Skip to content

fix(codex): add native plugin control plane - #15

Merged
SignalLayerLabs merged 1 commit into
mainfrom
codex/marginal-native-control-plane
Aug 13, 2026
Merged

SignalLayerLabs merged 1 commit into
mainfrom
codex/marginal-native-control-plane

Conversation

@SignalLayerLabs

Copy link
Copy Markdown
Owner

Problem

The native Codex plugin installed and enabled correctly, but its bundled skill called a global
marginal executable that plugin installation does not place on PATH. Even a separately
installed Python CLI could read a different data directory from the lifecycle hooks, producing a
split-brain status.

Solution

  • add a dependency-free control launcher to the plugin bundle
  • dispatch CLI commands from the generated zipapp without changing hook behavior
  • discover and use Codex's native plugin data directory
  • report live authenticated hook services, persisted hook evidence, coverage, and enforcement mode
    as separate facts
  • bound session receipt inspection and accept loopback endpoints only
  • update the bundled skill, docs, support/privacy pages, and release metadata to 0.3.2

User impact

One-command plugin users no longer need pip or a global executable. $marginal can truthfully
distinguish an active repository hook service, previously observed lifecycle evidence, Shadow Mode,
and Tool Enforcement.

Validation

  • Tests added and verified RED → GREEN
  • ruff format --check .
  • ruff check .
  • mypy src/marginal
  • pytest -q — 448 passed
  • Runtime freshness and official skill/plugin validators
  • Wheel/sdist build and Twine validation
  • Reproducible Plugins Directory ZIP
  • Isolated Codex 0.147.0 install/hook/status/remove smoke
  • Documentation and changelog updated
  • Claims remain limited to Tool Enforcement and the n=3 benchmark remains pass-through

Security and compatibility

The launcher does not read Codex credentials or expose session tokens. Live attestation reads
bounded user-private receipts, accepts only 127.0.0.1, uses authenticated status requests, and
reports only aggregate counts and repository hashes. Hook trust remains user-controlled through
/hooks.

Privacy review

  • Privacy profiles affected: local Codex plugin data only
  • New persisted fields: none
  • New emitted fields: aggregate live/observed hook state and coverage
  • Quasi-identifiers considered: repository hashes remain local and no raw session ID is emitted
  • Key-management or export implications: none

@SignalLayerLabs
SignalLayerLabs merged commit b3e3dba into main Aug 13, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant