mirror of
https://github.com/trailofbits/skills
synced 2026-06-21 14:12:00 +00:00
d5fe2e6a78
* feat(codex): add skill UI metadata * Use official Trail of Bits logo * fix: resolve code review findings for PR #175 Codex silently drops the icons as authored: its loader (codex-rs/core-skills resolve_asset_path) requires icon paths containing '..' to resolve under <plugin_root>/assets/, and the repo-root .codex/assets location fails that containment check. Verified empirically via codex app-server plugin/read: every iconSmall/iconLarge came back null; only brand_color applied. P1 fixed: - Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for all 38 plugins with skills and point every openai.yaml at ../../assets/trail-of-bits-mark.svg (the supported plugin-level shared asset pattern). Icons now resolve for marketplace installs too, since nothing escapes the plugin root. - Drop the .codex/ additions: .codex/skills/gh-cli/agents/ openai.yaml resolved nowhere (.codex/skills is not a Codex discovery root) and PR #173 removes the whole .codex/ tree P2 fixed: - Patch-bump all 38 touched plugins in plugin.json and marketplace.json so installed clients pick up the metadata Verified: - Static check replicating Codex's resolution algorithm: all 73 yaml files resolve under their plugin assets/ and exist - Live codex app-server probe: 71/72 loadable skills report resolved iconSmall/iconLarge and brand_color #D83A34 (claude-in-chrome-troubleshooting fails to load on main due to a pre-existing 64-char qualified-name limit, fixed by #173's rename; zeroize-audit's manifest mcpServers object is likewise a pre-existing Codex incompatibility fixed by #173) - validate_codex_skills.py, validate_plugin_metadata.py, prek all pass Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(codex): use skill-local icon assets --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
git-cleanup
A Claude Code skill for safely cleaning up accumulated git worktrees and local branches.
What It Does
Analyzes your local git repository and categorizes branches/worktrees into:
- Safe to delete: Branches fully merged into the default branch
- Needs review: Branches with deleted remotes (
[gone]) that may have local-only work - Theme-related: Groups of branches working on similar functionality
- Keep: Active work with unpushed commits or untracked local branches
The skill uses a gated workflow requiring explicit user confirmation before any deletions.
When to Use
Invoke with /git-cleanup when you have accumulated many local branches and worktrees that need cleanup.
Important: This skill only runs when explicitly invoked. It will never suggest cleanup proactively or run automatically.
Safety Features
- Two confirmation gates (analysis review, then deletion confirmation)
- Uses safe delete (
git branch -d) for merged branches; force delete (git branch -D) only for squash-merged branches where git cannot detect the merge - Blocks removal of worktrees with uncommitted changes
- Never touches protected branches (main, master, develop, release/*)
- Flags
[gone]branches for review instead of auto-deleting
Installation
claude plugins:add trailofbits/skills/git-cleanup
Example
User: /git-cleanup
Claude: [Analyzes branches and worktrees]
[Presents categorized tables]
"I found 5 branches safe to delete, 2 needing review.
Which would you like to clean up?"
User: "Delete the merged branches"
Claude: "I will delete these branches:
- feature/auth
- bugfix/login
Confirm? (yes/no)"
User: "yes"
Claude: [Executes and reports results]