Codetruss
Local acceptance gate for coding-agent changes — skills-only plugin for Claude Code and Codex
npx -y skills add DeliriumPulse/codetruss-plugins --skill codetrussAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 24 days oldThe repository was created 24 days ago. New is not bad, but a brand new repository carrying a familiar-sounding name is the shape a typosquat arrives in, and there has been no time for anyone else to find a problem with it.
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Operate CodeTruss local acceptance gates for coding-agent changes. Use when a developer asks to bind an agent task to allowed or denied files, configure repository verification, install or diagnose Claude Code or Codex hooks, review a working-tree or staged diff before commit, interpret or verify a signed CodeTruss receipt, repair a failed verdict, or explicitly opt into provider-backed review or receipt sync.
SKILL.md
6.4 KB, ~1.4k tokens by cl100k_base, as published. Nobody here has run it
CodeTruss
Use the installed codetruss CLI as the source of truth. Do not reimplement
scope classification, analyzers, verdict rules, signing, or hook behavior in the
agent.
Preserve the trust boundary
- Work inside the developer's Git repository and inspect existing policy before proposing changes.
- Run
codetruss --versionfirst. This skill targets v0.2.24 or newer. If the CLI is missing or older, explain the prerequisite, then obtain explicit consent before downloading or installing software, including an upgrade. - Offer only the official install paths from
https://codetruss.com/cli. Let the developer inspect a downloaded installer instead of piping it when they prefer an inspect-first flow. - Do not run
--llm,codetruss auth login, orcodetruss syncunless the developer explicitly requests that networked action. Never search for or print provider keys. - Do not broaden
allow, removedeny, add--no-verify, or edit a receipt to manufacture a green verdict. Fix the change or ask the developer to approve a genuine policy change. - For
codetruss runandcodetruss review, treat exit0asPASS, exit1asREVIEW_REQUIRED, exit2asFAILED, and exit3as a usage or environment failure. Exits 1 and 2 still produce receipts; other commands may use nonzero exits differently, so read their output. - Describe a valid signature as post-generation integrity evidence. Do not call it trusted execution, proof of authorship, or automatic compliance evidence.
Set up a repository
- Confirm the repository root and require a reasonably clean baseline when attribution matters.
- Inspect tracked paths, task context, existing
.codetruss.yml, package scripts, and the repository's normal lint, typecheck, test, or build commands. - Propose the smallest useful
allowglobs, appropriatedenyglobs, the exact verification commands CodeTruss is expected to detect, and one hook target. Keep secrets, generated output, production infrastructure, and unrelated migrations denied when appropriate. Show which tracked paths each glob matches, and flag empty or overly broad matches. Do not default to**/*. - Ask the developer to confirm the exact boundary, hook target, verification command list, and whether to trust that list for automatic execution.
- After confirmation, use
codetruss setupas the single guided setup path, with the approved repeated--allowand--denyvalues and one--hooks claude|codex|pre-commit|allvalue. Prefer its interactive trust prompt so the commands it actually prints can be compared with the approved list before answeringtrust. Use--yesonly after every choice is explicit and the inspected repository state is unchanged. Include--trust-verifyonly after the developer approves the exact detected list, so fingerprint trust is completed. Do not replace guided initial setup with ad hoc config editing or separate hook installation. - Read the setup output and verify the expected policy, hook health, and
local-only privacy reminder. When commands were detected, require their
full verification fingerprint and trusted result, then run
codetruss verify-policy statusand require exit 0 with the same fingerprint and command list. Otherwise confirm that setup reports no detected commands. If setup pauses before trust, show the exact commands and fingerprint, obtain approval, then rerun the same setup path with--trust-verify. - Remind Codex users to open
/hooksand approve the exact repository hook definition when setup reports that one-time host trust step.
The CLI's hook installer is idempotent and preserves supported existing hook
configuration. An existing .codetruss.yml remains authoritative: if setup
reports a policy mismatch, stop instead of overwriting or weakening it, and
treat any policy change as a separate developer decision. If the developer
approves the exact policy diff, make only that reviewed edit and rerun setup
without conflicting policy flags. A setup hook target installs or checks that
target; it does not remove other existing hooks. Never uninstall another hook
without an explicit removal request. Do not replace the installer with
plugin-bundled hook logic.
Review changes
- Use the developer's actual task statement. Ask for it if the intended change is unclear; do not invent a permissive task after seeing the diff.
- Use
codetruss review --task "..."for current tracked and untracked changes. Add--stagedonly when the developer requests the index or a pre-commit review. - Use repository policy by default. Pass task-specific
--allow,--deny, or--verifyvalues only when the developer explicitly sets or approves them. - Read the receipt ID and explicit reasons. Use
codetruss report latest --jsonwhen structured evidence is useful, then runcodetruss verify latestbefore describing the receipt as valid. - Report the verdict, scope exceptions, sensitive surfaces, analyzer findings, verification results, evidence limitations, and receipt path. Distinguish a policy dispute from a product or shell failure.
For a wrapped agent run, preserve the exact task and policy:
codetruss run --task "<task>" --allow "<glob>" --verify "<command>" -- <agent-command>
Do not stage, commit, reset, clean, or sync as a side effect of review.
Repair and recheck
- Repair the finding at its source while keeping the approved policy stable.
- Re-run the same review mode and verification commands after the change.
- If the developer intentionally changed a sensitive or denied surface, record that decision explicitly; do not silently reclassify it.
- Use
codetruss hooks status <surface>andcodetruss hooks doctor <surface>for diagnosis. Usecodetruss hooks uninstall <surface>only on an explicit removal request.
Keep the final response compact: verdict first, then actionable reasons, receipt ID/path, integrity result, and any decision still required from the developer.
What ships with it: 1 file
201 B alongside SKILL.md
agents/
- openai.yaml201 B