Forward PROSE_CODEX_ADD_DIR and PROSE_CODEX_NETWORK into Codex SDK thread options so workspace-write runs can grant narrow extra filesystem and network capabilities without danger-full-access.
Also refresh vulnerable transitive production dependencies in the CLI lockfile so the release audit remains green.
The CLI now ships first-party agent SDKs only. The `codex` harness —
a thin shim around `codex exec` — has been removed. Supported
harnesses: `codex-sdk`, `claude-sdk`, `mock`.
BREAKING CHANGE: `--harness codex` (and `PROSE_HARNESS=codex`) no
longer works. Switch to `--harness codex-sdk` for first-party,
in-process Codex SDK execution. `codex-sdk` remains the default,
so most users are unaffected.
- Delete `codex-cli.ts` and `process-harness.ts`; keep
`process-runner.ts` for the OpenProse skill installer
- Trim `codex-options.ts` to SDK-shaped helpers
- Drop `codex` from the smoke script and CI matrix
- Align README, post-release playtest, and package metadata
Moves `@openprose/prose-cli` from `cli/` to `tools/cli/` and seeds a
`tools/` convention at the repo root for shippable tooling published as
standalone artifacts. Package internals are unchanged — only paths
outside the package that hard-code the `cli/` segment were updated.
## What changed
- `git mv cli tools/cli` — package files render as 100%-similarity
renames, so `git log --follow` is preserved.
- `.github/workflows/cli-publish.yml`,
`.github/workflows/cli-release-check.yml`, and
`.github/workflows/cli-real-harness-smoke.yml`: every literal `cli/`
path (`paths:`, `working-directory:`, `cache-dependency-path:`,
artifact `path:`, and inline `node`/`bash` invocations) now points
at `tools/cli/`. `cli-skills-smoke.yml` had no `cli/` references and
is untouched.
- `tools/cli/package.json`: `repository.directory` and `homepage` flip
to `tools/cli` so the npm registry "Repository" link resolves.
- `README.md`: the badge nav, the prose-layout paragraph, and the repo
layout table now point at `tools/cli/`, plus a new `tools/` row
introducing the convention.
- `RELEASE.md`: cross-references to `cli/RELEASE.md` updated.
- `tools/cli/README.md`, `tools/cli/RELEASE.md`,
`tools/cli/POST_RELEASE_PLAYTEST.md`: public installer URL updated to
`https://raw.githubusercontent.com/openprose/prose/main/tools/cli/install.sh`.