Enable GitHub remote MCP OAuth with the tested public client credentials
and callback, and add GitHub to the API marketplace. Add GitHub and
Slack README warnings explaining public OAuth client identity.
Validation: JSON/config checks passed; live OAuth was not rerun.
## Summary
API-key installs of Codex Security currently stop waiting for Deep Scan
after 900 seconds even though the shipped skill expects a 97-hour tool
timeout. Sync the complete **0.1.24** maintained payload so the runtime,
skills, launcher, and MCP configuration agree: `tool_timeout_sec` is
**349200** and the launcher is executable.
Source: [`chatgpt/oai-maintained-plugins/plugins/codex-security` at
`97227e0be585e5710d8f872d2800650b1a1659ae`](https://github.com/openai/openai/tree/97227e0be585e5710d8f872d2800650b1a1659ae/chatgpt/oai-maintained-plugins/plugins/codex-security).
The resulting 124 files match that snapshot byte-for-byte and in file
mode. The four files stored outside Git were materialized from an
existing cache only after matching every SHA-256 in the pinned source
metadata. Existing marketplace entries already resolve to this
directory. Copyberry automation is a separate follow-up.
## Validation
- Codex CLI **0.154.0**, isolated profiles in API-key mode, using a
non-production test key and a staged copy of the built-in API catalog:
real `plugin add` and `mcp get` reject the old effective timeout of 900
in the regression assertion and pass with 349200 after the sync.
- The installed package starts its real stdio MCP server, initializes,
lists 45 tools, inspects a temporary target, and reads scan history
successfully.
- All 124 source, destination, and installed files match in bytes and
mode; all four blob hashes match.
- Plugin validation, the shipped completed-scan contract validation, and
`git diff --check` pass.
No live model scan, 97-hour wait, or native Windows/Desktop run was
performed. The disposable verification harness is outside the exported
payload.
<!-- explain-pr:impact:start -->
## Change impact
The existing catalog installs one complete 0.1.24 package, including the
MCP timeout required by Deep Scan.
```mermaid
flowchart LR
subgraph column_0["API catalog"]
direction TB
node_0["API marketplace entry"]
end
subgraph column_1["Plugin package"]
direction TB
node_1["Codex Security 0.1.24"]
end
subgraph column_2["Exports"]
direction TB
node_2["Maintained scan and risk skills"]
node_3["349200-second tool timeout<br/><code>.mcp.json</code>"]
end
subgraph column_3["MCP process"]
direction TB
node_4["Executable Node launcher"]
node_5["Loader uses refreshed runtime"]
end
node_0 -->|"resolves directory"| node_1
node_1 -->|"exports instructions"| node_2
node_1 -->|"exports configuration"| node_3
node_3 -->|"starts"| node_4
node_4 -->|"executes"| node_5
class node_0 context
class node_1 changed
class node_2 changed
class node_3 changed
class node_4 changed
class node_5 affected
classDef changed fill:#d7f5e5,stroke:#237a4b,color:#111
classDef affected fill:#e6f0ff,stroke:#3569a8,color:#111
classDef context fill:#f2f3f5,stroke:#6e7781,color:#111
```
> **Limits:** No live model scan, 97-hour wait, or native
Windows/Desktop run was performed. · Binary chunk and executable-mode
changes were checked locally; GitHub returned no textual patches for
them. · No CI checks were reported in the collected snapshot. Copyberry
automation remains a separate follow-up.
<details>
<summary>Source evidence (7)</summary>
-
[`.agents/plugins/api_marketplace.json:L250-L261`](https://github.com/openai/plugins/blob/1b8ca5bb510426e643a8e3b9c5a1fe802fd5b005/.agents/plugins/api_marketplace.json#L250-L261)
— The existing API marketplace resolves Codex Security to this local
plugin directory.
-
[`plugins/codex-security/.codex-plugin/plugin.json:L2-L20`](https://github.com/openai/plugins/blob/1b8ca5bb510426e643a8e3b9c5a1fe802fd5b005/plugins/codex-security/.codex-plugin/plugin.json#L2-L20)
— Version 0.1.24 exports the synchronized skills and MCP configuration.
-
[`plugins/codex-security/.mcp.json:L3-L53`](https://github.com/openai/plugins/blob/1b8ca5bb510426e643a8e3b9c5a1fe802fd5b005/plugins/codex-security/.mcp.json#L3-L53)
— Launches the bundled script, forwards the maintained environment
allowlist, and sets the tool timeout to 349200 seconds.
-
[`plugins/codex-security/scripts/launch_codex_security_mcp:L7-L28`](https://github.com/openai/plugins/blob/1b8ca5bb510426e643a8e3b9c5a1fe802fd5b005/plugins/codex-security/scripts/launch_codex_security_mcp#L7-L28)
— The existing launcher selects Node and runs the bundled loader. This
sync changes its Git mode from 100644 to 100755.
-
[`plugins/codex-security/mcp/server.mjs:L8-L24`](https://github.com/openai/plugins/blob/1b8ca5bb510426e643a8e3b9c5a1fe802fd5b005/plugins/codex-security/mcp/server.mjs#L8-L24)
— The unchanged loader reads and decompresses the runtime chunks
replaced by this sync. Chunk bytes were verified against pinned source
hashes.
-
[`plugins/codex-security/skills/deep-security-scan/SKILL.md:L46-L58`](https://github.com/openai/plugins/blob/1b8ca5bb510426e643a8e3b9c5a1fe802fd5b005/plugins/codex-security/skills/deep-security-scan/SKILL.md#L46-L58)
— The workflow invokes the coordinator and expects a 97-hour tool
timeout. Detaching the caller does not cancel the scan.
-
[`plugins/codex-security/skills/assess-patch-risk/SKILL.md:L1-L20`](https://github.com/openai/plugins/blob/1b8ca5bb510426e643a8e3b9c5a1fe802fd5b005/plugins/codex-security/skills/assess-patch-risk/SKILL.md#L1-L20)
— The synchronized skill directory also adds the maintained read-only
patch-risk assessment workflow.
**Collection limits**
- #393: plugins/codex-security/mcp/server.mjs.br.part-000: GitHub didn't
return a patch. The file may be binary, or the diff may have been
omitted.
- #393: plugins/codex-security/mcp/server.mjs.br.part-001: GitHub didn't
return a patch. The file may be binary, or the diff may have been
omitted.
- #393: plugins/codex-security/scripts/launch\_codex\_security\_mcp:
GitHub didn't return a patch. The file may be binary, or the diff may
have been omitted.
</details>
<!-- explain-pr:impact:end -->
Qodo is missing from the curated marketplaces, so users cannot discover
and install its core plugin directly from either catalog.
Add `qodo` to both the standard and API-key marketplaces as an external
Git subdirectory source pointing to `qodo-ai/qodo-skills` at
`codex-packages/qodo`. The entry follows the upstream default branch
without a pinned ref, displays the name “Qodo,” and uses the existing
`AVAILABLE` / `ON_INSTALL` policy under Developer Tools.
The core plugin provides setup, codebase wisdom, local review, and
review resolution skills. The separate opt-in `qodo-standards` package
is not included. No plugin contents are vendored into this repository.
Validation:
- Verified the upstream Codex package path, manifest, four skill
directories, and referenced icon assets.
- Parsed both marketplace files and checked matching Qodo entries,
unique plugin IDs, and preservation of all existing entries and
marketplace metadata.
- `git diff --check` passed.
CrowdStrike's Foundry and Fusion plugins are missing from the curated
CLI marketplaces, so API-key and Bedrock users currently need to
register separate Git marketplaces before installing them.
This adds `crowdstrike-falcon-foundry` and `crowdstrike-falcon-fusion`
to both the standard and API-key marketplaces as external Git sources.
Both follow their upstream default branches without pinned refs, include
their CrowdStrike display names, and use the existing `AVAILABLE` /
`ON_INSTALL` policy under Developer Tools. Plugin contents remain in
CrowdStrike's repositories.
Validation:
- Parsed both marketplace files and verified unique plugin IDs,
identical CrowdStrike entries, and preservation of all existing entries
and marketplace metadata.
- Verified plugin identifiers and display names against upstream Codex
manifests.
- `git diff --check` passed.
## Summary
Restore nine highly used plugins that are missing from the curated
marketplace:
- Data Analytics 0.2.8, including 15 skills.
- Creative Production 0.1.25, including 2 skills.
- Public Equity Investing 0.1.31, including 23 skills.
- Adobe 8.0.0, including 6 skills and a normalized `adobe` plugin name.
- Consensus 4.0.0, reconstructed from its complete app-only admin
release metadata.
- ChatCut 1.0.4, including its downloaded desktop-connection skill.
- Higgsfield 1.2.1, including its complete faceless-channel, narrator,
and subtitles skills.
- Lovable 2.0.1.
- ClickUp 1.0.3.
Each plugin includes its complete bundle, `.app.json`, plugin manifest,
and curated marketplace registration with the release's category and
authentication policy. Eight bundles were downloaded from their current
releases, including ClickUp's newly accessible complete release and
composer icon. Consensus has no skills and its complete app-only
definition was reconstructed from the authorized admin release. ChatCut
has no remote app dependencies, so its complete downloaded bundle
includes an empty `.app.json`.
Also synchronize the existing Slack plugin with its official author,
dark-mode branding, logo, composer icon, and authentication policy;
update Boltz to its official Scientific Research category and brand
color. Slack authentication and the Boltz category are consistent across
both marketplace manifests.
Ranked entries without a public remote plugin release are excluded.
## Verification
- Verified the imported source bundles, all 50 expected skill
directories, all nine remote release versions and application manifests,
and all marketplace categories and authentication policies.
- Parsed 53 JSON files and 50 YAML files; compiled all 166 Python files;
scanned 869 text files for credential/private-key patterns.
- `git diff --cached --check` passed before commit.
- Public Equity Investing: 140 tests outside the upstream-failing
deliverable-framework module passed.
- Data Analytics: 107 Node tests, 19 package-utils tests, 11
data-context tests, and the app-dependency test passed.
- The complete 204-test Public Equity suite has 30 existing failures in
`test_deliverable_framework`; the identical 30 failures were reproduced
against the unmodified downloaded release.
- Audited all 62 plugin bundles and Shopify's 20 separately packaged
skills; all release versions, app manifests, and skill identities match
their current remote releases.
## Summary
- Add official marketplace logos and composer icons for Airtable, Canva,
Datadog, monday.com, Shopify, and Stripe.
- Update Google Drive to curated release `0.1.15`.
- Preserve existing `.mcp.json` configurations.
## Verification
All 53 plugins have valid images, Google Drive matches its current
release, and its 20 Google Slides host tests pass.
## Summary
- Remove app-backed plugins that have no local `.mcp.json`.
- Preserve the Microsoft exceptions: Teams, SharePoint, Outlook Email,
and Outlook Calendar.
- Sync the remaining plugin definitions and add Product Design to both
marketplaces.
- Leave all existing `.mcp.json` files unchanged.
## Verification
Validated both marketplaces, protected MCP files, and the Product Design
starter contract.
Adds 30 plugins from the remote curated list. 14 of them have .mcp.json
configurations, while 16 can only be used from marketplace.json with
chatgpt connectors
## What changed
Added `interface.websiteURL` to the ClickUp plugin manifest with
`https://clickup.com`.
## Why
The ClickUp plugin directory listing currently shows no website even
though ClickUp supplied a valid company URL. The source manifest omitted
`websiteURL`, so publishing/materializing the plugin release produced a
null website field.
## Impact
The ClickUp listing can display the company website after the updated
release is published.
## Validation
- Parsed the updated manifest as JSON.
- Confirmed `interface.websiteURL` resolves to `https://clickup.com`.
- Change is limited to `plugins/clickup/.codex-plugin/plugin.json`.
## Currently
https://github.com/user-attachments/assets/5187d606-dbbf-4b2e-91b4-5b1911ed45af
## Why
The Stripe plugin was pointing at the connector id instead of the
expected ChatGPT app id.
## What changed
Updated `plugins/stripe/.app.json` so the Stripe app reference points to
`asdk_app_6983c208e5f8819196b7511519f97993`.
## Validation
- Ran `jq . plugins/stripe/.app.json` to validate the JSON.
- Confirmed the staged diff only changes the Stripe app id.
## Not included
No skill content, assets, or plugin package metadata changes.
Updates Asana's shared plugin icon.
## Current state
Asana's existing shared icon is outdated.
## Changes
- replace `assets/logo.png` with the supplied Asana artwork
- continue using that single asset for both `composerIcon` and `logo`
- bump the Asana plugin version from `0.1.3` to `0.1.4`
No `logoDark` override is needed because the shared asset works on both
light and dark surfaces. Skill files are unchanged.
## Risk
Low. The change replaces one shared image asset used by Asana's composer
and plugin-logo surfaces.
## Testing
- the committed asset matches the supplied source by SHA-256
- repository logo validation passes
- the final diff contains only the Asana manifest and shared logo
- `git diff --check origin/main...HEAD`
The complete plugin validator continues to report existing structural
checks for Asana's 512px composer asset and absent skills directory.
## Manual testing
Open Asana in the composer and on light and dark plugin surfaces and
confirm the shared icon renders correctly.
## Spiciness
1/5
## Summary
This PR imports the text and configuration portion of the supplied
Moody's update patch. It wires the plugin to Moody's M1 MCP endpoint,
adds five reporting workflows (earnings brief, issuer brief, peer
analysis, rating analysis, and sector brief), and introduces shared
template and citation guidance used by the new HTML report skills.
## User impact
Before this change, the Moody's plugin exposed only the existing MCP
exploration and company-analysis guidance. Users could not ask for the
new structured earnings, issuer, peer, rating, or sector deliverables
from the plugin.
After this change, Codex can discover the new Moody's reporting skills,
use the configured MCP server, follow the bundled report templates and
citation conventions, and run the rating-analysis deck builder from the
supplied sample payload.
## Root cause and fix
The plugin manifest did not declare an MCP server file and the new
reporting workflows were not present in the repository. This PR adds
`.mcp.json`, points `plugin.json` at it, and imports the supplied
skills, agent metadata, evals, templates, shared authoring guidance,
sample payload, and PowerPoint builder script.
The supplied patch was generated without binary payloads, so four
referenced assets could not be applied:
- `skills/moody-s-earnings-brief/assets/cover_img_0.png`
- `skills/moody-s-earnings-brief/assets/cover_img_1.png`
- `skills/moody-s-earnings-brief/assets/cover_img_2.png`
- `skills/moody-s-rating-analysis/assets/Moody_Corp_Template.pptx`
This draft intentionally preserves the patch as provided. The earnings
cover images are optional per the skill instructions, but the
rating-analysis skill references the omitted PPTX and will need that
asset before the deck workflow is complete.
## Validation
- Parsed all JSON files under `plugins/moody-s` with `jq -e .`.
- Ran `python3 -m py_compile
plugins/moody-s/skills/moody-s-rating-analysis/scripts/build_pptx.py`.
- Ran `node plugins/plugin-eval/scripts/plugin-eval.js analyze
plugins/moody-s --format markdown`.
- Result: command completed, but the imported plugin scored 0/100 with
three failures for excessive trigger/invoke token cost and the oversized
peer-analysis skill, plus warnings for progressive disclosure, Python
complexity, and missing tests.
- Ran `git diff --cached --check`.
- Result: reported six whitespace findings carried directly from the
supplied patch.
## Follow-up
Add the four omitted binary assets from a `git diff --binary` export or
separate upload, then rerun plugin evaluation and the rating deck
workflow before marking this ready for review.
## Summary
- Add a curated Replay.io plugin migrated from Replay's public Codex
bundle.
- Include the Replay app binding, two partner-authored skills, skill UI
metadata, upload hooks and scripts, branding, and license.
- Register Replay.io in the official marketplace under Developer Tools.
## Source and curated-plugin adaptations
The plugin mirrors [`replayio/plugins` at
`d934e9d`](https://github.com/replayio/plugins/tree/d934e9ddd9898db3af5cd859cf4257957daa5eb7/dist/codex/replayio).
The upstream files are preserved byte-for-byte except where the curated
distribution requires an adaptation:
- omit `.mcp.json` and its manifest reference so installs route through
the app binding
- use repository-standard relative hook script paths
- categorize the plugin as `Developer Tools`
- update one skill sentence to describe the app-backed connection
- add `agents/openai.yaml` metadata for both migrated skills
The source bundle contains no evals, so this change does not introduce
new evals.
## Validation
- plugin ingestion validation
- validation for both skills
- JSON and YAML parsing
- shell syntax checks for both hook scripts
- relative hook command smoke test
- source inventory and SHA-256 audit
- marketplace entry consistency check
- `git diff --check`
## What changed
- add GitHub's hosted MCP server declaration to the GitHub plugin
- authenticate the server through the `GITHUB_PAT` environment variable
- wire the plugin manifest to `.mcp.json`
- document PAT setup, least-privilege guidance, and connection
verification
## Why
Allow API key login users on codex to use the GitHub plugin through PAT.
## Validation
- `git diff --check`
- parsed the plugin and MCP manifests with `jq`
- verified the plugin manifest references `./.mcp.json`
- verified the hosted MCP URL and `GITHUB_PAT` environment-variable
mapping
## Manual Test
1. Set up local Codex
2. Install new GitHub plugin definition
3. Log in with an API key
4. Set up GitHub PAT
5. Check GitHub MCP is usable
## Summary
Export Codex Security external release 0.1.10.
- bump the external plugin manifest from 0.1.9 to 0.1.10
- update the packed MCP runtime and UI for unavailable patch state and
inspected commit diff targets
- improve triage finding intake and ranking guidance and result
contracts
- add the ticket intake reference
- update workbench database handling for inspected commit diff targets
Updates the Atlassian Rovo and Notion light and dark plugin logos.
## Current state
The two plugins do not expose the supplied light and dark logo artwork
through their plugin manifests.
## Changes
- add light and dark top-level logo assets for Atlassian Rovo
- update the Notion top-level light logo and add its dark logo
- map `logo` and `logoDark` in both plugin manifests
- bump both plugin patch versions
Composer icons, `agents/openai.yaml`, and skill files are unchanged.
## Risk
Low. The change is limited to top-level plugin logo assets and manifest
mappings. The main risk is incorrect appearance on light or dark
surfaces.
## Testing
- focused manifest and logo validation passed for both plugins
- destination assets match the supplied sources by SHA-256
- composer icon paths and bytes match `main`
- `agents/openai.yaml` and skill trees match `main`
- `git diff --check origin/main...HEAD`
The complete plugin validator continues to report pre-existing Rovo
composer-size/TODO checks and pre-existing Notion Markdown-formatting
checks.
## Manual testing
Open both plugins on light and dark surfaces and confirm the
corresponding logo is selected without affecting composer or agent
icons.
## Spiciness
1/5
## What changed
- add plugin-local MCP OAuth declarations for Notion, Linear, and Figma
- wire each plugin manifest to its new `.mcp.json`
- add all three plugins to `.agents/plugins/api_marketplace.json`
- bump the Notion, Linear, and Figma plugin patch versions
## Why
This PR makes the aforementioned OpenAI curated plugins work for API key
login users.
## Validation
- `git diff --check`
- parsed all changed JSON files with `jq`
- verified each plugin manifest references `./.mcp.json`
- verified each MCP declaration contains at least one server
- verified the new plugin versions are Notion `0.1.4`, Linear `0.0.3`,
and Figma `2.0.11`
## Manual Testing
1. Set up local Codex
2. Install new plugin definitions
3. Log in with an API key
4. Check OAuth is triggered and the plugins are usable
> ## Summary
>
> - publish the Boltz API CLI 0.1.1 skills-only plugin under
`plugins/boltz-api-cli`
> - register it in the default and API-key marketplaces under `Education
& Research`
> - include eight Boltz workflow skills plus the target-exploration
helpers
> - correct transitive site clustering and fail closed when binder
chains are ambiguous
> - harden installer, dependency-install, and API-key guidance for
public use
>
> ## Provenance
>
> The plugin payload comes from the official
`boltz-bio/boltz-api-skills` release asset `boltz-api-cli-0.1.1.zip` at
commit `70e480ebb14baecfc4456b49eb8b724611470b7c`.
>
> - release asset SHA-256:
`7ec459d0737f399ba1b2c8f6d966abe1060b80834f8c7c22ce959a0780f850c3`
> - the recomputed digest matches GitHub's published release-asset
digest
> - the release archive matches the commit's generated
`surfaces/codex-cli` payload; only the source-only `README.md` and
`DESIGN.md` are outside the release archive
>
> Repository divergence is intentional and reviewable: canonical public
category/marketplace metadata, Ruff and whitespace-only formatting in
otherwise unchanged helper files, focused `scan_sites.py` correctness
fixes and tests, exact validated helper dependency pins, and
consent/secret-handling hardening. No unrelated vendor content was
rewritten.
>
> ## Validation
>
> - public plugin validator: passed
> - all 8 skill validators: passed
> - Ruff format/check: passed
> - focused `scan_sites` tests: 6/6 passed
> - upstream exploration-script fixtures: 16/16 passed
> - fresh Python 3.12 environment with `gemmi==0.7.5` and
`numpy==2.4.6`: passed
> - Python compile check, marketplace invariants, relative-link
inspection, and `git diff --check`: passed
> - shell-tracing sentinel check confirmed the API-key presence probe
does not expose the key
> - canonical pre-submit review completed three full independent
review/remediation passes; final judgement: READY
>
> Static plugin analysis reports a 72/C score driven primarily by the
complete eight-skill vendor bundle's token budget, plus one
helper-complexity warning. The bundle is intentionally cohesive:
approximately 3,450 of 3,694 added lines are the verified vendor
payload, while roughly 200–250 lines are review-relevant integration,
safety, behavior, and test changes. Splitting the skills, shared setup
guidance, references, helpers, manifest, icon, or marketplace records
would produce an incomplete install and weaken provenance auditing.
>
> ## Residual risk
>
> Boltz's fallback installer remains mutable remote code (`curl | sh` /
`irm | iex`) executed as the user outside the sandbox, and the exact
PyPI pins are not hash-locked. The plugin now prefers verifiable pinned
artifacts, requires command-specific informed confirmation before
installer download/execution/escalation, probes before dependency
installation, requires approval before PyPI access, uses a throwaway
environment, and avoids requesting or persisting API keys. The remote
installer body, vendor API behavior, package publishers, and server-side
URL fetching were not independently audited.
## Summary
- export Codex Security v0.1.9 into the external plugins repository
using the managed promotion workflow
- update the public plugin payload, including its packaged MCP assets
- change the marketplace authentication trigger from `ON_INSTALL` to
`ON_USE`
## Impact
- publishes the reviewed v0.1.9 plugin payload
- aligns authentication with when the plugin is used
## Summary
Groups the small plugin skill and connector updates requested in one
draft PR.
Changes include:
- Adds Midpage litigation skills from `midpage-ai/litigation-skills`:
`cite-check`, `draft-brief`, `draft-long-form-memo`, and
`litigation-update-post`.
- Adds Datasite VDR workflow skills to the existing Datasite plugin
using the plugin-migrator import flow: `bulk-qa-answers`,
`document-quality-check`, `gap-analysis`, `irl-tracker`,
`launch-readiness-orchestrator`, `risk-analysis-audit`,
`smart-file-renaming`, and `vdr-index-setup`.
- Expands Render from the existing five skills to the current
`renderinc/render-codex-plugin` source set of 21 skills. Render uses the
updated plugin-migrator helper: one core `SKILL.md` import pass, then a
separate `--resources-only --include-references --include-assets` pass
for references/assets, both dry-run reviewed and SHA-256 verified by the
helper.
- Updates Supabase to use
`https://github.com/supabase-community/supabase-plugin`, bumps the
plugin version to `0.1.10`, and imports the partner PR's Supabase
skill/reference updates via plugin-migrator hash-checked copy. The
partner changelog files are intentionally not included because
`CHANGELOG.md` is not an approved plugin-migrator copy surface.
- Adds a connector-only Glean plugin pointing at the released template
app `templated_apps_6a29c565fdd4819194f27e26218cd95a`, with metadata and
logo derived from App Admin Read. Verified released version
`asdk_app_v_6a29c566b91c81919ded9c8f7dec598c` is `RELEASED_AS_TEMPLATE`.
- Adds Codex-facing `agents/openai.yaml` metadata for newly added
Datasite and Render skills.
- Keeps migration hygiene split across commits: Midpage, Datasite source
import, Render source import, Render resource import, Datasite/Render
metadata, Supabase skill/resource import, Supabase manifest update,
mechanical cleanup, then Glean connector/plugin metadata.
Source links:
- Midpage source: https://github.com/midpage-ai/litigation-skills
- Datasite source: https://github.com/DatasiteAI/codex-plugin and
https://github.com/DatasiteAI/mcp-skills
- Render source: https://github.com/renderinc/render-codex-plugin
- Supabase partner PR: https://github.com/Rodriguespn/plugins/pull/1
- Glean metadata source: App Admin Read for released template
app/version
Internal Slack/Gmail evidence links are captured on the Linear issue
rather than in this PR body to avoid publishing internal collaboration
URLs.
Notes:
- Datasite's public and internal source repos reference a few
`references/*.md` files from inside the skill text, but those files are
not present in either source repo or repo history. This PR does not
invent missing Datasite support docs.
- Render email said 22 skills; the current
`renderinc/render-codex-plugin` source contains 21 skill directories,
and this PR imports all 21.
- Glean's `interface.longDescription` matches the full App Admin
submitted `description` text.
Linear: https://linear.app/openai/issue/ASH-48 and
https://linear.app/openai/issue/ASH-21
## Validation
- Parsed changed plugin manifests/app files with `python3 -m json.tool`.
- Parsed all `agents/openai.yaml` files under Midpage, Datasite, Render,
and Supabase skill trees with Ruby YAML.
- Ran `git diff --check origin/main..HEAD`.
- Compared Datasite and Render imported source files against their
upstream repos, with only mechanical whitespace/mode cleanup ignored; no
missing or substantive differences.
- Confirmed Supabase `SKILL.md` and `security-rls-performance.md` match
the partner PR source byte-for-byte after plugin-migrator copy.
- Ran plugin validation for `plugins/glean` after moving Glean into this
grouped PR.
---------
Co-authored-by: Ashwin Mathews <ashwinm@openai.com>
Restores the GitHub plugin to its previous single logo asset.
## Current state
The recent icon update switched GitHub from `github.png` to separate
`logo.png` and `logo-dark.png` assets.
## What this PR changes
- Restores `./assets/github.png` as the GitHub plugin logo.
- Removes the separate `logoDark` manifest field.
- Deletes `logo.png` and `logo-dark.png`.
- Bumps the GitHub plugin version from `0.1.3` to `0.1.4`.
## Risk
Spiciness: 1/5. The main behavior change is intentional: GitHub returns
to using one logo asset in both themes.
## Validation
- `git diff --check origin/main...HEAD`
- Verified `github.png` exactly matches the pre-icon-update asset.
- Verified the manifest points to `github.png` and no longer contains
`logoDark`.
- Verified both replacement assets are deleted.
- Parsed all plugin manifests as JSON.
## Manual testing
- Inspect the GitHub plugin on light and dark backgrounds and confirm
the previous GitHub logo is displayed in both themes.
## Summary
- add the OpenAI Ads Conversions public Codex plugin
- package the conversions setup skill, public Ads documentation
references, and local verification helpers
- add the plugin to both public marketplace files so standard and
API-key-login Codex users can install it
- include portable usage guidance for users who cannot use Codex plugins
and need to load the skill instructions in another tool
## Public readiness
- removed internal dogfooding/internal marketplace install text from the
README
- scanned for internal-only terms, test Pixel IDs, dogfooding notes, and
stale local setup references
- kept deployment review guidance for privacy, security, consent, data
handling, and CAPI secret handling
## Validation
- /Users/tej/.virtualenvs/openai/bin/python
/Users/tej/.codex/skills/.system/plugin-creator/scripts/validate_plugin.py
plugins/openai-ads-conversions
- /Users/tej/.virtualenvs/openai/bin/python
/Users/tej/.codex/skills/.system/skill-creator/scripts/quick_validate.py
plugins/openai-ads-conversions/skills/openai-ads-conversions-setup
- python3
plugins/openai-ads-conversions/skills/openai-ads-conversions-setup/scripts/verify_capi_secret_not_exposed.py
plugins/openai-ads-conversions --fail-on high
- python3 -m json.tool on both marketplace files and plugin.json
- node plugins/plugin-eval/scripts/plugin-eval.js analyze
plugins/openai-ads-conversions --format markdown
Plugin Eval reported no failures, with warnings around token budget,
helper script complexity/line length, and missing tests for helper
scripts. Those helper scripts are copied from the internal dogfood
plugin payload and can be tightened in follow-up if reviewers want that
before public release.
## Context
Users sometimes paste Gmail web URLs expecting the Gmail connector to
fetch the underlying message or thread. Gmail does not document a
general mapping from browser URL tokens to Gmail API IDs, so treating
every Gmail URL as resolvable would be misleading. The current
alternative is also poor: an agent may search broadly or keep retrying
instead of quickly explaining what input it can use.
## Decision
Add a narrow skill-only fallback that recognizes a bounded set of Gmail
mailbox URL shapes and performs at most two exact-ID reads:
1. Try the extracted opaque token as a message ID.
2. Retry once as a thread ID only when the first result is invalid or
not found.
The skill does not broaden failures into mailbox searches, infer account
identity from the browser `/u/<index>/` slot, or claim support for
arbitrary Gmail URLs. Unsupported routes and failed exact lookups stop
immediately with guidance to provide sender, subject, approximate date,
an RFC 822 Message-ID, or pasted email text.
## Changes
- Add the pasted-link workflow reference with supported hosts, paths,
mailbox views, retry limits, account-boundary behavior, and recovery
copy.
- Route Gmail web URLs from the main Gmail skill to that workflow.
- Add focused eval cases for `#all`, `#inbox` with an attachment suffix,
unsupported search URLs, and exhausted exact-ID resolution.
- Bump the packaged Gmail plugin version from upstream `0.1.2` to
`0.1.3`.
## Validation
- `jq empty plugins/gmail/.codex-plugin/plugin.json
plugins/gmail/skills/gmail/evals/evals.json`
- `git -c core.fsmonitor=false diff --check`
- `node plugins/plugin-eval/scripts/plugin-eval.js analyze
plugins/gmail/skills/gmail --format markdown` (completed; only aggregate
token-budget findings)
- `node plugins/plugin-eval/scripts/plugin-eval.js analyze plugins/gmail
--format markdown` (95/100, no failures; one deferred-token warning)
## Limitations
- Gmail web URL tokens remain undocumented and may not correspond to API
message or thread IDs.
- Search, label, category, compose, and settings routes intentionally
fail fast.
- The browser account index does not select a connected Gmail account;
cross-mailbox links require the user to connect the mailbox that
contains the message.
[Codex
Thread](https://www.golinks.io/thread-id/019ecca1-0a7a-7160-b892-b6c63d229c24?trackSource=github)
Corrects the dark-mode logo manifest key introduced by #340.
## Current state
The icon update used `darkLogo`, but the supported plugin manifest field
is `logoDark`, so dark-mode logos are not discovered through the
expected key.
## What this PR changes
- Replaces `darkLogo` with `logoDark` in all 40 affected plugin
manifests.
- Leaves plugin versions, logo paths, and asset files unchanged.
## Risk
Spiciness: 1/5. This is a mechanical manifest-key correction with no
asset or version changes.
## Validation
- `git diff --check origin/main...HEAD`
- Parsed all 175 plugin manifests as JSON.
- Verified all 40 changes are limited to `darkLogo` -> `logoDark`.
- Verified all 40 `logoDark` asset references exist.
- Verified no `darkLogo` fields remain.
## Manual testing
- Inspect an affected plugin such as GitHub and confirm its manifest
uses `logoDark` with the existing dark-logo asset path.
## Summary
- add the Hex plugin bundle for project search and Hex Threads workflows
- connect the plugin to the existing Hex app connector
- register Hex in the default marketplace under Data & Analytics
This is intentionally connector/MCP-only and does not include Hex CLI
instructions. The repository URL and category are aligned to this public
marketplace.
## Impact
Hex can appear as a standalone installable plugin in the Codex Plugins
page instead of being available only as an optional dependency of
broader analytics plugins.
## Validation
- `validate_plugin.py plugins/hex`
- JSON validation for the plugin manifest, app manifest, and marketplace
- verified exactly one `hex` marketplace entry with `AVAILABLE` /
`ON_INSTALL` policy
- `git diff --check`
Updates plugin icons to use designer-reviewed light and dark assets.
## Summary
- Replace existing logo assets across 89 plugins with the reviewed icon
set
- Add `darkLogo` assets where dark-mode variants are available and
preserve distinct composer icons
- Keep legacy assets that remain referenced by skill metadata and remove
only obsolete, unreferenced assets
- Bump each changed plugin's patch version exactly once in a separate
commit
- Risk is limited to plugin branding and manifest asset references; no
plugin behavior changes
## Validation
- `git diff --check origin/main...HEAD`
- Parsed all 175 plugin manifests as valid JSON
- Verified every `logo`, `darkLogo`, and `composerIcon` reference
resolves to an existing asset
- Verified the 23 additional designer-provided assets byte-for-byte
against their source files
- Verified all 67 removed assets are no longer referenced
- Verified the branch contains exactly two commits: one for icon assets
and one for version bumps
- Manual review: inspect representative light and dark logos on white
and black backgrounds
## Summary
- require exactly five positive test cases
- require exactly three negative test cases
## Why
The ChatGPT app submission workflow expects a fixed amount of review
coverage. The skill previously described both values as minimums, which
allowed agents to generate larger and inconsistent test-case sets.
## Impact
Agents using the OpenAI Developers submission skill will generate
exactly five positive and exactly three negative test cases.
## Validation
- `git diff --check`
- verified the final skill instruction directly
Refs PSR-173
Companion to https://github.com/openai/topiary-intern-2026/pull/1169
---------
Co-authored-by: Joshua Liu <@openai.com>
## Summary
- add `.agents/plugins/api_marketplace.json` for API key login users
- populate it with shared `./plugins/...` declarations for plugins that
declare `skills` and no `apps` or `mcpServers` for now
- note this doesn't take effect yet, we still need to wire up the
plugins sync
## Validation
- `jq` JSON parse and shape checks for
`.agents/plugins/api_marketplace.json`
- set equality check against manifests with `skills` and without
`apps`/`mcpServers`
- source path existence check for every API marketplace entry
- `rg` check for stale `api_users_plugins` / `api_users_marketplace`
references
- `git diff --check`
## Manual Verification
1. local codex setup pointing to new marketplace
2. declared plugins are shown
3. verify they are skill only
4. verify plugin installation works
Broader validation is left to CI because this is a narrow
marketplace/docs change.
## Summary
Make PMIDs and DOIs clickable in user-facing Entrez results. The change
applies to tables, bullets, parentheticals, and source lists; raw
JSON/XML stays unchanged.
Also bumps `life-science-research` from `1.0.2` to `1.0.3` so downstream
installs pick up the new guidance.
## Validation
- installed the branch plugin locally and compared it with the curated
version
- verified tables, bullets, prose, source lists, and raw JSON output
- `quick_validate.py`
- `git diff --check origin/main...HEAD`
[Before/after
screenshots](https://github.com/openai/plugins/pull/330#issuecomment-4678844816)
## Summary
- Add 192x192 padded icon/logo assets for the plugin icons called out by
openai/openai#996735 that are owned in this repo: Base44, fal, Figma,
OpenAI Developers, Picsart, Shutterstock, Shopify, Supabase, and Vercel.
- Point the changed plugins' `logo` fields at the padded assets, and
point remaining tight `composerIcon` fields at the same padded assets
where present.
- Keep Vercel on a fully white 192x192 canvas so its white app-icon
background is extended consistently.
- Leave Browser, Databricks Genie, Sites, and Snowflake untouched
because matching plugin directories are not present in this repository.
## Validation
- `jq empty` on the changed plugin manifests
- `git diff --check`
- Targeted script verifying generated PNG outputs and manifest icon
paths
- Rendered Shopify and Supabase SVG outputs locally with `rsvg-convert`
for visual inspection
Related client-side workaround:
https://github.com/openai/openai/pull/996735
## Summary
- Audits plugin icon assets referenced by the Codex plugin catalog for
light- and dark-mode visibility.
- Updates icons whose original dark artwork becomes difficult or
impossible to identify on dark backgrounds.
- Preserves existing brand marks and uses the catalog's established
white-backed monochrome icon treatment where necessary.
- Reverts broader icon treatments for assets that were already
recognizable in both themes.
## Updated Plugins
- CircleCI
- Common Room
- Daloopa
- FINN
- MarcoPolo
- Network Solutions
- Omni Analytics
- Rox
- Superpowers
## Rationale
Several plugin icons used dark artwork on transparent backgrounds. In
dark mode, these marks became unreadable or nearly indistinguishable
from the surrounding UI.
For monochrome assets such as CircleCI and Superpowers, this PR uses a
fixed white-backed treatment rather than relying on theme-dependent SVG
rendering. This follows an existing catalog convention already used by
icons such as GitHub, Notion, Vercel, and Netlify.
Reapply the reviewed plugin category update from #303 now that the
temporary wait period documented in #319 has ended.
Update marketplace and plugin manifest categories to the canonical
taxonomy. Patch-bump all 172 catalog plugin versions so the ingest batch
can publish fresh releases and refresh category metadata for every
plugin record in the database, including plugins whose checked-in
category did not change.
Each version is exactly one patch above its version on current `main`.
Base44 preserves the repository’s established prerelease convention
(`1.0.1-beta.1` to `1.0.2-beta.1`). Changes merged after the temporary
revert, including the latest Google Drive release, are preserved.
Validation:
- Verified all 172 catalog manifests are exactly one patch above current
`main`.
- Verified categories use the approved taxonomy and marketplace/manifest
values agree.
- Verified no manifest fields other than `version` and the reviewed
`interface.category` changes were modified.
- Ran `cloud-plugin-admin catalog validate
.agents/plugins/marketplace.json` (`valid=172`, `invalid=0`).
- Parsed the marketplace and every plugin manifest as JSON.
## Summary
- strengthen Google Slides creation, template-following, and
source-adaptation guidance
- route general slide planning and archetype selection across net-new
decks, existing-deck additions, and template/reference workflows
- require semantic layout selection, coherent layout families, style-run
preservation, meaningful emphasis, and evidence legibility
- keep exact text, speaker-note, and media-identity parity conditional
on source-based fidelity requests
- add actionable batch-update recipes for mixed-style text and speaker
notes
- clarify that the main agent must read applicable skill references
itself without prohibiting subagents for other scoped work
- bump the Google Drive plugin version from `0.1.4` to `0.1.5`
## Why
Trajectory reviews found that slide work could be mechanically
successful while still misusing layouts, flattening hierarchy,
inheriting misleading emphasis, dropping evidence, or accepting
unreadable crops and blank bullet artifacts. These are general
slide-quality failures, not only migration failures.
The guidance now separates three scopes:
- universal slide planning and quality rules for creation and editing
- existing-layout and template-following rules for using suitable
inherited slots
- source-fidelity rules for exact adaptation or migration, including
notes and media parity
The instruction against delegating skill reading is also scoped to the
main agent personally reading the applicable references; subagents
remain available for execution, extraction, and QA after that grounding.
## Impact
Agents following the Google Slides skill should produce more coherent
net-new decks, better template-following slides, and more faithful
source adaptations. The plugin version bump gives downstream consumers a
refresh signal for the updated behavior.
## Validation
- `quick_validate.py plugins/google-drive/skills/google-slides`
- `jq . plugins/google-drive/.codex-plugin/plugin.json`
- local Markdown reference-link validation
- artifacts_gym/plugin skill parity check excluding plugin-specific
assets
- `git diff --check`
## Summary
- Add explicit Gmail self-delivery guidance for requests such as “email
me this report” in a deferred self-delivery reference.
- Keep the existing skill description unchanged and route only
self-delivery synonyms from the top level.
- Send self-delivery emails directly with `send_email` using `to: "me"`
and no `cc` or `bcc`.
- Preserve normal confirmation and recipient-safety behavior for
ambiguous destinations or recipients other than the authenticated Gmail
account.
## Why
The Gmail connector already supports resolving `me` to the authenticated
user’s email address, but the skill’s draft-oriented guidance caused
automated self-delivery requests to stop at a draft. This change allows
those requests to complete without loosening safeguards for emails sent
to other recipients. The detailed behavior lives in
`references/self-delivery.md` so it is loaded only for self-delivery
requests rather than every new-email task.
## Validation
- Sent a self-delivery smoke-test email with `to: "me"`; Gmail returned
the message in `SENT`, `INBOX`, and `UNREAD` without creating a draft.
- Parsed the updated skill frontmatter with Ruby YAML.
- Ran the skill creator's `quick_validate.py`; the skill is valid.
- Ran `git diff --check`.
- Ran `plugin-eval analyze`; the skill parsed successfully with no
failures.
- Confirmed the detailed self-delivery behavior is deferred rather than
added to the top-level skill body.