mirror of
https://github.com/trailofbits/skills
synced 2026-06-21 14:12:00 +00:00
d5fe2e6a78
* feat(codex): add skill UI metadata * Use official Trail of Bits logo * fix: resolve code review findings for PR #175 Codex silently drops the icons as authored: its loader (codex-rs/core-skills resolve_asset_path) requires icon paths containing '..' to resolve under <plugin_root>/assets/, and the repo-root .codex/assets location fails that containment check. Verified empirically via codex app-server plugin/read: every iconSmall/iconLarge came back null; only brand_color applied. P1 fixed: - Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for all 38 plugins with skills and point every openai.yaml at ../../assets/trail-of-bits-mark.svg (the supported plugin-level shared asset pattern). Icons now resolve for marketplace installs too, since nothing escapes the plugin root. - Drop the .codex/ additions: .codex/skills/gh-cli/agents/ openai.yaml resolved nowhere (.codex/skills is not a Codex discovery root) and PR #173 removes the whole .codex/ tree P2 fixed: - Patch-bump all 38 touched plugins in plugin.json and marketplace.json so installed clients pick up the metadata Verified: - Static check replicating Codex's resolution algorithm: all 73 yaml files resolve under their plugin assets/ and exist - Live codex app-server probe: 71/72 loadable skills report resolved iconSmall/iconLarge and brand_color #D83A34 (claude-in-chrome-troubleshooting fails to load on main due to a pre-existing 64-char qualified-name limit, fixed by #173's rename; zeroize-audit's manifest mcpServers object is likewise a pre-existing Codex incompatibility fixed by #173) - validate_codex_skills.py, validate_plugin_metadata.py, prek all pass Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(codex): use skill-local icon assets --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Workflow Skill Design
A Claude Code plugin that teaches design patterns for building workflow-based skills and provides a review agent for auditing existing skills.
Components
Skills
- designing-workflow-skills — Guides the design and structuring of workflow-based Claude Code skills with multi-step phases, decision trees, subagent delegation, and progressive disclosure.
Agents
- workflow-skill-reviewer — Reviews workflow-based skills for structural quality, pattern adherence, tool assignment correctness, and anti-pattern detection. Produces a graded audit report.
What This Plugin Teaches
Five workflow patterns for structuring skills:
| Pattern | Use When |
|---|---|
| Routing | Multiple independent tasks from shared intake |
| Sequential Pipeline | Dependent steps, each feeding the next |
| Linear Progression | Single path, same every time |
| Safety Gate | Destructive/irreversible actions needing confirmation |
| Task-Driven | Complex dependencies with progress tracking |
Plus: anti-pattern detection, tool assignment rules, and progressive disclosure guidance.
Installation
/plugin install trailofbits/skills:workflow-skill-design
Usage
Designing a New Skill
Ask Claude to help design a workflow skill — the skill triggers automatically when the request involves multi-step workflows, phased execution, routing patterns, or skill architecture.
Reviewing an Existing Skill
The workflow-skill-reviewer agent can be spawned to audit any skill:
Review the skill at plugins/my-plugin/skills/my-skill/ for quality issues.
File Structure
plugins/workflow-skill-design/
.claude-plugin/
plugin.json
skills/
designing-workflow-skills/
SKILL.md
references/
workflow-patterns.md
anti-patterns.md
tool-assignment-guide.md
progressive-disclosure-guide.md
workflows/
design-a-workflow-skill.md
review-checklist.md
agents/
workflow-skill-reviewer.md
README.md