warden

Agents

Claude Code and Codex hooks that lease devices per session.

warden install wires hooks into every agent it detects: Claude Code (~/.claude or claude on PATH) and Codex ($CODEX_HOME / ~/.codex or codex on PATH). --claude / --codex force one (or both) regardless of detection.

Rules for agents

  • Claim before use. warden claim ios --json (or android), then use the returned udid / serial for every argent / simctl / adb call. Never pick a device from list-devices or simctl list on your own.
  • Never touch a booted device you did not claim — it belongs to another session.
  • If the hook blocks an argent call, run warden claim and switch to the returned device.
  • Release when done: warden release --mine (add --shutdown to stop sims warden created).

Claude Code

warden install --claude adds:

Codex

warden install --codex merges the same two hooks into $CODEX_HOME/hooks.json (default ~/.codex/hooks.json). Hooks already declared in config.toml [[hooks.*]] tables count as installed. Codex hooks use Claude's format and stdin JSON, and a PreToolUse exit 2 + stderr blocks the call, so warden hook pretool|session-end serves both agents unchanged:

~/.codex/hooks.json
{
  "hooks": {
    "PreToolUse": [{ "matcher": "mcp__argent__.*|mcp__plugin_goldie_argent__.*",
                     "hooks": [{ "type": "command", "command": "$HOME/.local/bin/warden hook pretool", "timeout": 30 }] }],
    "SessionEnd": [{ "hooks": [{ "type": "command", "command": "$HOME/.local/bin/warden hook session-end", "timeout": 3 }] }]
  }
}

Codex skips new or changed hooks until you trust them: run /hooks in Codex once after installing.

  • Codex caps SessionEnd hooks at 3 s and always sends reason other, so the /clear exception never applies. Anything SessionEnd can't finish in time is picked up by warden gc once the leases go stale.
  • For the skill in Codex, use warden skill install.

On this page