mirror of
https://github.com/trailofbits/skills
synced 2026-06-21 14:12:00 +00:00
d5fe2e6a78
* feat(codex): add skill UI metadata * Use official Trail of Bits logo * fix: resolve code review findings for PR #175 Codex silently drops the icons as authored: its loader (codex-rs/core-skills resolve_asset_path) requires icon paths containing '..' to resolve under <plugin_root>/assets/, and the repo-root .codex/assets location fails that containment check. Verified empirically via codex app-server plugin/read: every iconSmall/iconLarge came back null; only brand_color applied. P1 fixed: - Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for all 38 plugins with skills and point every openai.yaml at ../../assets/trail-of-bits-mark.svg (the supported plugin-level shared asset pattern). Icons now resolve for marketplace installs too, since nothing escapes the plugin root. - Drop the .codex/ additions: .codex/skills/gh-cli/agents/ openai.yaml resolved nowhere (.codex/skills is not a Codex discovery root) and PR #173 removes the whole .codex/ tree P2 fixed: - Patch-bump all 38 touched plugins in plugin.json and marketplace.json so installed clients pick up the metadata Verified: - Static check replicating Codex's resolution algorithm: all 73 yaml files resolve under their plugin assets/ and exist - Live codex app-server probe: 71/72 loadable skills report resolved iconSmall/iconLarge and brand_color #D83A34 (claude-in-chrome-troubleshooting fails to load on main due to a pre-existing 64-char qualified-name limit, fixed by #173's rename; zeroize-audit's manifest mcpServers object is likewise a pre-existing Codex incompatibility fixed by #173) - validate_codex_skills.py, validate_plugin_metadata.py, prek all pass Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(codex): use skill-local icon assets --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
gh-cli
A Claude Code plugin that intercepts GitHub URL fetches and redirects Claude to use the authenticated gh CLI instead.
Problem
Claude Code's WebFetch tool and Bash curl/wget commands don't use the user's GitHub authentication. This means:
- Private repos: Fetches fail with 404 errors
- Rate limits: Unauthenticated requests are limited to 60/hour (vs 5,000/hour authenticated)
- Missing data: Some API responses are incomplete without authentication
Solution
This plugin provides:
- PreToolUse hooks that intercept GitHub URL access via
WebFetchorcurl/wget, and suggest the correctghCLI command - A
ghPATH shim that blocks anti-patterns: API/contents/fetching and non-session-scoped temp directory clones - A SessionEnd hook that automatically cleans up cloned repositories when the session ends
What Gets Intercepted
| Tool | Pattern | Suggestion |
|---|---|---|
WebFetch |
github.com/{owner}/{repo} |
gh repo view owner/repo |
WebFetch |
github.com/.../blob/... |
gh repo clone + Read |
WebFetch |
github.com/.../tree/... |
gh repo clone + Read/Glob/Grep |
WebFetch |
api.github.com/repos/.../pulls |
gh pr list / gh pr view |
WebFetch |
api.github.com/repos/.../issues |
gh issue list / gh issue view |
WebFetch |
api.github.com/... |
gh api <endpoint> |
WebFetch |
raw.githubusercontent.com/... |
gh repo clone + Read |
Bash |
curl https://api.github.com/... |
gh api <endpoint> |
Bash |
curl https://raw.githubusercontent.com/... |
gh repo clone + Read |
Bash |
wget https://github.com/... |
gh release download |
Bash (shim) |
gh api repos/.../contents/... |
gh repo clone + Read |
Bash (shim) |
gh repo clone ... /tmp/... (non-session-scoped) |
Session-scoped clone path |
What Passes Through
- Non-GitHub URLs (any domain that isn't
github.com,api.github.com,raw.githubusercontent.com, orgist.github.com) - GitHub Pages sites (
*.github.io) - Commands already using
gh(except anti-patterns blocked by the shim; see table above) - Git commands (
git clone,git push, etc.) - Search commands that mention GitHub URLs (
grep,rg, etc.)
Note: When hooks deny blob/tree/raw URLs, the denial message explicitly warns against using gh api to fetch and base64-decode file contents as a fallback — clone the repo instead.
Automatic Cleanup
Cloned repositories are stored in session-scoped temp directories ($TMPDIR/gh-clones-<session-id>/). A SessionEnd hook automatically removes them when the session ends, so there's no manual cleanup needed and concurrent sessions don't interfere with each other.
Prerequisites
- GitHub CLI (
gh) must be installed and authenticated (gh auth login) - If
ghis not installed, the hooks pass through without disruption
Installation
/plugin marketplace add trailofbits/skills
/plugin install gh-cli