* feat(codex): add skill UI metadata
* Use official Trail of Bits logo
* fix: resolve code review findings for PR #175
Codex silently drops the icons as authored: its loader
(codex-rs/core-skills resolve_asset_path) requires icon paths
containing '..' to resolve under <plugin_root>/assets/, and the
repo-root .codex/assets location fails that containment check.
Verified empirically via codex app-server plugin/read: every
iconSmall/iconLarge came back null; only brand_color applied.
P1 fixed:
- Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for
all 38 plugins with skills and point every openai.yaml at
../../assets/trail-of-bits-mark.svg (the supported plugin-level
shared asset pattern). Icons now resolve for marketplace
installs too, since nothing escapes the plugin root.
- Drop the .codex/ additions: .codex/skills/gh-cli/agents/
openai.yaml resolved nowhere (.codex/skills is not a Codex
discovery root) and PR #173 removes the whole .codex/ tree
P2 fixed:
- Patch-bump all 38 touched plugins in plugin.json and
marketplace.json so installed clients pick up the metadata
Verified:
- Static check replicating Codex's resolution algorithm: all 73
yaml files resolve under their plugin assets/ and exist
- Live codex app-server probe: 71/72 loadable skills report
resolved iconSmall/iconLarge and brand_color #D83A34
(claude-in-chrome-troubleshooting fails to load on main due to
a pre-existing 64-char qualified-name limit, fixed by #173's
rename; zeroize-audit's manifest mcpServers object is likewise
a pre-existing Codex incompatibility fixed by #173)
- validate_codex_skills.py, validate_plugin_metadata.py, prek all
pass
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(codex): use skill-local icon assets
---------
Co-authored-by: Dan Guido <dan@trailofbits.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Remove legacy codex compatiblity scripts/shims.
Codex supports claude plugins so this shouldn't be necessary.
Add a script to test the plugin loadablility in both claude and codex
* fix: resolve code review findings for PR #173
Review findings addressed (4 reviewers: pr-review-toolkit agents,
Codex gpt-5.3-codex, direct diff review):
P2 fixed:
- Bump versions for the 5 substantively changed plugins in both
plugin.json and marketplace.json (gh-cli 1.5.0 new skill,
claude-in-chrome-troubleshooting 1.1.0 skill rename,
modern-python 1.5.1 / skill-improver 1.0.3 hooks change,
zeroize-audit 0.1.1 MCP config relocation) so clients pick up
the changes
- README Codex install: replace unpasteable /plugins slash-command
block with verified CLI syntax (codex plugin marketplace add)
- check_claude_loadability: parse_json_output now fails fast with
command context on empty CLI output instead of returning None
- check_codex_loadability: surface skipped RPC error messages in
timeout failures instead of a bare TimeoutError
P3 fixed:
- Both checkers: error out when marketplace.json lists no plugins
instead of passing vacuously
Dismissed:
- @latest CLI installs in validate.yml: deliberate; the check
validates against the clients users actually run
- select.select portability: CI-only script on ubuntu-latest
- Divergent mcpServers validation between checkers: intentional;
the Codex checker enforces the repo's .mcp.json convention
Verified: ruff, prek, validate_plugin_metadata.py, and both
loadability checks pass end-to-end (39 plugins, 74 skills, 2 MCP
servers load in Claude Code and Codex)
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Dan Guido <dan@trailofbits.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Add claude-in-chrome-troubleshooting plugin
Diagnose and fix Claude in Chrome MCP extension connectivity issues,
particularly the native host conflict between Claude.app (Cowork) and
Claude Code CLI.
Also creates marketplace.json with all existing plugins.
Original skill by @jeffzwang from @ExaAILabs.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Remove personal email from plugin.json
CI requires opensource@trailofbits.com or no email.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>