Two agents used the hub as a maker and a buyer on a local server; each finding below was checked
against the code or the database before this fix.
- verified-email and lead-pipeline accept only a work email: never a free mail provider, and at the
input company's domain when one is given. A finder returned a Gmail address for a company's CMO,
the checker called it valid, and the tool charged its fee.
- A script's price headline shows its cap after the observed range ("$0.0103/run so far · seller
up to $0.02 a run"): recent runs may all have charged little.
- `treg catalog get` on a hub tool no longer labels the whole run cost "per successful run to the
maker"; it prints the seller price and, separately, what a run cost a caller.
- After a publish, the CLI's example call uses the tool's own inputs, not a fixed figma.com body.
- `treg hub ls` shows the maker's price and the search state (no / requested / yes / rejected,
update waits) on the version callers get, marked ◀.
- `treg hub price` on a script says it moved only the cap; the fee is the ctx.charge lines.
- The recipe rules (summary 1-200 characters; the input keys; required, example, int max) are in
skill.md, llms.txt and the `treg hub init` output.
- A version in `checking` or `review` is never shown on the public views (catalog get, share
page); before, `catalog get <id>@N` showed an unreviewed summary and price to anyone.
- New `treg whoami`; `treg balance` names the team. `treg whoami` used to run the system whoami
through `treg with` and print the machine's user name.
- `_kv` keeps a space after a 7-character label ("listingrequested" in `treg hub list`).
Updates docs/context/architecture/hub.md.
treg — Codex / ChatGPT plugin
A distribution wrapper, not a second product. It ships the same skill that
treg skill bootstrap already installs into ~/.codex/skills/, packaged so people find treg by
searching the plugin directory that ChatGPT and Codex share.
One of five shop windows. The Claude Code plugin lives at the repo root (
.claude-plugin/+skills/treg/) and declares no connector in its manifest, so it installs with no token and nothing about it waits on a review queue — its skill wires up the CLI and the MCP tools at first run instead. Cursor is the same bootstrap in Cursor's own layout (plugins/treg/), and DeepSeek Harness is an npm bundle (package.json+dsh/) whose MCP row is disabled until there is a token. All of them are rendered by the samescripts/build_plugin.pyfrom the same source; they differ only in the prepended bootstrap. Seedocs/CLAUDE-PLUGIN.md,docs/DSH-PLUGIN.mdanddocs/MINIMAX-PLUGIN.md(skills-only, fromplugins/minimax/).
plugin/
├── .codex-plugin/plugin.json the manifest + the listing copy
├── skills/treg/ GENERATED — do not edit by hand
└── assets/ icon + logo (▚, black & white)
The assets
logo.png (1024×1024) and icon.png (512×512) are the ▚ mark in pure black and white — white
quadrants on a black rounded square. They are rendered from the geometry in
assets/brand/twitter/avatar-dark.svg, scaled rather than upscaled, so re-rendering at any size is
exact:
viewBox 512 · outer rx 112 · quadrants 140.5² at (111,111) and (260.5,260.5), rx 20
icon.svg is deliberately the filled variant, not the transparent mark-white.svg: a white mark
on transparency vanishes on a light background, and composerIcon renders in a host UI whose
backdrop we do not control.
Note interface.brandColor is still clay #e0703f — the product colour on treg.to. That is an
accent beside a monochrome mark, not a conflict, but change both together if the brand moves.
The skill is generated
src/treg/web/skill.md is the one source. It is served at /skill.md, written into every agent by
treg skill bootstrap, and rendered into this plugin by:
python3 scripts/build_plugin.py # regenerate BOTH plugins
python3 scripts/build_plugin.py --check # fail if either is stale (also a test)
Two things differ from the served copy, both because a plugin arrives where the server does not:
{BASE}is baked to the public deployment. The server substitutes that placeholder per request; nothing substitutes it inside an installed plugin, so a raw copy would ship the literal.- A bootstrap section is prepended. Every other install path implies the CLI already exists —
treg skill bootstraponly runs becausetregis installed. This is the one path where the skill can land on a machine with no treg at all, and without it a first run ends incommand not found.
Never edit skills/treg/SKILL.md. Change src/treg/web/skill.md and regenerate;
tests/test_plugin.py fails if the two disagree.
Testing it locally (verified with codex-cli 0.145.0)
No desktop app required — the Codex CLI installs and loads plugins itself.
The marketplace manifest is a user-side file and is deliberately not part of this plugin. It
lives at ~/.agents/plugins/marketplace.json, and its path is resolved relative to $HOME,
not to the manifest and not as an absolute path:
{
"name": "superdesign-local",
"interface": { "displayName": "superdesign (local dev)" },
"plugins": [
{
"name": "treg",
"source": { "source": "local", "path": "./devs/superdesign/tools-registry-oss/plugin" },
"policy": { "installation": "AVAILABLE", "authentication": "ON_INSTALL" },
"category": "Developer Tools"
}
]
}
Then:
codex plugin list # treg@superdesign-local — not installed
codex plugin add treg@superdesign-local # the @marketplace suffix is REQUIRED
codex plugin list # installed, enabled, 0.7.1
Installed copies land in ~/.codex/plugins/cache/$MARKETPLACE/$PLUGIN/$VERSION/. Confirm the skill
actually loaded — it should appear as treg:tools-registry:
codex exec --skip-git-repo-check "List the names of every skill you have available."
codex plugin marketplace add ./plugin does not work: that command expects a marketplace root,
and this directory is a plugin.
The listing copy is the product
category and capabilities are not guesses — they are what OpenAI's own shipped plugins use
(github is Developer Tools + ["Interactive", "Write"]; gmail is Communication;
openai-templates is Productivity). The published docs show neither list, so read a real installed
manifest under ~/.codex/plugins/cache/ before inventing a value.
Before submitting through OpenAI's plugin portal, check the manifest version matches
pyproject.toml (a test enforces this), and that the copy still describes what treg does: it
compares providers and the agent chooses. treg does not route automatically and does not fail
over — the landing page had to be corrected for that claim once already, and a directory listing is
harder to correct than a web page. A test guards this too.