A working, agentic Codex environment for safe, AI-assisted data analysis. It takes a data question from raw file to a verified, sourced, management-ready HTML presentation — cleaning data, comparing figures, visualizing them, and writing an executive summary, all under a Safe-Zone discipline with independent verification and human-in-the-loop checkpoints.
It is a teaching environment, built on the agentic-context-engineering method
(the four mechanisms — AGENTS.md, standards, skills, subagents — plus stable IDs,
registries, business-logic templates, and a two-round QA system).
Compare the Central Bank of Armenia (CBA) refinancing rate to peer central banks:
- Bring the local CBA rate file into the Safe Zone and clean it.
- Fetch peer policy rates (Fed, ECB, BoE, …) from the open web — each cited.
- Combine and analyze — spread, direction, volatility.
- Visualize as charts a manager reads in ten seconds.
- Assemble and verify a self-contained HTML presentation.
-
Open Codex with this folder as the working directory, and trust it when prompted. The kit is self-contained:
AGENTS.mdis the root switchboard,.agents/skills/holds the skills,.codex/holds the subagents and the project config,standards/holds the six standards, and the content folders hold the data and outputs.Trust matters: Codex loads project-scoped
.codex/layers — the subagents, the sandbox setting and the Safe-Zone hook — only for a trusted project. Untrusted, the skills andAGENTS.mdstill work; the subagents and the hook do not. -
Python 3 is used for data work. No install is needed for CSVs (standard library). If you point the kit at an Excel file (
.xlsx), it will create a disposable.venvand installpandas/openpyxlautomatically — then throw it away. If that install can't run, it falls back to CSV and tells you. -
Web access is on, and it had to be turned on.
sandbox_mode = "workspace-write"disables the network by default, so.codex/config.tomlsetsnetwork_access = trueunder[sandbox_workspace_write]. Without it$fetch-peer-ratesand$web-researchcannot run at all, and the.xlsxpath cannotpip install.That makes egress a sandbox-level permission, and the Safe-Zone classification the only thing standing in front of it. A
PreToolUsehook prints a reminder before each web call — itsmatcheris a regex over the tool name, so confirm the web tool's name in your Codex build and narrow the pattern before you rely on it. The hook only prints; it cannot block.
The whole flagship, end to end:
$workflow "Compare the CBA refinancing rate to peer central banks for a board briefing"
…or step by step (each step is a skill; each producing step is checked by a QA skill before it's accepted):
$intake data/cba-refinance-rate.csv # classify (Safe Zone) + register → source-qa
$clean-data DS-001 # fix missing/dupes/outliers/dates → clean-qa
$fetch-peer-rates # peer rates from the web, cited → source-qa
$analyze "CBA vs peers" # spread / direction / volatility → analysis-qa
$visualize FND-001 # self-contained SVG charts → presentation-qa
$presentation FND-001 # self-contained HTML presentation → presentation-qa
$qa-check presentations/RPT-001-*.html # independent re-check on demand
Separately, when a question needs fresh information from the open web rather than a number for the pipeline:
$web-research "How have peer central banks guided on 2026 rate cuts?"
# sourced brief WRB-NNN → web-research-qa
- Classify before you use or send. Every dataset is public / internal /
restricted. Restricted data never reaches a web tool or an external prompt.
The shipped
data/internal/loan-portfolio-CONFIDENTIAL.csvis a restricted example to practice this. →standards/safe-zone.md - No unsourced figures. Every number traces to a dataset cell, a logged
computation, or an official source in
sources/source-registry.md. "Not found" is an acceptable answer; a plausible guess is not. →standards/evidence-and-figures.md - Compute with throwaway scripts, verify independently. Analysis runs as a
disposable Python script (deleted after), then a separate verification
script recomputes and checks it (also deleted). Only the data, charts, HTML,
and a markdown record of the method + verdict survive. →
standards/ephemeral-compute.md
| Path | What it is |
|---|---|
AGENTS.md |
Root switchboard — read the map here |
context/analysis-brief.md |
The anchor — the decision, vocabulary, Safe-Zone posture |
standards/ |
The six standards, as plain documents. Named by AGENTS.md, the folder notes, and each skill |
.agents/skills/ |
Codex skills — producing skills + their QA skills. Invoke with $name |
.codex/agents/ |
data-steward, analyst, presenter, web-research — one TOML each |
.codex/config.toml |
Sandbox, approval policy, and the Safe-Zone egress hook |
data/ |
Datasets + registry (shipped: a dirty CBA rate file + a peer-rates template + a restricted example) |
web-research/ |
Open-web sources (WRS-NNN) + research briefs (WRB-NNN) + two registries + brief template |
analysis/ |
Cleaning logs, combined data, findings + registry + finding template |
presentations/ |
Charts + HTML presentations + registry + HTML template |
sources/ |
Source registry (SRC-NNN) + evidence policy |
scratch/ |
The only place throwaway scripts live — empty at rest |
TRAINER-GUIDE.md |
Maps the 8-meeting course onto the skills/exercises |
data/cba-refinance-rate.csv(and.xlsx) — a monthly CBA refinancing-rate series that is deliberately dirty: two missing values, one duplicate row, one out-of-range outlier (95.0where9.5was meant), mixed date formats, and a stray percent sign. It is illustrative only (source tier P4) — refresh from the official CBA before publishing any figure.data/peer-rates.template.csv— the empty schemafetch-peer-ratesfills with real, web-sourced peer rates. No fabricated numbers are shipped.data/internal/loan-portfolio-CONFIDENTIAL.csv— a small, obviously-fictional restricted file for the classification exercise. It must never go to a web tool.
The kit ships empty of results (no findings, charts, or presentations yet) so
each cohort produces its own. Every artifact you generate is registered with a
stable ID in the relevant _index.md, verified, and QA'd before it's accepted.
Presentations are self-contained HTML — open them in any browser offline, or
open one in a browser for review.