mrkeyoor.com_
Thu 01 Oct 15:40 UTC
LLM Toolsevaluationupdated 01 Oct 2026

awesome-codex-plugins review

Awesome Codex Plugins is a curated Git repository and installable marketplace with 249 mirrored community plugin bundles, plus links to official Codex plugins. It helps Codex users browse and install skills, MCP integrations, and workflow packages from one source instead of cloning each publisher's repository separately.

Verdict

Our sampled Ontoly wrapper installed 0 packages in 6 seconds and reported 0 known vulnerabilities, but that result covers 1 nested package inside a 249-entry marketplace. Use Awesome Codex Plugins for discovery and convenient mirrored installs, then review the chosen bundle as third-party code with its own permissions and services. Teams that need a single publisher or immutable releases should stay with an official catalog or pin a reviewed commit.

We ran it

Lab card: what happened when we ran awesome-codex-pluginsScreenshot of awesome-codex-plugins (hol.org/plugins/best-codex-plugins)
Install✓ · 6s0 packages · 1 MB
Buildn/ano build script
Testsn/ano test script
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo9824 files~252,569 lines of source · 112.6 MB · 13 CI workflows · tests dir

Answers from our run

Does awesome-codex-plugins build from source?

Dependencies installed in 6 seconds (0 packages), and the project has no separate build step. We cloned commit 82e70c7 into a clean Debian container with 3 CPUs and no project-specific setup.

Does awesome-codex-plugins have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does awesome-codex-plugins have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use awesome-codex-plugins?

Anyone treating catalog admission as a code audit: the README says the scanner is a triage signal and explicitly warns that a scan is not a safety guarantee.

What are the alternatives to awesome-codex-plugins?

OpenAI Plugins, OpenAI Skills, Awesome AI Plugins. Our sampled Ontoly wrapper installed 0 packages in 6 seconds and reported 0 known vulnerabilities, but that result covers 1 nested package inside a 249-entry marketplace.

Setup4/56-second sample install; individual plugin requirements still vary
Docs5/5Clear marketplace, plugin anatomy, scanner, and submission guidance
Community5/5October 1 activity with 10 open issues and 12 open PRs
Maturity3/5249 entries and CI, but no releases and a mirror edge case

Who it’s for

Codex users who want one browsable source for community plugins and skills.
Teams willing to inspect a plugin's manifest, instructions, tools, and requested access before installation.
Plugin authors who can meet the catalog's manifest, security policy, license, and scanner rules.
Maintainers who want local mirrored bundles instead of fetching every upstream repository during installation.

Who it’s NOT for

Anyone treating catalog admission as a code audit: the README says the scanner is a triage signal and explicitly warns that a scan is not a safety guarantee.
Teams that require immutable versioned releases: the repository had no GitHub release, and its documented marketplace command follows the main branch.
Publishers with several plugins in one repository who expect every bundle to appear automatically: open issue 430 reports a 10-plugin source being mirrored as only 1 installable bundle.
Buyers seeking one tested application: our run covered the nested Ontoly wrapper, while the 249-entry marketplace contains unrelated third-party code and instructions.

Setup reality

Our lab checked commit 82e70c7 and ran npm inside plugins/0xsarwagya/ontoly-codex-plugin/, not across all 249 marketplace entries. Installation succeeded in 6 seconds, installed 0 packages, and used 1 MB on disk. There was no build or test script, so both steps were skipped. Npm audit reported 0 known vulnerabilities.

Using the catalog requires a Codex client with marketplace support and the Git repository URL; the documented command sparsely checks out .agents/plugins and plugins from main. The catalog itself needs no API key. Individual plugins can add MCP servers, app connections, CLIs, or service credentials, so each manifest and skill must be reviewed separately.

The full checkout contained 9,824 files, about 252,569 lines of source, and occupied 112.6 MB. Our scan found 13 CI workflow files, no Dockerfile, and a tests directory. The catalog mirrors upstream bundles and applies a centralized scanner threshold of 80/130, but it does not turn 249 publishers into one release or one trust boundary.

The marketplace contains 249 mirrored plugin bundles

The generated marketplace listed 249 community entries on October 1, 2026. Each entry points to a local path under plugins/, so Codex installs the catalog's mirrored copy instead of contacting the publisher's repository during that install. The README also lists 12 official plugins available through Codex's built-in directory. That makes this repository useful as a discovery layer and a working marketplace source, rather than a static page of links.

Adding it is straightforward: point the Codex marketplace command at the Git repository, request the .agents/plugins and plugins sparse paths, then list or install by name. The docs warn against passing the raw JSON URL because Codex expects a Git repository and returns a 404 for that file URL. Desktop and IDE users can add the same repository through plugin settings.

An 80/130 scanner floor catches packaging and security smells

With plugin-scanner 3.15.5, catalog admission requires a centralized score of at least 80/130 with no high or critical findings. The contribution guide also requires a valid .codex-plugin/plugin.json, SECURITY.md, a license, a README, and the absence of hardcoded secrets or dangerous MCP command patterns. Source-repository scanner CI is recommended, while the catalog's own scan is the admission decision.

That floor is useful, but the repository states that a scan is not a safety guarantee. The score covers manifest validity, security files, operational security, documentation, installability, maintenance, provenance, and publisher quality. It cannot decide whether a long skill instruction matches your policy or whether an authenticated MCP action is appropriate for your data. A score narrows the review queue; it does not replace permission review.

What happened when we ran it

Our lab method cloned commit 82e70c7 and measured 9,824 files, about 252,569 lines of source, and a 112.6 MB checkout. The machine had 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges. Because this repository is a collection, we selected plugins/0xsarwagya/ontoly-codex-plugin/ as its npm project rather than pretending one command exercised all 249 entries.

Inside that wrapper, npm finished in 6 seconds, installed 0 packages, and left a 1 MB footprint. Npm audit found 0 known vulnerabilities across all severity levels. The package defined no build or test command, so those stages were skipped. The result says the Ontoly wrapper's package shell is light. It says nothing about the separate Ontoly CLI, its MCP runtime, or the other 248 marketplace entries.

Following main gives fresh mirrors without immutable releases

The documented setup follows the main branch, and GitHub showed no tagged release for the repository. Mirrored bundles improve install availability because Codex does not need every upstream source during installation. They also place the catalog generator between publisher changes and what users receive. For a company rollout, record the reviewed commit and inspect its local source path before adding that marketplace revision to managed machines.

The checkout has 13 CI workflow files, a tests directory, and no Dockerfile. Those repository signals cover the catalog machinery, while individual bundles remain heterogeneous. Some contain only instructions. Others add scripts, app integrations, or MCP servers that reach external systems. A green catalog workflow cannot collapse those different capabilities into one approval decision.

Issue 430 shows a 10-to-1 mirroring failure

Open issue 430 describes a source repository containing 10 self-contained plugin bundles whose catalog mirror exposed only 1. The reporter also found 3 entries from another publisher resolving to the same local source path. This is a concrete discovery and distribution bug for multi-plugin repositories: the human README can imply wider coverage than the generated install paths deliver. Publishers should verify the generated marketplace entry after merge.

The issue was still open after an update on September 29, 2026. Until the generator expands repository marketplaces or documents a supported multi-bundle convention, one repository per submitted plugin is the safer shape. Users should check the local source.path when a listing promises several tools, especially if multiple names appear to share one bundle.

October 1 activity matters more than the missing release tag

GitHub showed a push on October 1, 2026, with 10 open issues and 12 open pull requests. Recent merged work added plugins, refreshed listings, corrected a tool-count claim, updated links, and removed one entry. That is active curation. The absence of a GitHub release still matters for pinning, but it is not evidence that the marketplace has been abandoned.

Awesome Codex Plugins earns a place in an experienced user's discovery workflow because 249 mirrored entries are easier to inspect than 249 unrelated repository URLs. The safe unit of adoption remains the individual plugin and the exact commit. Our 6-second Ontoly result is useful evidence for that wrapper only. Treat the catalog's 80/130 gate as an initial filter, then read the files that will instruct your agent or connect it to outside systems.

Alternatives

ProjectWhat it isPick it when
OpenAI Plugins gh↗OpenAI's own repository for first-party plugin bundles.pick this instead when you want a smaller first-party source rather than a broad community catalog.
OpenAI Skills gh↗OpenAI's catalog of reusable Codex skill packages.pick this instead when instructions and skills are the requirement and full plugin bundles add unnecessary scope.
Awesome AI PluginsA broader catalog spanning Codex, Claude Code, Gemini, OpenCode, and other assistants.pick this instead when your team uses several agent platforms and wants one cross-platform discovery list.

What people are saying

  1. [github-trending] hashgraph-online/awesome-codex-plugins

Sources

  1. Awesome Codex Plugins README
  2. Generated Codex marketplace
  3. Plugin scanner and contribution requirements
  4. Multi-plugin mirroring issue 430

More llm tools reviews

claude-style-patch · agent-toolkit-for-aws · agent-memory · codex-astra-luna-orchestrator · okf-agent-memory · mlc-llm · the whole board →