Operate CodeTruss local acceptance gates for coding-agent changes.

Apache-2.0Auto-check passedSecurity

Install Codetruss

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins codetruss --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss .claude/skills/codetruss && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codetruss
GitHub stars
1.2k
Token cost
~2k tokens
SKILL.md length
1,078 words
Files
2
Skills in repo
686
Repo updated
First seen
Licence
Apache-2.0

At a glance

Operate CodeTruss local acceptance gates for coding-agent changes.

  • Works in 7 steps: Confirm the repository root and require… → Inspect tracked paths, task context,… → Propose the smallest useful allow globs,… → …
  • A developer asks to bind an agent task to allowed
  • SKILL.md covers Preserve the trust boundary, Set up a repository, Review changes and Repair and recheck
  • Calls codex; reaches codetruss.com

What it does

Codetruss is an agent skill from hashgraph-online/awesome-codex-plugins. Operate CodeTruss local acceptance gates for coding-agent changes. Use when a developer asks to bind an agent task to allowed or denied files, configure repository verification, install or diagnose Claude Code or Codex hooks, review a working-tree or staged diff before commit, interpret or verify a signed CodeTruss receipt, repair a failed verdict, or explicitly opt into provider-backed review or receipt sync.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • A developer asks to bind an agent task to allowed
  • Configure repository verification
  • Diagnose Claude Code
  • Review a working-tree

Example prompts

  • “/codetruss”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the repository root and require a reasonably clean baseline when
  2. Inspect tracked paths, task context, existing .codetruss.yml, package
  3. Propose the smallest useful allow globs, appropriate deny globs, the
  4. Ask the developer to confirm the exact boundary, hook target, verification
  5. After confirmation, use codetruss setup as the single guided setup path,
  6. Read the setup output and verify the expected policy, hook health, and
  7. Remind Codex users to open /hooks and approve the exact repository hook

What it can do on your machine

Read from SKILL.md and the folder at commit 78497e5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • codetruss.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codetruss loads about 2k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 1,078 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 78497e5, republished under its Apache-2.0 licence (© hashgraph-online). 1,078 words, ~1,992 tokens.

Download SKILL.mdSave it as .claude/skills/codetruss/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
codetruss
description
Operate CodeTruss local acceptance gates for coding-agent changes. Use when a developer asks to bind an agent task to allowed or denied files, configure repository verification, install or diagnose Claude Code or Codex hooks, review a working-tree or staged diff before commit, interpret or verify a signed CodeTruss receipt, repair a failed verdict, or explicitly opt into provider-backed review or receipt sync.

CodeTruss

Use the installed codetruss CLI as the source of truth. Do not reimplement scope classification, analyzers, verdict rules, signing, or hook behavior in the agent.

Preserve the trust boundary

  • Work inside the developer's Git repository and inspect existing policy before proposing changes.
  • Run codetruss --version first. This skill targets v0.2.35 or newer. If the CLI is missing or older, explain the prerequisite, then obtain explicit consent before downloading or installing software, including an upgrade.
  • Offer only the official install paths from https://codetruss.com/cli. Let the developer inspect a downloaded installer instead of piping it when they prefer an inspect-first flow.
  • Do not run --llm, codetruss auth login, or codetruss sync unless the developer explicitly requests that networked action. Never search for or print provider keys.
  • Do not broaden allow, remove deny, add --no-verify, or edit a receipt to manufacture a green verdict. Fix the change or ask the developer to approve a genuine policy change.
  • For codetruss run and codetruss review, treat exit 0 as PASS, exit 1 as REVIEW_REQUIRED, exit 2 as FAILED, and exit 3 as a usage or environment failure. Exits 1 and 2 still produce receipts; other commands may use nonzero exits differently, so read their output.
  • A receipt also names what did not run, and that boundary moved in v0.2.35. A local run now executes the shared SAST engine over the JavaScript, TypeScript and TSX in the repository, covering SQL injection, mass assignment, un-awaited database writes, swallowed errors, coercion-prone ==, and N+1 queries in loops. The rest of the rule pack (command injection, code injection, path traversal, SSRF, open redirect, XSS, insecure deserialization), every non-JavaScript language, and the hosted symbol graph stay hosted-only. Read the receipt's own "What did not run" section instead of asserting either way from memory. Report a PASS as the deterministic passes finding nothing new, never as evidence that the change is secure.
  • Local security findings are REVIEW_REQUIRED at most. They never fail a verdict on their own, so do not report one as a blocking failure.
  • Describe a valid signature as post-generation integrity evidence. Do not call it trusted execution, proof of authorship, or automatic compliance evidence.

Set up a repository

  1. Confirm the repository root and require a reasonably clean baseline when attribution matters.
  2. Inspect tracked paths, task context, existing .codetruss.yml, package scripts, and the repository's normal lint, typecheck, test, or build commands.
  3. Propose the smallest useful allow globs, appropriate deny globs, the exact verification commands CodeTruss is expected to detect, and one hook target. Keep secrets, generated output, production infrastructure, and unrelated migrations denied when appropriate. Show which tracked paths each glob matches, and flag empty or overly broad matches. Do not default to **/*.
  4. Ask the developer to confirm the exact boundary, hook target, verification command list, and whether to trust that list for automatic execution.
  5. After confirmation, use codetruss setup as the single guided setup path, with the approved repeated --allow and --deny values and one --hooks claude|codex|pre-commit|all value. Prefer its interactive trust prompt so the commands it actually prints can be compared with the approved list before answering trust. Use --yes only after every choice is explicit and the inspected repository state is unchanged. Include --trust-verify only after the developer approves the exact detected list, so fingerprint trust is completed. Do not replace guided initial setup with ad hoc config editing or separate hook installation.
  6. Read the setup output and verify the expected policy, hook health, and local-only privacy reminder. When commands were detected, require their full verification fingerprint and trusted result, then run codetruss verify-policy status and require exit 0 with the same fingerprint and command list. Otherwise confirm that setup reports no detected commands. If setup pauses before trust, show the exact commands and fingerprint, obtain approval, then rerun the same setup path with --trust-verify.
  7. Remind Codex users to open /hooks and approve the exact repository hook definition when setup reports that one-time host trust step.

The CLI's hook installer is idempotent and preserves supported existing hook configuration. An existing .codetruss.yml remains authoritative: if setup reports a policy mismatch, stop instead of overwriting or weakening it, and treat any policy change as a separate developer decision. If the developer approves the exact policy diff, make only that reviewed edit and rerun setup without conflicting policy flags. A setup hook target installs or checks that target; it does not remove other existing hooks. Never uninstall another hook without an explicit removal request. Do not replace the installer with plugin-bundled hook logic.

Show full SKILL.md (327 more words)Show less

Review changes

  1. Use the developer's actual task statement. Ask for it if the intended change is unclear; do not invent a permissive task after seeing the diff.
  2. Use codetruss review --task "..." for current tracked and untracked changes. Add --staged only when the developer requests the index or a pre-commit review.
  3. Use repository policy by default. Pass task-specific --allow, --deny, or --verify values only when the developer explicitly sets or approves them.
  4. Read the receipt ID and explicit reasons. Use codetruss report latest --json when structured evidence is useful, then run codetruss verify latest before describing the receipt as valid.
  5. Report the verdict, scope exceptions, sensitive surfaces, analyzer findings, verification results, evidence limitations, and receipt path. Distinguish a policy dispute from a product or shell failure.

Since v0.2.32, a run with no allow policy infers the scope of the turn and marks those files allowed (inferred) on the receipt: treat an inferred allow as weaker evidence than a declared boundary and still propose a real .codetruss.yml.

Since v0.2.34, a finding may carry a Suggested fixes entry with a diff and a required safety note: present it, never apply it automatically, and keep the note's rotation-first ordering for a credential, whose diff is deliberately masked and cannot apply cleanly.

For a wrapped agent run, preserve the exact task and policy:

bash
codetruss run --task "<task>" --allow "<glob>" --verify "<command>" -- <agent-command>

Do not stage, commit, reset, clean, or sync as a side effect of review.

Repair and recheck

  • Repair the finding at its source while keeping the approved policy stable.
  • Re-run the same review mode and verification commands after the change.
  • If the developer intentionally changed a sensitive or denied surface, record that decision explicitly; do not silently reclassify it.
  • Use codetruss hooks status <surface> and codetruss hooks doctor <surface> for diagnosis. Use codetruss hooks uninstall <surface> only on an explicit removal request.

Keep the final response compact: verdict first, then actionable reasons, receipt ID/path, integrity result, and any decision still required from the developer.

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/DeliriumPulse/codetruss-plugins/skills/codetruss of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 78497e5

Compare with similar skills

Codetruss next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codetruss compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codetruss this skillhashgraph-online/awesome-codex-plugins1.2k—~2kAutomated safety check: PassApache-2.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 686 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.2k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.2k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.2k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.2k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.2k GitHub stars~618 tokensUpdated today
    Auto-check passed
  • Manuscript Engagement Analytics

    hashgraph-online/awesome-codex-plugins

    Analyze nonfiction manuscripts for reader engagement signals, including heading-level word counts, slow starts, long slogs, weak takeaway titles, value pacing, beta-reader comment dropoff, and…

    1.2k GitHub stars~875 tokensUpdated today
    Auto-check passed

Categories

Questions about Codetruss

What does Codetruss do?

Operate CodeTruss local acceptance gates for coding-agent changes. Codetruss is an agent skill from hashgraph-online/awesome-codex-plugins. Operate CodeTruss local acceptance gates for coding-agent changes.

When should I use Codetruss?

Codetruss fits situations like: A developer asks to bind an agent task to allowed; configure repository verification; diagnose Claude Code; review a working-tree.

How do I install Codetruss in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a claude-code`. Or copy the skill folder (plugins/DeliriumPulse/codetruss-plugins/skills/codetruss in hashgraph-online/awesome-codex-plugins) into .claude/skills/codetruss in your project. Claude Code loads it when a task matches its description.

How do I install Codetruss in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a codex`. Or copy the skill folder (plugins/DeliriumPulse/codetruss-plugins/skills/codetruss in hashgraph-online/awesome-codex-plugins) into .agents/skills/codetruss in your project. Codex loads it when a task matches its description.

Can I use Codetruss in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codetruss, .gemini/skills/codetruss, .github/skills/codetruss and .opencode/skills/codetruss in your project.

What does Codetruss need to run?

Going by SKILL.md and its folder, Codetruss needs the command-line tools its instructions call (codex).

Does Codetruss access the network?

SKILL.md names 1 domain. In commands or code: codetruss.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Codetruss safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Codetruss use?

Codetruss is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Codetruss use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codetruss?

Skills that share tags, products or a category with Codetruss: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codetruss?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,242 GitHub stars. The repository holds 686 skills in this directory. The repository was last updated on October 8, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.