Fla Ascend Performance
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
Operate CodeTruss local acceptance gates for coding-agent changes.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins codetruss --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss .claude/skills/codetruss && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codetruss" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss into .claude/skills/codetruss/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codetruss", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/DeliriumPulse/codetruss-plugins/skills/codetrussType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins codetruss --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss .agents/skills/codetruss && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codetruss" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss into .agents/skills/codetruss/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codetruss", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins codetruss --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss .cursor/skills/codetruss && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codetruss" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss into .cursor/skills/codetruss/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codetruss", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hashgraph-online/awesome-codex-plugins.git --path plugins/DeliriumPulse/codetruss-plugins/skills/codetruss--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins codetruss --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss .gemini/skills/codetruss && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codetruss" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss into .gemini/skills/codetruss/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codetruss", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hashgraph-online/awesome-codex-plugins codetrussInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss .github/skills/codetruss && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codetruss" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss into .github/skills/codetruss/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codetruss", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hashgraph-online/awesome-codex-plugins codetruss --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss .opencode/skills/codetruss && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codetruss" agent skill from https://github.com/hashgraph-online/awesome-codex-plugins/tree/main/plugins/DeliriumPulse/codetruss-plugins/skills/codetruss into .opencode/skills/codetruss/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codetruss", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codetrussOperate CodeTruss local acceptance gates for coding-agent changes.
Codetruss is an agent skill from hashgraph-online/awesome-codex-plugins. Operate CodeTruss local acceptance gates for coding-agent changes. Use when a developer asks to bind an agent task to allowed or denied files, configure repository verification, install or diagnose Claude Code or Codex hooks, review a working-tree or staged diff before commit, interpret or verify a signed CodeTruss receipt, repair a failed verdict, or explicitly opt into provider-backed review or receipt sync.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Security. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 78497e5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
codexFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
codetruss.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Codetruss loads about 2k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 1,078 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from hashgraph-online/awesome-codex-plugins at commit 78497e5, republished under its Apache-2.0 licence (© hashgraph-online). 1,078 words, ~1,992 tokens.
.claude/skills/codetruss/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use the installed codetruss CLI as the source of truth. Do not reimplement
scope classification, analyzers, verdict rules, signing, or hook behavior in the
agent.
codetruss --version first. This skill targets v0.2.35 or newer. If the
CLI is missing or older, explain the prerequisite, then
obtain explicit consent before downloading or installing software, including an upgrade.https://codetruss.com/cli. Let
the developer inspect a downloaded installer instead of piping it when they
prefer an inspect-first flow.--llm, codetruss auth login, or codetruss sync unless the
developer explicitly requests that networked action. Never search for or
print provider keys.allow, remove deny, add --no-verify, or edit a receipt to
manufacture a green verdict. Fix the change or ask the developer to approve a
genuine policy change.codetruss run and codetruss review, treat exit 0 as PASS, exit 1
as REVIEW_REQUIRED, exit 2 as FAILED, and exit 3 as a usage or
environment failure. Exits 1 and 2 still produce receipts; other commands
may use nonzero exits differently, so read their output.==, and N+1
queries in loops. The rest of the rule pack (command injection, code
injection, path traversal, SSRF, open redirect, XSS, insecure
deserialization), every non-JavaScript language, and the hosted symbol graph
stay hosted-only. Read the receipt's own "What did not run" section instead
of asserting either way from memory.
Report a PASS as the deterministic passes finding nothing new, never as
evidence that the change is secure.REVIEW_REQUIRED at most. They never fail a
verdict on their own, so do not report one as a blocking failure..codetruss.yml, package
scripts, and the repository's normal lint, typecheck, test, or build commands.allow globs, appropriate deny globs, the
exact verification commands CodeTruss is expected to detect, and one hook
target. Keep secrets, generated output, production infrastructure, and
unrelated migrations denied when appropriate. Show which tracked paths each
glob matches, and flag empty or overly broad matches. Do not default to **/*.codetruss setup as the single guided setup path,
with the approved repeated --allow and --deny values and one
--hooks claude|codex|pre-commit|all value. Prefer its interactive trust
prompt so the commands it actually prints can be compared with the approved
list before answering trust. Use --yes only after every choice is
explicit and the inspected repository state is unchanged. Include
--trust-verify only after the developer approves the exact detected list,
so fingerprint trust is completed. Do not replace guided initial setup with
ad hoc config editing or separate hook installation.codetruss verify-policy status and require exit 0 with the same fingerprint
and command list. Otherwise confirm that setup reports no detected commands.
If setup pauses before trust, show the exact commands and fingerprint, obtain
approval, then rerun the same setup path with --trust-verify./hooks and approve the exact repository hook
definition when setup reports that one-time host trust step.The CLI's hook installer is idempotent and preserves supported existing hook
configuration. An existing .codetruss.yml remains authoritative: if setup
reports a policy mismatch, stop instead of overwriting or weakening it, and
treat any policy change as a separate developer decision. If the developer
approves the exact policy diff, make only that reviewed edit and rerun setup
without conflicting policy flags. A setup hook target installs or checks that
target; it does not remove other existing hooks. Never uninstall another hook
without an explicit removal request. Do not replace the installer with
plugin-bundled hook logic.
codetruss review --task "..." for current tracked and untracked changes.
Add --staged only when the developer requests the index or a pre-commit
review.--allow, --deny, or
--verify values only when the developer explicitly sets or approves them.codetruss report latest --json when structured evidence is useful, then run
codetruss verify latest before describing the receipt as valid.Since v0.2.32, a run with no allow policy infers the scope of the turn and marks
those files allowed (inferred) on the receipt: treat an inferred allow as
weaker evidence than a declared boundary and still propose a real .codetruss.yml.
Since v0.2.34, a finding may carry a Suggested fixes entry with a diff and a required safety note: present it, never apply it automatically, and keep the note's rotation-first ordering for a credential, whose diff is deliberately masked and cannot apply cleanly.
For a wrapped agent run, preserve the exact task and policy:
codetruss run --task "<task>" --allow "<glob>" --verify "<command>" -- <agent-command>Do not stage, commit, reset, clean, or sync as a side effect of review.
codetruss hooks status <surface> and
codetruss hooks doctor <surface> for diagnosis. Use
codetruss hooks uninstall <surface> only on an explicit removal request.Keep the final response compact: verdict first, then actionable reasons, receipt ID/path, integrity result, and any decision still required from the developer.
© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in plugins/DeliriumPulse/codetruss-plugins/skills/codetruss of hashgraph-online/awesome-codex-plugins.
Open the folder on GitHubat commit 78497e5
Codetruss next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Codetruss this skillhashgraph-online/awesome-codex-plugins | 1.2k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~6.3k | Automated safety check: Pass | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit | 480 | 1 repos | ~3.3k | Automated safety check: Pass | None | |
| Security Alert Triageelastic/agent-skills | 592 | 1 repos | ~3.5k | Automated safety check: Notes | Apache-2.0 |
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
yan-labs/serenity-aleabitoreddit
Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
SummerSec/ShiroAttack2
当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…
hashgraph-online/awesome-codex-plugins
Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.
hashgraph-online/awesome-codex-plugins
Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).
hashgraph-online/awesome-codex-plugins
A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…
hashgraph-online/awesome-codex-plugins
Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…
hashgraph-online/awesome-codex-plugins
Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.
hashgraph-online/awesome-codex-plugins
Analyze nonfiction manuscripts for reader engagement signals, including heading-level word counts, slow starts, long slogs, weak takeaway titles, value pacing, beta-reader comment dropoff, and…
Categories
Operate CodeTruss local acceptance gates for coding-agent changes. Codetruss is an agent skill from hashgraph-online/awesome-codex-plugins. Operate CodeTruss local acceptance gates for coding-agent changes.
Codetruss fits situations like: A developer asks to bind an agent task to allowed; configure repository verification; diagnose Claude Code; review a working-tree.
Run `npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a claude-code`. Or copy the skill folder (plugins/DeliriumPulse/codetruss-plugins/skills/codetruss in hashgraph-online/awesome-codex-plugins) into .claude/skills/codetruss in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a codex`. Or copy the skill folder (plugins/DeliriumPulse/codetruss-plugins/skills/codetruss in hashgraph-online/awesome-codex-plugins) into .agents/skills/codetruss in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill codetruss -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codetruss, .gemini/skills/codetruss, .github/skills/codetruss and .opencode/skills/codetruss in your project.
Going by SKILL.md and its folder, Codetruss needs the command-line tools its instructions call (codex).
SKILL.md names 1 domain. In commands or code: codetruss.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Codetruss is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Codetruss: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,242 GitHub stars. The repository holds 686 skills in this directory. The repository was last updated on October 8, 2026.
Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.