* feat(codex): add skill UI metadata * Use official Trail of Bits logo * fix: resolve code review findings for PR #175 Codex silently drops the icons as authored: its loader (codex-rs/core-skills resolve_asset_path) requires icon paths containing '..' to resolve under <plugin_root>/assets/, and the repo-root .codex/assets location fails that containment check. Verified empirically via codex app-server plugin/read: every iconSmall/iconLarge came back null; only brand_color applied. P1 fixed: - Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for all 38 plugins with skills and point every openai.yaml at ../../assets/trail-of-bits-mark.svg (the supported plugin-level shared asset pattern). Icons now resolve for marketplace installs too, since nothing escapes the plugin root. - Drop the .codex/ additions: .codex/skills/gh-cli/agents/ openai.yaml resolved nowhere (.codex/skills is not a Codex discovery root) and PR #173 removes the whole .codex/ tree P2 fixed: - Patch-bump all 38 touched plugins in plugin.json and marketplace.json so installed clients pick up the metadata Verified: - Static check replicating Codex's resolution algorithm: all 73 yaml files resolve under their plugin assets/ and exist - Live codex app-server probe: 71/72 loadable skills report resolved iconSmall/iconLarge and brand_color #D83A34 (claude-in-chrome-troubleshooting fails to load on main due to a pre-existing 64-char qualified-name limit, fixed by #173's rename; zeroize-audit's manifest mcpServers object is likewise a pre-existing Codex incompatibility fixed by #173) - validate_codex_skills.py, validate_plugin_metadata.py, prek all pass Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(codex): use skill-local icon assets --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
second-opinion
Run code reviews using external LLM CLIs (OpenAI Codex, Google Gemini) on uncommitted changes, branch diffs, or specific commits.
Prerequisites
OpenAI Codex CLI
- Codex CLI installed:
npm i -g @openai/codex - OpenAI API key or ChatGPT Plus subscription configured for Codex
Google Gemini CLI
- Gemini CLI installed:
npm i -g @google/gemini-cli - Google account authenticated
- Code review extension:
gemini extensions install https://github.com/gemini-cli-extensions/code-review - Security extension:
gemini extensions install https://github.com/gemini-cli-extensions/security
Installation
/plugin marketplace add trailofbits/skills
/plugin install second-opinion
Usage
/second-opinion
The command will prompt for:
- Review tool — Codex, Gemini, or both (default)
- Review scope — uncommitted changes, branch diff, or specific commit
- Project context — optionally include CLAUDE.md/AGENTS.md for project-aware review
- Review focus — general, security, performance, or error handling
Quick invocation
/second-opinion check the uncommitted changes for security issues
Inline arguments pre-fill the scope and focus, skipping redundant questions.
How It Works
Shells out to codex review and/or gemini CLI with high-capability model configurations. When both tools are selected (the default), runs Codex first then Gemini, presenting results side by side for comparison.
Codex MCP Tools
This plugin bundles Codex CLI's built-in MCP server (codex mcp-server), which auto-starts when the plugin is installed and provides two MCP tools:
- codex — start a new Codex session with a prompt, model, sandbox, and approval policy settings
- codex-reply — continue an existing session by thread ID for multi-turn conversations
These tools work independently of the /second-opinion slash command. Use them when you want direct, programmatic access to Codex without the interactive prompt workflow.