Skip to content

SafeInstall plugin 0.1.1

Choose a tag to compare

@Mickdownunder Mickdownunder released this 01 Oct 20:46

SafeInstall plugin 0.1.1

Last verified: 2026-10-01

Local Codex plugin distribution, bundling the existing CLI 0.15.0. This is not
an OpenAI public-directory listing or an npm CLI release.

Changes

  • Include complete license terms for @npmcli/agent 5.0.2 (ISC), @sigstore/verify
    4.1.0 (Apache-2.0), and proxy-agent-negotiate 1.1.0 (MIT) in THIRD_PARTY_NOTICES.
  • Preserve original dependency licenses and notices. The builder uses reviewed,
    version-pinned, SHA-256-checked local supplements and rejects unreviewed missing
    texts or corrupted supplements. No license-fetch network requests are made.
  • Correct the previous portal-upload description. The
    current submission rules
    exclude lifecycle hooks; ordinary MCP submissions expect public HTTPS, while
    local MCP requires separate coordination. This full plugin is not currently
    eligible for ordinary public-directory submission.

Runtime behavior and dependency versions are unchanged. Exact upstream license
texts are used where available; ISC/MIT terms use separately identified published
author metadata without inventing copyright ownership or dates.

Downloads and installation

  • safeinstall-plugin-0.1.1.zip: plugin-only distribution, manifest at ZIP root.
  • safeinstall-plugin-0.1.1.tgz: local marketplace including the hidden
    .agents/plugins/marketplace.json and the safeinstall/ plugin.
  • SHA256SUMS: integrity checksums for both archives.
  • THIRD_PARTY_NOTICES: supplemental terms, also included inside both archives.

Requires Node.js ^22.22.2 || ^24.15.0 || >=26.0.0 and a compatible local Codex
plugin host. No repository checkout or dependency installation is needed.
After verifying SHA256SUMS, extract the TGZ into a new directory, preserving
.agents/, and register its root:

codex plugin marketplace add "/absolute/path/to/extracted-marketplace"
codex plugin add safeinstall@safeinstall-local

Review and explicitly trust the hook through the host before expecting automatic
blocking. Installation does not grant hook trust. Start a new chat as needed,
then ask "Set up SafeInstall in this project".

Verification and boundaries

Lint and typecheck passed; 12 focused extracted-plugin/license tests passed.
Actual Codex CLI 0.159.2 discovery on Node 24.19.0 found both MCP tools and all
four skills without granting hook trust. License attacks include unknown missing
texts, changed versions/license identifiers, truncated supplements, and empty
license files; plugin tests cover raw installs, malformed events and trust bypass.

Desktop hook activation remains a user-controlled step, not established by the
client smoke. The hook is not an OS sandbox: arbitrary code execution/downloads
outside supported shell commands are not covered. Policies remain local;
registry/provenance checks still contact their existing services. Universal host
execution, legal ownership beyond published notices, and OpenAI directory review
are not established by these tests.