The marketplace contains 249 mirrored plugin bundles
The generated marketplace listed 249 community entries on October 1, 2026. Each entry points to a local path under plugins/, so Codex installs the catalog's mirrored copy instead of contacting the publisher's repository during that install. The README also lists 12 official plugins available through Codex's built-in directory. That makes this repository useful as a discovery layer and a working marketplace source, rather than a static page of links.
Adding it is straightforward: point the Codex marketplace command at the Git repository, request the .agents/plugins and plugins sparse paths, then list or install by name. The docs warn against passing the raw JSON URL because Codex expects a Git repository and returns a 404 for that file URL. Desktop and IDE users can add the same repository through plugin settings.
An 80/130 scanner floor catches packaging and security smells
With plugin-scanner 3.15.5, catalog admission requires a centralized score of at least 80/130 with no high or critical findings. The contribution guide also requires a valid .codex-plugin/plugin.json, SECURITY.md, a license, a README, and the absence of hardcoded secrets or dangerous MCP command patterns. Source-repository scanner CI is recommended, while the catalog's own scan is the admission decision.
That floor is useful, but the repository states that a scan is not a safety guarantee. The score covers manifest validity, security files, operational security, documentation, installability, maintenance, provenance, and publisher quality. It cannot decide whether a long skill instruction matches your policy or whether an authenticated MCP action is appropriate for your data. A score narrows the review queue; it does not replace permission review.
What happened when we ran it
Our lab method cloned commit 82e70c7 and measured 9,824 files, about 252,569 lines of source, and a 112.6 MB checkout. The machine had 3 CPUs, 8 GB of RAM, Node 22, no secrets, and no elevated privileges. Because this repository is a collection, we selected plugins/0xsarwagya/ontoly-codex-plugin/ as its npm project rather than pretending one command exercised all 249 entries.
Inside that wrapper, npm finished in 6 seconds, installed 0 packages, and left a 1 MB footprint. Npm audit found 0 known vulnerabilities across all severity levels. The package defined no build or test command, so those stages were skipped. The result says the Ontoly wrapper's package shell is light. It says nothing about the separate Ontoly CLI, its MCP runtime, or the other 248 marketplace entries.
Following main gives fresh mirrors without immutable releases
The documented setup follows the main branch, and GitHub showed no tagged release for the repository. Mirrored bundles improve install availability because Codex does not need every upstream source during installation. They also place the catalog generator between publisher changes and what users receive. For a company rollout, record the reviewed commit and inspect its local source path before adding that marketplace revision to managed machines.
The checkout has 13 CI workflow files, a tests directory, and no Dockerfile. Those repository signals cover the catalog machinery, while individual bundles remain heterogeneous. Some contain only instructions. Others add scripts, app integrations, or MCP servers that reach external systems. A green catalog workflow cannot collapse those different capabilities into one approval decision.
Issue 430 shows a 10-to-1 mirroring failure
Open issue 430 describes a source repository containing 10 self-contained plugin bundles whose catalog mirror exposed only 1. The reporter also found 3 entries from another publisher resolving to the same local source path. This is a concrete discovery and distribution bug for multi-plugin repositories: the human README can imply wider coverage than the generated install paths deliver. Publishers should verify the generated marketplace entry after merge.
The issue was still open after an update on September 29, 2026. Until the generator expands repository marketplaces or documents a supported multi-bundle convention, one repository per submitted plugin is the safer shape. Users should check the local source.path when a listing promises several tools, especially if multiple names appear to share one bundle.
October 1 activity matters more than the missing release tag
GitHub showed a push on October 1, 2026, with 10 open issues and 12 open pull requests. Recent merged work added plugins, refreshed listings, corrected a tool-count claim, updated links, and removed one entry. That is active curation. The absence of a GitHub release still matters for pinning, but it is not evidence that the marketplace has been abandoned.
Awesome Codex Plugins earns a place in an experienced user's discovery workflow because 249 mirrored entries are easier to inspect than 249 unrelated repository URLs. The safe unit of adoption remains the individual plugin and the exact commit. Our 6-second Ontoly result is useful evidence for that wrapper only. Treat the catalog's 80/130 gate as an initial filter, then read the files that will instruct your agent or connect it to outside systems.

