
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
codex-skillforge
Advanced tools
ESLint for Codex skills and plugins.
SkillForge helps Codex extension authors scaffold, lint, smoke-test, inspect, and package skills/plugins before they publish or submit them to a marketplace.
Listed in awesome-codex-plugins under "Validate Before You Ship."
npx codex-skillforge lint .
Example output:
SkillForge plugin lint found 3 issue(s):
[ERROR] plugin.skills.missing - Manifest path does not exist: ./skills/
[WARNING] skill.description.vague - Description should clearly say what the skill does and when Codex should use it.
[ERROR] metadata.openai-yaml.legacy-shape - agents/openai.yaml fields must live under interface:
Codex skills and plugins are small, powerful folders. They are also easy to get subtly wrong:
agents/openai.yaml shapes./-relativeSkillForge is not a marketplace. It is the publish-readiness check you run before sharing a Codex skill/plugin repo.
SkillForge is a CLI linter, not a Codex runtime plugin. Running lint, doctor, and smoke reads local files and reports issues; it does not install skills, load plugins into Codex, or execute scripts from the target project.
Commands that write files are explicit:
init creates scaffold files in the destination you choose.pack writes release artifacts to an output directory.For cautious use, pin the npm version, review the source, and start with read-only commands:
npx codex-skillforge@0.1.3 lint .
npx codex-skillforge@0.1.3 smoke ./path/to/skill
Run with npm:
npx codex-skillforge lint .
Or install it in a project:
npm install --save-dev codex-skillforge
npx skillforge lint .
After installing, you can use the shorter aliases:
skillforge lint .
csf lint .
See a tiny working example repo:
See real-world scan notes:
The examples/real-world-cases/ folder contains tiny, intentionally flawed examples based on issues found while scanning public Codex plugin bundles:
missing-mcp-server-file: plugin manifest points at ./mcp.json, but the file is absent.stale-skill-reference: SKILL.md links to a reference file that no longer exists.weak-trigger-description: skill frontmatter is valid YAML, but too vague for reliable triggering.Try them:
npx codex-skillforge lint examples/real-world-cases/missing-mcp-server-file
npx codex-skillforge lint examples/real-world-cases/stale-skill-reference
npx codex-skillforge lint examples/real-world-cases/weak-trigger-description --strict
Create and check a new skill:
npx codex-skillforge init skill ./my-skill --name my-skill
npx codex-skillforge lint ./my-skill
npx codex-skillforge smoke ./my-skill
npx codex-skillforge pack ./my-skill
Check an existing Codex extension repo:
npx codex-skillforge lint .
If SkillForge is installed globally or in your project, the same workflow is shorter:
skillforge lint .
skillforge smoke ./my-skill
skillforge pack ./my-skill
skillforge init skill ./my-skill --name my-skill
skillforge init plugin ./my-plugin --name my-plugin
skillforge init plugin ./hook-plugin --name hook-plugin --template hook-package
skillforge lint ./my-skill --format text
skillforge lint ./my-skill --format json
skillforge lint ./my-skill --format sarif
skillforge lint ./my-skill --strict
skillforge lint .
skillforge doctor .
skillforge smoke ./my-skill
skillforge pack ./my-plugin
lint . can inspect a repository-style collection and recursively find skill/plugin folders under paths like .agents/skills and plugins.
Default lint mode focuses on high-confidence publish-readiness problems. Use --strict to include advisory checks such as trigger-description quality, large skill bodies, unreferenced scripts, and plugin name/folder mismatch.
Use SkillForge in CI:
name: SkillForge
on:
pull_request:
push:
branches: [main]
jobs:
lint-codex-extensions:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: f0d010c/skillforge@main
with:
path: .
format: sarif
Add skillforge.json to a skill or plugin root:
{
"name": "my-codex-skill",
"type": "skill",
"examples": [
{
"prompt": "Use $my-codex-skill to review a React UI for visual issues.",
"shouldTrigger": true
}
],
"checks": {
"maxSkillMdLines": 500,
"requireOpenAiYaml": false,
"allowScripts": true
}
}
Skill checks:
SKILL.md frontmatter has name and description.agents/openai.yaml uses the current nested interface, policy, and dependencies shape.SKILL.md.Plugin checks:
.codex-plugin/plugin.json exists and parses.version and description.skills, mcpServers, apps, hooks, and visual asset paths resolve../-relative and stay inside the plugin root.hooks/hooks.json is detected and parsed.codex_hooks feature flag.Codex reads local skills from repo and user locations such as:
./.agents/skills/<skill-name>
$HOME/.agents/skills/<skill-name>
Plugins are distributed through marketplace files such as:
./.agents/plugins/marketplace.json
$HOME/.agents/plugins/marketplace.json
skillforge pack writes:
<name>.zipINSTALL.mdmarketplace-entry.json0: pass, or warnings only1: lint errors or failed smoke checks2: invalid CLI usage or unreadable inputBefore publishing:
npm run build
npm test
npm audit
npm pack --dry-run
Verify from a clean directory after npm publish:
mkdir skillforge-smoke
cd skillforge-smoke
npx codex-skillforge --version
npx codex-skillforge init skill ./demo-skill --name demo-skill
npx codex-skillforge lint ./demo-skill
FAQs
Creator tooling for OpenAI Codex skills and plugins.
The npm package codex-skillforge receives a total of 4 weekly downloads. As such, codex-skillforge popularity was classified as not popular.
We found that codex-skillforge demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.