does\nnot prove an allow or deny decision without an explicit structured decision.\n`metricSource=local_rollout`, `dashboardEquivalence=unsupported`, and\n`billingInference=unsupported` are hard semantic boundaries. The inspector is\ndiagnostic-only: it never changes reviewer models, approval modes, or trusted\ncommand rules.\n\nInterpret approval problem classes independently:\n\n- `persistence_runaway` requires a structured `ALLOW`, unresolved pending\n state, and a later equivalent request. An explicit persistence failure is\n reported separately and does not by itself establish a runaway.\n Recommend repairing approval persistence before changing reviewer cost.\n- `rule_miss_amplification` means one structural equivalence repeated across at\n least two independently resolved `ALLOW` reviews. Denied, unknown, mixed, or\n unresolved repetition is not a rule miss. Review the exact operation manually before\n considering one narrow, reversible rule.\n- `legitimate_or_diverse_boundary_volume` means the available evidence does not\n prove either defect. Do not weaken the sandbox.\n\n`reviewerEscalationsObserved` means reviewer-originated escalation traffic. Do\nnot call it reviewer recursion unless `approvalRecursionRisk=observed`, which\nalso requires directly observed nested reviewer lineage.\n\nUse the Rule Governor fields separately. `rule_secret_exposure` requires removal\nof credential material and rotation if it may remain valid, but never repeat the\nvalue. `rule_brittleness_warning` identifies literals longer than 256 characters.\n`broad_interpreter_rule` identifies interpreter-wide trust. Never create or\nrecommend broad PowerShell, shell, Python, Node, curl, network, filesystem-write,\nor outside-workspace rules.\n`ruleSecretCandidateOrdinals`, `ruleSecretCandidateClasses`, and\n`ruleSecretConfidence` identify only the bounded local rule order and safe shape\ncategory. Use an ordinal for local follow-up; never paste the rule or value.\n\n`machineHealthContributors` names the unchanged threshold clauses that produced\nthe process diagnosis. `machineHealthConfidence=threshold_observation_only` and\n`responsivenessObservation=not_measured` mean the result is resource pressure,\nnot a measured UI-latency or freeze prediction.\n\nUse `approvalModesObserved`, `reviewerControlCapability`, and\n`reviewerCompatibility` as a capability probe. `supported` means only that the\nruntime explicitly reported configurability; it does not prove a compatible\nlightweight reviewer is advertised. `unsupported` or `unavailable` must remain\ndiagnostic-only.\n\n`rolloutSelectedMiB`, growth, projection, lineage, replay, and compaction fields\ndescribe only the bounded selected files. Growth and 24-hour projection use\nfile-lifetime metadata and are estimates, as declared by\n`rolloutGrowthObservation`. Exact cross-file duplicates are a replay signal, not\nproof of billed-token duplication. `tokenInheritedSnapshots` and\n`tokenLineageDeltaFiles` show exact ancestor deltas that were removed;\nnon-exact history is not inferred. `tokenUsageScope` means the token total is not\na usage invoice and must not be presented as one.\n`tokenSelectedCumulativeInputM` retains the frozen cumulative heuristic input.\nUse `tokenIntervalInputM` and the other `tokenInterval*` fields for the marginal\ndifference between comparable timestamped snapshots in the selected tails.\n`rolloutProjectionComparable=false` or\n`rolloutGrowthObservation=suppressed_partial_coverage` means no 24-hour\nprojection should be quoted. `quotaRiskBasis=frozen_selected_cumulative_heuristic`\nconfirms that this engineering release did not recalibrate scoring.\n\nUse task-age, top-lineage review share, fork, effort, and spawn-origin fields as\nbounded efficiency observations. For simple work with\n`spawnContextAmplification=observed`, recommend `fork_turns=\"none\"` or the\nsmallest sufficient positive history. `nestedAgentObservation=not_observed`\nmust not be described as recursive fan-out. Surface a configured/effective\nreviewer difference as a possible mapping or policy layer, not automatically a\ndefect. Do not rewrite the primary reasoning default.\n\nInterpret the result:\n\n- `HEALTHY`: continue normally.\n- `WARNING`: recommend reducing concurrency when convenient.\n- `CRITICAL`: recommend saving active work and restarting Codex at a convenient\n checkpoint.\n\nEvery status is advisory. After reporting it, continue the user's requested\nwork unless the user independently asks to pause. Never use a Chronos status to\nrefuse, suspend, cancel, or stop a Codex task.\n\nInterpret the filesystem-helper fields separately:\n\n- `fsHelper=WARNING`: warn that the helper is degrading and recommend saving\n work before relying on more sandboxed file operations.\n- `fsHelper=CRITICAL` with `pcRestartAdvised=true`: advise a full Windows\n restart at a convenient checkpoint after work is saved. Continue the task if\n the user chooses not to restart yet.\n\nTreat `logDb=WARNING` or `logDb=CRITICAL` as a product-level diagnostic-log\nchurn condition. Explain that sequence counts demonstrate row churn, not exact\nphysical SSD writes or confirmed drive damage. Report `logDbReasons` and keep\n`logDbPerformanceImpact=not_measured` separate from `machineHealth`.\n\nInterpret `quotaRisk` separately from the overall machine-health status:\n\n- `LOW`: no current aggregate quota-amplification signal.\n- `ELEVATED`: call out the reported contributors and recommend a clean\n checkpoint soon.\n- `HIGH`: recommend the relevant `tokenAdvice` actions before extending the\n task substantially. Continue the user's requested work.\n- `UNAVAILABLE`: no recent compatible rollout aggregate was found.\n\nReport `tokenQuotaContributors` whenever quota risk is elevated or high. These\ntags identify the already-measured threshold clauses responsible for the\nclassification; they are explanatory and do not change scoring. `tokenAdvice`\nmay still be `none` when no supported remediation tag matches; use\n`tokenAdviceReason` to explain that case.\n\nApply the `tokenAdvice` tags:\n\n- `lower-effort`: use Medium for routine stages; reserve High, Extra High, Max,\n and Ultra for bounded work that benefits from them.\n- `fresh-task`: at the next clean milestone, start a focused new task instead\n of continuing to resend a large context.\n- `bound-subagents`: avoid Ultra when quota constrained. If agents are needed,\n use `fork_turns=\"none\"` or the smallest useful positive count and prefer\n Medium reasoning.\n- `avoid-repeat-compaction`: repeated compaction is itself model work; prefer a\n focused new task after preserving the required handoff.\n- `cache-write-risk`: GPT-5.6 cache writes can be more expensive than uncached\n input. Chronos can expose the volume but cannot patch Codex request fields.\n\nWhen automatic review is materially active, remove pathological review\nregeneration first, then reduce avoidable tool calls, then inspect rule quality,\nthen bound task and worker amplification. Make unavoidable reviews cheaper only\nafter those causes are addressed. Try operations expected to be sandbox-safe\nbefore escalating; request escalation only after a real boundary is identified.\n\nDo not describe a high `tokenCachedReadPct` as a leak or as equivalent spend.\nCache reads indicate reuse and are discounted, but they still contribute to\ntoken-throughput limits. Interpret `cacheWriteObservation=unsupported_schema`\nas unavailable telemetry. Only interpret `tokenCacheWriteObserved=false` as a\nmeasured zero when `cacheWriteObservation=observed`; neither proves that no\nupstream cache activity occurred.\n\nWhen the user requests durable quota tuning, recommend this conservative\nstarting point but do not edit configuration without an explicit request:\n\n```toml\ntool_output_token_limit = 4000\nmodel_auto_compact_token_limit_scope = \"body_after_prefix\"\n\n[agents]\nmax_concurrent_threads_per_session = 2\ndefault_subagent_reasoning_effort = \"medium\"\n```\n\n## Legacy actions\n\nOlder Chronos versions exposed `plan` and `cleanup` actions. They remain\naccepted for command compatibility, but they are advisory-only:\n\n```powershell\n\"<skill-root>\\scripts\\chronos.cmd\" -Action plan\n```\n\n`plan` reports only a candidate count. `cleanup`, including `cleanup -Force`,\nis disabled and always stops zero processes. Do not attempt an alternative\nprocess-termination command.\n\n## Safety\n\n- Never block, pause, or end a Codex task based on a Chronos result.\n- This Inspector skill never terminates a process. Governor can stop only the\n bounded Git subprocess it started when fingerprinting exceeds its time or\n byte limit; it does not terminate Codex or unrelated user processes.\n- Never delete logs, caches, worktrees, or user data.\n- Never create SQLite triggers, delete rows, change schemas, checkpoint, or\n vacuum Codex databases. SQLite coordination-sidecar activity remains possible\n under the documented logical read-only connection.\n- Never change Codex reviewer configuration, approval mode, trusted-command\n rules, model catalogs, or sandbox permissions.\n- Never expose usernames, local paths, prompts, responses, tool arguments,\n tool output, environment values, or unrelated process details.\n\nChronos mitigates symptoms; it cannot patch an internal Codex lifecycle defect. Restarting Codex remains the reliable recovery when app-owned helpers or handles remain elevated.\n"
}SHA-256: 864de0f4c93691fc24953227f8dcb44de40e86dc1b9d1bf723771a98121a45a8