security-ownership-map
OfficialMap security ownership from Git history and find sensitive code concentrated among too few maintainers.
Data & analysis
Scaffold Codex plugin directories, manifests, optional files, and marketplace entries with editable placeholders.
Creates a normalized Codex plugin directory with the required `.codex-plugin/plugin.json`, a full manifest schema, and editable placeholders. Optional flags add skills, hooks, scripts, assets, MCP, or app files. It can also create or update `.agents/plugins/marketplace.json` while preserving display metadata and required policy fields.
# Plugin names are normalized to lower-case hyphen-case and must be <= 64 chars.
# The generated folder and plugin.json name are always the same.
# Run from repo root (or replace .agents/... with the absolute path to this SKILL).
# By default creates in /plugins/.
python3 .agents/skills/plugin-creator/scripts/create_basic_plugin.py
Open /.codex-plugin/plugin.json and replace [TODO: ...] placeholders.
Generate or update the repo marketplace entry when the plugin should appear in Codex UI ordering:
# marketplace.json always lives at /.agents/plugins/marketplace.json
python3 .agents/skills/plugin-creator/scripts/create_basic_plugin.py my-plugin --with-marketplace
For a home-local plugin, treat `` as the root and use:
python3 .agents/skills/plugin-creator/scripts/create_basic_plugin.py my-plugin \
--path ~/plugins \
--marketplace-path ~/.agents/plugins/marketplace.json \
--with-marketplace
python3 .agents/skills/plugin-creator/scripts/create_basic_plugin.py my-plugin --path \
--with-skills --with-hooks --with-scripts --with-assets --with-mcp --with-apps --with-marketplace
is the directory where the plugin folder will be created (for example ~/code/plugins).
///.///.codex-plugin/plugin.json.interface section./.agents/plugins/marketplace.json when --with-marketplace is set.
name plus interface.displayName placeholders before adding the first plugin entry.My Plugin → my-pluginMy--Plugin → my-plugin-skills/hooks/scripts/assets/.mcp.json.app.jsonmarketplace.json always lives at /.agents/plugins/marketplace.json.~/.agents/plugins/marketplace.json plus ./plugins/.name plus optional interface.displayName.plugins[] as render order in Codex. Append new entries unless a user explicitly asks to reorder the list.displayName belongs inside the marketplace interface object, not individual plugins[] entries.policy.installationpolicy.authenticationcategorypolicy.installation: "AVAILABLE"policy.authentication: "ON_INSTALL"policy.installation values:
NOT_AVAILABLEAVAILABLEINSTALLED_BY_DEFAULTpolicy.authentication values:
ON_INSTALLON_USEpolicy.products as an override. Omit it unless the user explicitly requests product gating.{
"name": "plugin-name",
"source": {
"source": "local",
"path": "./plugins/plugin-name"
},
"policy": {
"installation": "AVAILABLE",
"authentication": "ON_INSTALL"
},
"category": "Productivity"
}
Use --force only when intentionally replacing an existing marketplace entry for the same plugin name.
If /.agents/plugins/marketplace.json does not exist yet, create it with top-level "name", an "interface" object containing "displayName", and a plugins array, then add the new entry.
For a brand-new marketplace file, the root object should look like:
{
"name": "[TODO: marketplace-name]",
"interface": {
"displayName": "[TODO: Marketplace Display Name]"
},
"plugins": [
{
"name": "plugin-name",
"source": {
"source": "local",
"path": "./plugins/plugin-name"
},
"policy": {
"installation": "AVAILABLE",
"authentication": "ON_INSTALL"
},
"category": "Productivity"
}
]
}
plugin.json "name" are always the same normalized plugin name..codex-plugin/plugin.json present.--force only when overwrite is intentional.interface.displayName.policy.installation, policy.authentication, and category even if their values are defaults.policy.products only when the user explicitly asks for that override.source.path relative to repo root as ./plugins/.For the exact canonical sample JSON for both plugin manifests and marketplace entries, use:
references/plugin-json-spec.mdAfter editing SKILL.md, run:
python3 /scripts/quick_validate.py .agents/skills/plugin-creator
Map security ownership from Git history and find sensitive code concentrated among too few maintainers.
Deploy, link, or publish web projects on Netlify through the Netlify CLI.
Access ~12.4M US business registrations — LLCs, corps, formation dates, registered agents — free from 5 state open-data portals.
Detect when presentation language is steering your decision instead of the facts themselves.
Inspect Sentry issues and events, summarize production errors, and retrieve health data through read-only CLI queries.
Plan, scaffold, refactor, and validate ChatGPT Apps SDK projects with an MCP server and widget UI.
Build or update full-page Figma screens with linked design-system components, variables, and styles.
Builds a code-aligned Figma design system through phased creation, validation, and user approval.
Runs Figma Plugin API scripts with the required call parameters, API rules, IDs, and validation workflow.
Create and validate a Codex-compatible animated pet atlas from concepts, brand cues, or reference art.
Generate or edit raster assets, validate the result, and place selected files into the project workspace.