Skip to content

Harden Codex plugin preflight and project memory - #169

Merged
pacphi merged 3 commits into
mainfrom
feat/codex-plugin-preflight
Aug 20, 2026
Merged

pacphi merged 3 commits into
mainfrom
feat/codex-plugin-preflight

Conversation

@pacphi

@pacphi pacphi commented Aug 20, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • make Codex plugin inspection validate portable skill frontmatter and warn on the version-bounded security-guidance Stop-output incompatibility
  • document and enforce that agentic-kit never installs or enables Codex plugins
  • pin Ruflo project memory across Claude, Codex, and OpenCode while preserving the native agentdb-memory.db writer
  • migrate only agentic-kit-owned legacy Codex MCP registrations; preserve user-owned entries

Root causes addressed

  • Codex owns its plugin tables/cache, so setup and sync must remain read-only on that surface
  • hook-document validation alone missed invalid SKILL.md metadata and runtime-output advisories
  • Codex and OpenCode Ruflo processes could rely on inherited cwd instead of an explicit project-memory launch contract

Validation

  • pnpm run check
  • full local suite: 2,004 tests plus statusline/dashboard/admin suites
  • GitHub matrix passes Node 22/24/26 on Ubuntu, macOS, and Windows
  • quality, internal links, and maintainer devcontainer checks pass

Notes

The .swarm/memory.db and .swarm/agentdb-memory.db pair is intentional: the first is the compatibility pin and the native bridge may use the sibling as its active writer.

@pacphi
pacphi marked this pull request as ready for review August 20, 2026 17:23
@pacphi
pacphi merged commit 417c5dd into main Aug 20, 2026
14 checks passed
@pacphi
pacphi deleted the feat/codex-plugin-preflight branch August 20, 2026 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant