ArmorCodex icon

ArmorCodex

Intent-based security for Codex with MCP plan registration, policy gating, CSRG cryptographic proofs, and audit logging on `bash` and `apply_patch`.

armoriq/armorcodex · v0.3.2 · Development & Workflow

ArmorIQOwner verifiedsafe

Trust Score

92

Security

100

Surfaces

1

What is ArmorCodex?

ArmorCodex is a published development & workflow plugin for AI coding agents in the mcp ecosystem, developed by ArmorIQ and distributed through the HOL AI plugin registry. Intent-based security for Codex with MCP plan registration, policy gating, CSRG cryptographic proofs, and audit logging on `bash` and `apply_patch`.

Canonical slug
armoriq/armorcodex
Version
v0.3.2 · updated Oct 3, 2026

Trust & Reputation

HOL Trust Score
92

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
100pts
Maintenance
100pts
MCP Posture
100pts
Plugin Security
100pts
Provenance
70pts
Publisher Quality
75pts

Registry Snapshot

Publisher verification
No
Marketplace source
Unknown
Scanner
Broker fallback
Safety label
safe
Digest verified
Yes

Trust & reputation

Trust & Reputation

HOL Trust Score
92

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
100pts
Maintenance
100pts
MCP Posture
100pts
Plugin Security
100pts
Provenance
70pts
Publisher Quality
75pts

Provenance

Plugin root
plugins/armorcodex
Source repo
https://github.com/armoriq/armorCodex
Source commit
65bcd5a79c48…
Publisher verified
No
Owner verified
@Harihara04sudhan

Scanner CI check is still running

No action is required. This listing will update after the catalog rechecks scanner CI.

README badge check is still running

No action is required. This listing will update after the catalog rechecks the source README.

Security Posture

safe
Safety label
100
Security score
0
High findings
Provider
registry-broker-fallback
Grade
A · safe
Version
Unknown
cisco-skill-scanner: not_applicable

Findings

No normalized findings were returned for this plugin.

ArmorCodex — Frequently asked questions

What is ArmorCodex?
ArmorCodex is an AI plugin in the HOL registry. Intent-based security for Codex with MCP plan registration, policy gating, CSRG cryptographic proofs, and audit logging on `bash` and `apply_patch`.
How do I install ArmorCodex?
Install ArmorCodex in your harness: Codex — codex plugin marketplace add armoriq/armorCodex; MCP — git clone https://github.com/armoriq/armorCodex. Full step-by-step guidance is on the HOL plugin page.
How do I install ArmorCodex in Codex?
To install ArmorCodex in Codex, start with codex plugin marketplace add armoriq/armorCodex. The complete step-by-step install guide for Codex is on the HOL plugin page.
How do I install ArmorCodex in MCP?
To install ArmorCodex in MCP, start with git clone https://github.com/armoriq/armorCodex. The complete step-by-step install guide for MCP is on the HOL plugin page.
Is ArmorCodex free?
Pricing for ArmorCodex is published on its HOL plugin page when the maker schedules a launch.
Who publishes ArmorCodex?
ArmorCodex is published by ArmorIQ and listed on HOL.
Is ArmorCodex available now?
ArmorCodex availability is listed on its HOL plugin page.

Install Guidance

Install in Codex

Install through the Codex CLI plugin marketplace.

Codex plugin docs
  1. 1

    Register the marketplace

    Run in any terminal. Codex reads the marketplace entry from .agents/plugins/marketplace.json (or the legacy .claude-plugin path) in the repository. If the repository ships none, add the generated entry from the Advanced section below first.

    shell
  2. 2

    Install from the Plugins browser

    Open Codex, open the Plugins browser, choose the armorCodex marketplace, and install armorcodex.

  3. 3

    Verify the marketplace registration

    shell

Plugin Manifest

{
  "name": "armorcodex",
  "version": "0.3.2",
  "description": "ArmorIQ intent-based security enforcement for Codex: Bash command guardrails with intent verification, optional CSRG cryptographic proofs, and audit logging. Codex hooks currently fire for Bash, apply_patch, and MCP tool calls; non-Bash file/web activity may need supplemental controls. See CODEX_HARNESS_LIMITATIONS.md.",
  "author": {
    "name": "ArmorIQ",
    "email": "[email protected]",
    "url": "https://armoriq.ai"
  },
  "homepage": "https://armoriq.ai",
  "repository": "https://github.com/armoriq/armorCodex",
  "license": "MIT",
  "keywords": [
    "security",
    "policy",
    "audit",
    "intent",
    "armoriq",
    "mcp",
    "hooks"
  ],
  "hooks": "./.codex/hooks.json",
  "mcpServers": "./.registry/mcp.json",
  "interface": {
    "displayName": "ArmorCodex",
    "developerName": "ArmorIQ",
    "shortDescription": "Intent-based security policy and audit for Codex.",
    "longDescription": "ArmorIQ intent-based security enforcement for OpenAI Codex. Treat as a strong Bash guardrail and audit layer, not a complete boundary for every Codex capability. Codex hooks currently emit Bash, apply_patch, and MCP tool calls. ArmorCodex provides plan registration through MCP, intent-plan matching, permission gating, and post-run audit on those tools. Non-Bash activity (file edits, web search, app connectors) is gated where Codex emits hook events.",
    "category": "Security",
    "capabilities": [
      "MCP",
      "Hooks"
    ],
    "websiteURL": "https://armoriq.ai",
    "privacyPolicyURL": "https://armoriq.ai/privacy-policy",
    "termsOfServiceURL": "https://armoriq.ai/terms-of-service",
    "brandColor": "#00E5CC",
    "composerIcon": "./assets/armoriq-logo.png",
    "logo": "./assets/armoriq-logo.png",
    "defaultPrompt": [
      "Show me what security rules are protecting this project.",
      "Block any commands that fetch URLs or exfiltrate data.",
      "Walk me through your plan before running anything."
    ]
  },
  "userConfig": {
    "api_key": {
      "type": "string",
      "title": "ArmorIQ API Key",
      "description": "Your ArmorIQ API key (get one at https://armoriq.ai). Leave blank to run in local-only mode without backend audit/intent.",
      "sensitive": true
    },
    "mode": {
      "type": "string",
      "title": "Enforcement Mode",
      "description": "enforce = block on policy/intent failures (recommended). monitor = log only, never block.",
      "sensitive": false
    },
    "intent_required": {
      "type": "boolean",
      "title": "Require Intent Plan",
      "description": "When true, every Bash command must be backed by a registered intent plan (Codex hooks currently only intercept Bash). Disable for advisory-only use.",
      "sensitive": false
    },
    "crypto_policy_enabled": {
      "type": "boolean",
      "title": "Enable Crypto Policy Binding",
      "description": "Bind policy rules to a Merkle tree so post-issuance tampering is detected.",
      "sensitive": false
    },
    "use_production": {
      "type": "boolean",
      "title": "Use Production Endpoints",
      "description": "When true, talks to ArmorIQ production. When false, expects a local backend on 127.0.0.1.",
      "sensitive": false
    }
  },
  "registryIndexVersion": 5
}

Marketplace Source

Repo URL
https://github.com/armoriq/armorCodex
Marketplace path
Unknown
Source path
plugins/armoriq/armorCodex
Install policy
AVAILABLE

File Inventory

.codex-plugin/plugin.json

plugin-manifest

2,862 bytes

8e0cc21c54a2f946…

.codex/hooks.json

file

1,922 bytes

bda3948335a18b4e…

.mcp.json

file

135 bytes

6c4f9e3621ba07c0…

.registry/mcp.json

mcp-config

96 bytes

769c471da05c5152…

assets/armoriq-logo.png

asset

9,292 bytes

bfedc70745374a3c…

hooks/hooks.json

file

1,561 bytes

f1fee5d46aa4130c…

package-lock.json

file

47,355 bytes

2c0cc70301233534…

package.json

file

451 bytes

bfd41601eb72db9a…

README.md

file

1,677 bytes

5b18b43b5be08c22…

SECURITY.md

file

1,250 bytes

9994da5baab1eff3…