Files
Lixin2026 d5fe2e6a78 feat(codex): add UI metadata for skills (#175)
* feat(codex): add skill UI metadata

* Use official Trail of Bits logo

* fix: resolve code review findings for PR #175

Codex silently drops the icons as authored: its loader
(codex-rs/core-skills resolve_asset_path) requires icon paths
containing '..' to resolve under <plugin_root>/assets/, and the
repo-root .codex/assets location fails that containment check.
Verified empirically via codex app-server plugin/read: every
iconSmall/iconLarge came back null; only brand_color applied.

P1 fixed:
- Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for
  all 38 plugins with skills and point every openai.yaml at
  ../../assets/trail-of-bits-mark.svg (the supported plugin-level
  shared asset pattern). Icons now resolve for marketplace
  installs too, since nothing escapes the plugin root.
- Drop the .codex/ additions: .codex/skills/gh-cli/agents/
  openai.yaml resolved nowhere (.codex/skills is not a Codex
  discovery root) and PR #173 removes the whole .codex/ tree

P2 fixed:
- Patch-bump all 38 touched plugins in plugin.json and
  marketplace.json so installed clients pick up the metadata

Verified:
- Static check replicating Codex's resolution algorithm: all 73
  yaml files resolve under their plugin assets/ and exist
- Live codex app-server probe: 71/72 loadable skills report
  resolved iconSmall/iconLarge and brand_color #D83A34
  (claude-in-chrome-troubleshooting fails to load on main due to
  a pre-existing 64-char qualified-name limit, fixed by #173's
  rename; zeroize-audit's manifest mcpServers object is likewise
  a pre-existing Codex incompatibility fixed by #173)
- validate_codex_skills.py, validate_plugin_metadata.py, prek all
  pass

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(codex): use skill-local icon assets

---------

Co-authored-by: Dan Guido <dan@trailofbits.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 12:28:41 -04:00
..
2026-02-11 19:59:33 -05:00

git-cleanup

A Claude Code skill for safely cleaning up accumulated git worktrees and local branches.

What It Does

Analyzes your local git repository and categorizes branches/worktrees into:

  • Safe to delete: Branches fully merged into the default branch
  • Needs review: Branches with deleted remotes ([gone]) that may have local-only work
  • Theme-related: Groups of branches working on similar functionality
  • Keep: Active work with unpushed commits or untracked local branches

The skill uses a gated workflow requiring explicit user confirmation before any deletions.

When to Use

Invoke with /git-cleanup when you have accumulated many local branches and worktrees that need cleanup.

Important: This skill only runs when explicitly invoked. It will never suggest cleanup proactively or run automatically.

Safety Features

  • Two confirmation gates (analysis review, then deletion confirmation)
  • Uses safe delete (git branch -d) for merged branches; force delete (git branch -D) only for squash-merged branches where git cannot detect the merge
  • Blocks removal of worktrees with uncommitted changes
  • Never touches protected branches (main, master, develop, release/*)
  • Flags [gone] branches for review instead of auto-deleting

Installation

claude plugins:add trailofbits/skills/git-cleanup

Example

User: /git-cleanup

Claude: [Analyzes branches and worktrees]
        [Presents categorized tables]
        "I found 5 branches safe to delete, 2 needing review.
         Which would you like to clean up?"

User: "Delete the merged branches"

Claude: "I will delete these branches:
         - feature/auth
         - bugfix/login
         Confirm? (yes/no)"

User: "yes"

Claude: [Executes and reports results]