* feat(codex): add skill UI metadata
* Use official Trail of Bits logo
* fix: resolve code review findings for PR #175
Codex silently drops the icons as authored: its loader
(codex-rs/core-skills resolve_asset_path) requires icon paths
containing '..' to resolve under <plugin_root>/assets/, and the
repo-root .codex/assets location fails that containment check.
Verified empirically via codex app-server plugin/read: every
iconSmall/iconLarge came back null; only brand_color applied.
P1 fixed:
- Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for
all 38 plugins with skills and point every openai.yaml at
../../assets/trail-of-bits-mark.svg (the supported plugin-level
shared asset pattern). Icons now resolve for marketplace
installs too, since nothing escapes the plugin root.
- Drop the .codex/ additions: .codex/skills/gh-cli/agents/
openai.yaml resolved nowhere (.codex/skills is not a Codex
discovery root) and PR #173 removes the whole .codex/ tree
P2 fixed:
- Patch-bump all 38 touched plugins in plugin.json and
marketplace.json so installed clients pick up the metadata
Verified:
- Static check replicating Codex's resolution algorithm: all 73
yaml files resolve under their plugin assets/ and exist
- Live codex app-server probe: 71/72 loadable skills report
resolved iconSmall/iconLarge and brand_color #D83A34
(claude-in-chrome-troubleshooting fails to load on main due to
a pre-existing 64-char qualified-name limit, fixed by #173's
rename; zeroize-audit's manifest mcpServers object is likewise
a pre-existing Codex incompatibility fixed by #173)
- validate_codex_skills.py, validate_plugin_metadata.py, prek all
pass
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(codex): use skill-local icon assets
---------
Co-authored-by: Dan Guido <dan@trailofbits.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Pre-commit hooks auto-fixed missing newlines at EOF and trailing
whitespace to satisfy end-of-file-fixer and trailing-whitespace checks.
Co-authored-by: Dallas McIntyre <dkmcintyre@safaricircuits.com>
Co-authored-by: Claude Code <noreply@anthropic.com>
* better ci validations, fix marketplace error
* fix lints
* fix lint script
* fix lint script2
* fix ruff errors
* fix abs path regex
* fix shellcheck lint
* fix: resolve code review findings for PR #85
- Remove dead CHANGED_FILES code path (unreachable in CI)
- Add version and description consistency checks between plugin.json
and marketplace.json
- Eliminate duplicate plugin.json reads via parse_plugin_json()
- Fix bats test discovery for filenames with spaces (print0/xargs -0)
- Sync marketplace.json with plugin.json for 5 pre-existing mismatches
(second-opinion version, ask-questions/burpsuite/fix-review/insecure-defaults descriptions)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: gh-cli bats tests fail when gh is in /usr/bin
The _no_gh test helpers used PATH=/usr/bin:/bin to exclude gh, but
on Ubuntu CI runners gh is installed at /usr/bin/gh. Fix by creating
a temp directory with symlinks to only jq and bash.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: improve plugin descriptions for better skill triggering
- ask-questions-if-underspecified: restore trigger context ("asking
questions") while keeping invocation constraint
- burpsuite-project-parser: drop filler "directly from the command
line", use outcome-oriented "for security analysis"
- insecure-defaults: restore specific scenarios (hardcoded credentials,
fallback secrets, weak auth defaults) for better matching
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Dan Guido <dan@trailofbits.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* update version numbers of any plugins with updates and a note about doing this for future claudes
* update more plugins versions and sync with marketplace
* claude.md update