A Curated Codex Plugin List That Actually Checks What You're Installing
You're browsing for a Codex plugin, and you've got no easy way to know if the thing is safe to run. Plugin directories tend to be either exhaustive or trustworthy, rarely both. Awesome Codex & ChatGPT Plugins takes a different approach: it's a curated list where every entry has to clear a security scan before it gets in.
What It Does
This repository is a curated collection of plugins, skills, and resources for OpenAI Codex and ChatGPT. The twist is the admission requirement. Every plugin submitted to the list has to pass the HOL AI Plugin Scanner, and the catalog-owned centralized scan must report a numeric score of at least 80 out of 130 before anything gets merged.
The repo also functions as a working Codex marketplace. It publishes a marketplace manifest at .agents/plugins/marketplace.json, which points at mirrored installable plugin bundles stored under ./plugins/. That means you can clone the repo and point Codex directly at it as a plugin source, rather than just reading a list and installing things by hand.
The list itself is organized into sections: Start Here, Official Plugins, Community Plugins, Plugin Development, Guides & Articles, Related Projects, Claim Your Plugin, Plugin Trust Scores, Plugin Quality, and Contributing. It's built on the standard awesome-list format, but the scanner gate is what separates it from the pile of other README-driven lists out there.
Why It's Cool
-
The security scan is mandatory, not decorative. Plenty of curated lists mention that they "review" submissions. This one publishes a numeric threshold: a centralized score of 80 or higher out of 130. That's a concrete bar you can point at when someone asks why a plugin isn't listed.
-
You can use it as an actual marketplace. The
marketplace.jsonfile under.agents/pluginsisn't just documentation—it makes the repo installable as a Codex plugin source. You add the repo once via the CLI, and then you're browsing plugins through Codex's own tooling instead of copying and pasting install instructions from a markdown file. -
There's a preflight path for plugin authors. Before you submit anything, you can run the scanner locally. The README suggests
pipx run plugin-scanner lint .andpipx run plugin-scanner verify ., which means you find out whether you'd pass before you open a pull request. That's a small thing, but it saves everyone time. -
CI gating on your own repo is optional but recommended. The list requires the centralized scan for admission, but it also points to a HOL scanner GitHub Action you can wire into your source repo. The README is explicit that source-repo CI is recommended for pre-submission feedback but not required. I appreciate that honesty—it doesn't pretend the action is a hard gate when it isn't.
-
It acknowledges that Codex and ChatGPT are converging. The README notes that Codex now lives inside the ChatGPT desktop app while remaining a distinct coding workspace, and that OpenAI plugins can support ChatGPT, Codex, or both. The repo positions itself as a Codex-compatible marketplace rather than pretending the distinction doesn't exist.
How to Try It
The simplest path is to browse the list on GitHub and read through the categories. If you want to use it as a marketplace source in Codex, the README gives you the CLI setup:
- Add the repo as a marketplace source (one-time setup):
codex plugin marketplace add \
'https://github.com/hashgraph-online/awesome-codex-plugins.git' \
--ref 'main' \
--sparse '.agents/plugins' \
--sparse 'plugins'
- Then browse and install. The marketplace name is derived from the repo name:
codex plugin list
If you're building a plugin and want to check it before submitting, run the preflight commands from the Start Here section:
pipx run plugin-scanner lint .
pipx run plugin-scanner verify .
The repo also links to SCANNER_GUIDE.md and CONTRIBUTING.md for the full requirements. You can find everything at github.com/hashgraph-online/awesome-codex-plugins.
Final Thoughts
This is a niche project for a specific audience: developers who are already using Codex and want a plugin source they don't have to manually vet. The scanner requirement is the whole point—without it, this would just be another list. Whether the 80/130 threshold is the right number is a judgment call the maintainers have made, and it's a reasonable one. If you're plugin-curious but cautious about what you install, this is worth a look. If you're building plugins, the preflight tooling gives you a clear target to aim for.