* feat(codex): add skill UI metadata
* Use official Trail of Bits logo
* fix: resolve code review findings for PR #175
Codex silently drops the icons as authored: its loader
(codex-rs/core-skills resolve_asset_path) requires icon paths
containing '..' to resolve under <plugin_root>/assets/, and the
repo-root .codex/assets location fails that containment check.
Verified empirically via codex app-server plugin/read: every
iconSmall/iconLarge came back null; only brand_color applied.
P1 fixed:
- Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for
all 38 plugins with skills and point every openai.yaml at
../../assets/trail-of-bits-mark.svg (the supported plugin-level
shared asset pattern). Icons now resolve for marketplace
installs too, since nothing escapes the plugin root.
- Drop the .codex/ additions: .codex/skills/gh-cli/agents/
openai.yaml resolved nowhere (.codex/skills is not a Codex
discovery root) and PR #173 removes the whole .codex/ tree
P2 fixed:
- Patch-bump all 38 touched plugins in plugin.json and
marketplace.json so installed clients pick up the metadata
Verified:
- Static check replicating Codex's resolution algorithm: all 73
yaml files resolve under their plugin assets/ and exist
- Live codex app-server probe: 71/72 loadable skills report
resolved iconSmall/iconLarge and brand_color #D83A34
(claude-in-chrome-troubleshooting fails to load on main due to
a pre-existing 64-char qualified-name limit, fixed by #173's
rename; zeroize-audit's manifest mcpServers object is likewise
a pre-existing Codex incompatibility fixed by #173)
- validate_codex_skills.py, validate_plugin_metadata.py, prek all
pass
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* fix(codex): use skill-local icon assets
---------
Co-authored-by: Dan Guido <dan@trailofbits.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
* Fix `allowed-tools` to use spec-compliant space-delimited strings
Per the agentskills.io specification, `allowed-tools` must be a single
string of space-delimited patterns, not a YAML list. Converted all 23
SKILL.md files from the `- Item` list format to the correct
`"Item1 Item2"` string format. Also updated the frontmatter examples in
CLAUDE.md and the workflow-skill-design skill template to match.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Fix remaining allowed-tools format in firebase-apk-scanner and workflow-skill-design docs
- Convert firebase-apk-scanner from comma-separated to space-delimited
- Update anti-patterns.md and tool-assignment-guide.md examples from YAML lists to space-delimited strings
- Remove unnecessary quotes from SKILL.md template placeholder
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* Cover commands, new SKILL.md files, and fix template placeholder
Extends the previous spec-compliance fixes:
* Convert command frontmatter (commands/*.md) — per Claude Code
docs, command files use the same frontmatter as skills, so the
same space-delimited rule applies.
* Convert three SKILL.md files added since the original PR:
mutation-testing, trailmark-structural, trailmark-summary.
* Fix the placeholder in the workflow-skill-design template.
The previous "[minimum tools needed, space-delimited]" was YAML
flow-sequence syntax, which parses as a list — the opposite of
what the placeholder claims. Replaced with a concrete-looking
space-delimited example plus a comment.
Zeroize-audit agent files still use `allowed-tools:` in YAML list
form. They are intentionally excluded: per the project's own docs
(workflow-skill-design references), agents declare tools with
`tools:` (not `allowed-tools:`). Fixing those requires changing
the field name as well as the format and is out of scope for this
PR.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* zeroize-audit agents: switch allowed-tools to tools
Subagents declare their tool allowlist via `tools:` (comma-separated),
not `allowed-tools:` — see Claude Code's subagent docs and this
repo's own designing-workflow-skills/SKILL.md:47:
> Skills use `allowed-tools:` in frontmatter. Agents use `tools:`
> in frontmatter.
Before this change, the zeroize-audit agents declared their tool list
under `allowed-tools:`, which Claude Code does not read for subagents.
The field was effectively a no-op; the spawned agents had no tool
restriction enforced.
Renames the field on all 11 agents to `tools:` and reformats the YAML
list as comma-separated to match the documented format and existing
agents elsewhere in the repo (e.g. function-analyzer.md,
spec-compliance-checker.md). Tool sets are unchanged.
Behavior change: tools now actually constrain what each spawned agent
can call. The lists are the ones the original author intended.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* skill-improver: convert command allowed-tools to space-delimited
The two command files in plugins/skill-improver/commands/ still used
the JSON flow-array format (`allowed-tools: ["..."]`), which the rest
of this PR converted everywhere else. Convert them to the spec-compliant
space-delimited string form for consistency.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Dan Guido <dan@trailofbits.com>
* Add spec-compliance-checker agent to spec-to-code-compliance plugin
Introduces a formal agent definition for the full specification-to-code
compliance workflow. Updates SKILL.md to reference agent and bumps
version to 1.1.0.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix {baseDir} paths and bump marketplace.json version
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: resolve code review findings for PR #82
- Normalize double hyphens to em dashes in agent rationalizations table
for consistency with SKILL.md formatting conventions
- Add invocation example to SKILL.md Agent section
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Rename 10 command files that contained `:` in their filenames, which is
invalid on Windows filesystems (reserved for drive letters).
The `trailofbits:` namespace is preserved in the frontmatter `name` field,
so slash commands like `/trailofbits:audit-context` continue to work.
Fixes#51
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>