mirror of
https://github.com/trailofbits/skills
synced 2026-06-21 14:12:00 +00:00
d5fe2e6a78
* feat(codex): add skill UI metadata * Use official Trail of Bits logo * fix: resolve code review findings for PR #175 Codex silently drops the icons as authored: its loader (codex-rs/core-skills resolve_asset_path) requires icon paths containing '..' to resolve under <plugin_root>/assets/, and the repo-root .codex/assets location fails that containment check. Verified empirically via codex app-server plugin/read: every iconSmall/iconLarge came back null; only brand_color applied. P1 fixed: - Vendor trail-of-bits-mark.svg into plugins/<name>/assets/ for all 38 plugins with skills and point every openai.yaml at ../../assets/trail-of-bits-mark.svg (the supported plugin-level shared asset pattern). Icons now resolve for marketplace installs too, since nothing escapes the plugin root. - Drop the .codex/ additions: .codex/skills/gh-cli/agents/ openai.yaml resolved nowhere (.codex/skills is not a Codex discovery root) and PR #173 removes the whole .codex/ tree P2 fixed: - Patch-bump all 38 touched plugins in plugin.json and marketplace.json so installed clients pick up the metadata Verified: - Static check replicating Codex's resolution algorithm: all 73 yaml files resolve under their plugin assets/ and exist - Live codex app-server probe: 71/72 loadable skills report resolved iconSmall/iconLarge and brand_color #D83A34 (claude-in-chrome-troubleshooting fails to load on main due to a pre-existing 64-char qualified-name limit, fixed by #173's rename; zeroize-audit's manifest mcpServers object is likewise a pre-existing Codex incompatibility fixed by #173) - validate_codex_skills.py, validate_plugin_metadata.py, prek all pass Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(codex): use skill-local icon assets --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Modern Python
Modern Python tooling and best practices using uv, ruff, ty, and pytest. Based on patterns from trailofbits/cookiecutter-python.
Author: William Tan
When to Use
- Setting up a new Python project with modern, fast tooling
- Replacing pip/virtualenv with uv for faster dependency management
- Replacing flake8/black/isort with ruff for unified linting and formatting
- Replacing mypy with ty for faster type checking
- Adding pre-commit hooks and security scanning to an existing project
What It Covers
Core Tools:
- uv - Package/dependency management (replaces pip, virtualenv, pip-tools, pipx, pyenv)
- ruff - Linting and formatting (replaces flake8, black, isort, pyupgrade)
- ty - Type checking (replaces mypy, pyright)
- pytest - Testing with coverage enforcement
- prek - Pre-commit hooks (replaces pre-commit)
Security Tools:
- shellcheck - Shell script linting
- detect-secrets - Secret detection in commits
- actionlint - GitHub Actions syntax validation
- zizmor - GitHub Actions security audit
- pip-audit - Dependency vulnerability scanning
- Dependabot - Automated dependency updates with supply chain protection
Standards:
- pyproject.toml - Single configuration file with dependency groups (PEP 735)
- PEP 723 - Inline script metadata for single-file scripts
- src/ layout - Standard package structure
- Python 3.11+ - Minimum version requirement
Hook: Legacy Command Interception
This plugin includes a SessionStart hook that prepends PATH shims for python, pip, pipx, and uv. When Claude runs a bare python, pip, or pipx command, the shell resolves to the shim, which prints an error with the correct uv alternative and exits non-zero. uv run is unaffected because it prepends its managed virtualenv's bin/ to PATH, shadowing the shims.
| Intercepted Command | Suggested Alternative |
|---|---|
python ... |
uv run python ... |
python -m module |
uv run python -m module |
python -m pip |
uv add/uv remove |
pip install pkg |
uv add pkg or uv run --with pkg |
pip uninstall pkg |
uv remove pkg |
pip freeze |
uv export |
uv pip ... |
uv add/uv remove/uv sync |
pipx install <pkg> |
uv tool install <pkg> |
pipx run <pkg> |
uvx <pkg> |
pipx uninstall <pkg> |
uv tool uninstall <pkg> |
pipx upgrade <pkg> |
uv tool upgrade <pkg> |
pipx upgrade-all |
uv tool upgrade --all |
pipx ensurepath |
uv tool update-shell |
pipx inject <pkg> <dep> |
uv tool install --with <dep> <pkg> |
pipx list |
uv tool list |
Commands like grep python, which python, and cat python.txt work normally because python is a shell argument, not the command being invoked.
Installation
/plugin install trailofbits/skills/plugins/modern-python