setup — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited setup (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
claudex's /claudex:think needs two other plugins: the Codex plugin (openai/codex-plugin-cc, for the Codex runtime) and superpowers (anthropics/claude-plugins-official, for the brainstorming flow). This skill installs both, then runs the Codex CLI check.
This skill depends only on the claude CLI and Bash, so it works even before either dependency exists. Every step is idempotent — re-running /claudex:setup is safe and resumes cleanly.
Install both plugins first, so the user reloads once — only then is codex:setup invokable, and you run it last.
1. install codex plugin (CLI, no reload needed yet)
2. install superpowers (CLI, no reload needed yet)
3. ONE reload gate (user runs /reload-plugins → both go live)
4. invoke codex:setup (now available; verifies the Codex CLI)Check first, then add the marketplace and install only if missing:
claude plugin marketplace list 2>/dev/null | grep -q openai-codex \
|| claude plugin marketplace add openai/codex-plugin-cc
claude plugin list 2>/dev/null | grep -q 'codex@' \
|| claude plugin install codex@openai-codexclaude plugin marketplace list 2>/dev/null | grep -q claude-plugins-official \
|| claude plugin marketplace add anthropics/claude-plugins-official
claude plugin list 2>/dev/null | grep -q 'superpowers@' \
|| claude plugin install superpowers@claude-plugins-officialIf a marketplace add fails (e.g. no network), report it and stop — the install in that step can't succeed. The two plugins are independent, so a failure on one doesn't invalidate the other.
Plugins installed via the CLI are not live in the running session — their skills (like codex:setup) aren't invokable until a reload. Check whether codex:setup is available to you now:
/reload-plugins (or restart Claude Code) once, then re-run /claudex:setup to finish — it'll skip the already-installed plugins and run the Codex CLI check."* Then stop. The idempotent checks in steps 1–2 make the re-run cheap.
Invoke codex:setup (via the Skill tool). It checks the local Codex CLI, offers to npm install -g @openai/codex if missing, and prints !codex login guidance if the CLI is installed but not authenticated. Present its output to the user.
Run claude plugin list and confirm claudex, codex, and superpowers are all enabled. Report the final state. /claudex:think is now ready to use.
user scope. Pass --scope project to theinstall commands if the user wants the deps tied to this project instead.
to step 4 (the Codex CLI check) and report that nothing needed installing.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.