security-ownership-map
OfficialMaps people to files from Git history to reveal sensitive-code ownership, bus factor, and ownership clusters.
Data & analysis
Scaffold a Codex plugin folder, manifest, and marketplace entry from one script.
Runs `create_basic_plugin.py` to create a plugin folder with the required `.codex-plugin/plugin.json`, optional companion folders (skills, hooks, scripts, assets, .mcp.json, .app.json), and — with `--with-marketplace` — a `.agents/plugins/marketplace.json` entry. Plugin names are normalized to lower-case hyphen-case (max 64 chars), and the outer folder always matches the manifest `name`. Generated files contain `[TODO: ...]` placeholders that you fill in before publishing, plus default `policy.installation: AVAILABLE`, `policy.authentication: ON_INSTALL`, and a `category`.
# Plugin names are normalized to lower-case hyphen-case and must be <= 64 chars.
# The generated folder and plugin.json name are always the same.
# Run from repo root (or replace .agents/... with the absolute path to this SKILL).
# By default creates in /plugins/.
python3 .agents/skills/plugin-creator/scripts/create_basic_plugin.py
Open /.codex-plugin/plugin.json and replace [TODO: ...] placeholders.
Generate or update the repo marketplace entry when the plugin should appear in Codex UI ordering:
# marketplace.json always lives at /.agents/plugins/marketplace.json
python3 .agents/skills/plugin-creator/scripts/create_basic_plugin.py my-plugin --with-marketplace
For a home-local plugin, treat `` as the root and use:
python3 .agents/skills/plugin-creator/scripts/create_basic_plugin.py my-plugin \
--path ~/plugins \
--marketplace-path ~/.agents/plugins/marketplace.json \
--with-marketplace
python3 .agents/skills/plugin-creator/scripts/create_basic_plugin.py my-plugin --path \
--with-skills --with-hooks --with-scripts --with-assets --with-mcp --with-apps --with-marketplace
is the directory where the plugin folder will be created (for example ~/code/plugins).
///.///.codex-plugin/plugin.json.interface section./.agents/plugins/marketplace.json when --with-marketplace is set.
name plus interface.displayName placeholders before adding the first plugin entry.My Plugin → my-pluginMy--Plugin → my-plugin-skills/hooks/scripts/assets/.mcp.json.app.jsonmarketplace.json always lives at /.agents/plugins/marketplace.json.~/.agents/plugins/marketplace.json plus ./plugins/.name plus optional interface.displayName.plugins[] as render order in Codex. Append new entries unless a user explicitly asks to reorder the list.displayName belongs inside the marketplace interface object, not individual plugins[] entries.policy.installationpolicy.authenticationcategorypolicy.installation: "AVAILABLE"policy.authentication: "ON_INSTALL"policy.installation values:
NOT_AVAILABLEAVAILABLEINSTALLED_BY_DEFAULTpolicy.authentication values:
ON_INSTALLON_USEpolicy.products as an override. Omit it unless the user explicitly requests product gating.{
"name": "plugin-name",
"source": {
"source": "local",
"path": "./plugins/plugin-name"
},
"policy": {
"installation": "AVAILABLE",
"authentication": "ON_INSTALL"
},
"category": "Productivity"
}
Use --force only when intentionally replacing an existing marketplace entry for the same plugin name.
If /.agents/plugins/marketplace.json does not exist yet, create it with top-level "name", an "interface" object containing "displayName", and a plugins array, then add the new entry.
For a brand-new marketplace file, the root object should look like:
{
"name": "[TODO: marketplace-name]",
"interface": {
"displayName": "[TODO: Marketplace Display Name]"
},
"plugins": [
{
"name": "plugin-name",
"source": {
"source": "local",
"path": "./plugins/plugin-name"
},
"policy": {
"installation": "AVAILABLE",
"authentication": "ON_INSTALL"
},
"category": "Productivity"
}
]
}
plugin.json "name" are always the same normalized plugin name..codex-plugin/plugin.json present.--force only when overwrite is intentional.interface.displayName.policy.installation, policy.authentication, and category even if their values are defaults.policy.products only when the user explicitly asks for that override.source.path relative to repo root as ./plugins/.For the exact canonical sample JSON for both plugin manifests and marketplace entries, use:
references/plugin-json-spec.mdAfter editing SKILL.md, run:
python3 /scripts/quick_validate.py .agents/skills/plugin-creator
Maps people to files from Git history to reveal sensitive-code ownership, bus factor, and ownership clusters.
Deploy web projects to Netlify using the Netlify CLI (`npx netlify`). Use when the user asks to deploy, host, publish, or link a site/repo on Netlify, including preview and production deploys.
Use when the user asks to inspect Sentry issues or events, summarize recent production errors, or pull basic Sentry health data via the Sentry CLI; perform read-only queries using the `sentry` command
Scaffold ChatGPT Apps SDK projects from docs-first plans into MCP server + widget code.
Build full Figma screens from code or descriptions using the target file's published design system.
Reference skill for executing JavaScript in Figma files via the `use_figma` MCP tool, defining API rules and patterns for plugin code.
Create Codex-compatible animated pets and pet spritesheets from a concept, brand, or reference art.
Generate or edit bitmap images directly inside a Codex project, with workspace-bound save paths.
Authoritative OpenAI developer-doc answers with citations for coding and API questions.