Files
trailofbits-skills/plugins/second-opinion
Lixin2026 d5fe2e6a78 feat(codex): add UI metadata for skills (#175)
* feat(codex): add skill UI metadata

* Use official Trail of Bits logo

* fix: resolve code review findings for PR #175

Codex silently drops the icons as authored: its loader
(codex-rs/core-skills resolve_asset_path) requires icon paths
containing '..' to resolve under <plugin_root>/assets/, and the
repo-root .codex/assets location fails that containment check.
Verified empirically via codex app-server plugin/read: every
iconSmall/iconLarge came back null; only brand_color applied.

P1 fixed:
- Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for
  all 38 plugins with skills and point every openai.yaml at
  ../../assets/trail-of-bits-mark.svg (the supported plugin-level
  shared asset pattern). Icons now resolve for marketplace
  installs too, since nothing escapes the plugin root.
- Drop the .codex/ additions: .codex/skills/gh-cli/agents/
  openai.yaml resolved nowhere (.codex/skills is not a Codex
  discovery root) and PR #173 removes the whole .codex/ tree

P2 fixed:
- Patch-bump all 38 touched plugins in plugin.json and
  marketplace.json so installed clients pick up the metadata

Verified:
- Static check replicating Codex's resolution algorithm: all 73
  yaml files resolve under their plugin assets/ and exist
- Live codex app-server probe: 71/72 loadable skills report
  resolved iconSmall/iconLarge and brand_color #D83A34
  (claude-in-chrome-troubleshooting fails to load on main due to
  a pre-existing 64-char qualified-name limit, fixed by #173's
  rename; zeroize-audit's manifest mcpServers object is likewise
  a pre-existing Codex incompatibility fixed by #173)
- validate_codex_skills.py, validate_plugin_metadata.py, prek all
  pass

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(codex): use skill-local icon assets

---------

Co-authored-by: Dan Guido <dan@trailofbits.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-05 12:28:41 -04:00
..

second-opinion

Run code reviews using external LLM CLIs (OpenAI Codex, Google Gemini) on uncommitted changes, branch diffs, or specific commits.

Prerequisites

OpenAI Codex CLI

  • Codex CLI installed: npm i -g @openai/codex
  • OpenAI API key or ChatGPT Plus subscription configured for Codex

Google Gemini CLI

  • Gemini CLI installed: npm i -g @google/gemini-cli
  • Google account authenticated
  • Code review extension: gemini extensions install https://github.com/gemini-cli-extensions/code-review
  • Security extension: gemini extensions install https://github.com/gemini-cli-extensions/security

Installation

/plugin marketplace add trailofbits/skills
/plugin install second-opinion

Usage

/second-opinion

The command will prompt for:

  1. Review tool — Codex, Gemini, or both (default)
  2. Review scope — uncommitted changes, branch diff, or specific commit
  3. Project context — optionally include CLAUDE.md/AGENTS.md for project-aware review
  4. Review focus — general, security, performance, or error handling

Quick invocation

/second-opinion check the uncommitted changes for security issues

Inline arguments pre-fill the scope and focus, skipping redundant questions.

How It Works

Shells out to codex review and/or gemini CLI with high-capability model configurations. When both tools are selected (the default), runs Codex first then Gemini, presenting results side by side for comparison.

Codex MCP Tools

This plugin bundles Codex CLI's built-in MCP server (codex mcp-server), which auto-starts when the plugin is installed and provides two MCP tools:

  • codex — start a new Codex session with a prompt, model, sandbox, and approval policy settings
  • codex-reply — continue an existing session by thread ID for multi-turn conversations

These tools work independently of the /second-opinion slash command. Use them when you want direct, programmatic access to Codex without the interactive prompt workflow.