AI Global Academy Join the waitlist

Courses / Bonus: the course with Codex or Qwen Code

Lesson 9.3 · 75 minFollowing sections 2–8 with Codex

Duration~75 min in the lesson + ~25 min homework
PrerequisitesLesson 9.2; the checkpoint required by the course lesson chosen for the practice (lesson-1.6 for lesson 2.1).
Checkpointnone (the Do along ends with the chosen lesson's own commit)

What you will have

The student has completed one real course lesson with Codex, holds a lesson-by-lesson guide to every place where sections 2–8 rely on a Claude Code feature, and has started docs/codex-notes.md, a log of the differences they meet.

Video

The video for this lesson is not recorded yet.

Prompts used in this lesson

Part 3 — Three lessons that need more than a swap

Prompt to Claude
Also keep the pointer lines at the top of our existing AGENTS.md and put the
generated AGENTS.md content below them. After the move, show me the first ten
lines of AGENTS.md.
Prompt to Claude
Purpose: before I push, I want a security review of everything that differs
from origin/main, committed or not.

Review only for security: tables or policies that are open to anonymous
requests, secrets that could reach the browser, logs or Git, admin pages or
endpoints that skip the auth check, unvalidated input, and anything that lets
one visitor read another person's data.

Done looks like: a list of findings, each with the file, the risk in plain
words, how someone could use it, and a suggested fix. If you find nothing,
say what you checked. Do not change any file.

Do along

Do these steps on your own project. Most of the time goes to the course lesson you run in step 6.

  1. Pause after Part 1. Create docs/codex-notes.md with the three columns from Part 1.
  2. After Part 5, choose the lesson. If you work in order, it is lesson 2.1 (start from lesson-1.6). Otherwise take the next lesson on your path.
  3. Find the lesson's row in the guide and note what you will do differently.
  4. If you fetched a checkpoint from the reference repository, open AGENTS.md and make sure the pointer lines from lesson 9.1 are at the top.
  5. Start codex in the project. Check /status: Read Only, the right folder.
  6. Follow the lesson from start to finish. Send its prompts as written. Translate on-screen steps with the tables.
  7. Run every step of the lesson's "Check your work".
  8. Write one line in docs/codex-notes.md for each difference: an on-screen step you translated, a file in a different place, a result that did not match.
  9. End with the lesson's own commit. Include docs/codex-notes.md in it.

Check your work

  1. Run the chosen lesson's "Check your work" list. Expected: every step gives the expected result, with work done by Codex.
  2. Open docs/codex-notes.md. Expected: at least one line, or the sentence "no differences in lesson X.Y".
  3. Start a new Codex session and ask which instruction files it read. Expected: AGENTS.md and CLAUDE.md.
  4. Run git log --oneline -1. Expected: the lesson's commit message.
  5. Point to the row of the guide for lesson 4.7 and say what replaces /security-review. Expected: /review with security instructions, then the lesson's audit prompt.

Common problems

  • A later prompt names a file that does not exist in your project. → Codex organised the code differently from the recording. → Ask: "The course expects lib/submit-lead.ts. Where is that code here? Do not change anything." Then either use your path in the prompt or ask Codex to move the code, and note it.
  • Codex stopped following the project rules after lesson 3.2 or after a checkout. → AGENTS.md was replaced and the pointer lines are gone. → Put them back at the top of AGENTS.md and start a new session.
  • A command fails with "Operation not permitted" or cannot reach the network. → It ran inside the sandbox. → Approve when Codex asks to run it with permission, or run it yourself.
  • Codex cannot open your local site in the browser. → The development server is not running. → Start npm run dev in your own terminal and give Codex the address.
  • The result differs from the video. → Run the lesson's checks; they decide, not the video. If one fails, use the cause-first brief from lesson 1.5.

Homework

About 25 minutes, after the lesson, on your own. Nothing later in the course depends on it. The homework of the course lesson you ran is separate; do it with Codex too.

  1. Mark your road ahead. Go through the guide and pick out every row for a lesson you have not done yet. In docs/codex-notes.md, add a section "Lessons ahead" with one line per row: the lesson and what you will do in Codex. Deliverable: that section. Done when: it has a line for each of 3.2, 4.7 and 8.3 that is still ahead of you, in your own words.
  2. Your approval rules. List the approval prompts Codex showed during the lesson you ran, and next to each the reason from Part 4: internet, a local port, or the Git folder. Then write, under "My approval rules" in the same file, which commands you will approve after reading and which you will run yourself. Deliverable: three to five lines. Done when: every prompt you saw falls under one of your rules.
  3. Sort the differences. Read your lines in docs/codex-notes.md and mark each "once" or "will come back". For each that will come back, write the sentence you will add to a prompt next time, such as "read docs/brief.md first". If you met no differences, do this after your next lesson. Deliverable: the marked list. Done when: every line has a mark and every "will come back" line has its sentence.

Commit docs/codex-notes.md and push, without a tag.