Context Guard icon

Context Guard

Preserves authoritative requirements and verification evidence across long-running Codex tasks and context compaction.

gerui-lv/context-guard · v0.13.9 · Development & Workflow

Gerui LvOwner verifiedreview

Trust Score

71

Security

71

Surfaces

1

What is Context Guard?

Context Guard is a published development & workflow plugin for AI coding agents in the codex ecosystem, developed by Gerui Lv and distributed through the HOL AI plugin registry. Preserves authoritative requirements and verification evidence across long-running Codex tasks and context compaction.

Canonical slug
gerui-lv/context-guard
Version
v0.13.9 · updated Sep 15, 2026

Trust & Reputation

HOL Trust Score
71

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
76pts
Maintenance
0pts
MCP Posture
100pts
Plugin Security
71pts
Provenance
70pts
Publisher Quality
75pts

Registry Snapshot

Publisher verification
No
Marketplace source
Unknown
Scanner
Broker fallback
Safety label
review
Digest verified
Yes
1 bundled skill — copy or download SKILL.mdOpen skills

Trust & reputation

Trust & Reputation

HOL Trust Score
71

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
76pts
Maintenance
0pts
MCP Posture
100pts
Plugin Security
71pts
Provenance
70pts
Publisher Quality
75pts

Provenance

Plugin root
plugins/GreenLv/codex-context-guard
Source repo
https://github.com/GreenLv/codex-context-guard
Source commit
ce667adefd71…
Publisher verified
No
Owner verified
@GreenLv

Continuous scanner CI detected

No action is required. This plugin receives the full trust score.

Verified badge not detected

Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.

Security Posture

review
Safety label
71
Security score
0
High findings
Provider
registry-broker-fallback
Grade
C · review
Version
Unknown
cisco-skill-scanner: unknown

Findings

mediumpublishabilitypublishability.asset.missing

Referenced asset is missing from the plugin package.

mediumpublishabilitypublishability.link.missing.termsOfServiceURL

termsOfServiceURL should be present for marketplace readiness.

lowoperational-securitysupply-chain.lockfile-missing

Repository snapshot does not include a lockfile.

infoskill-securityskill-scan.unavailable

Cisco skill scanner exited with code 1: Error loading skill: No SKILL.md and no .md files found in /var/folders/9z/48v7m0s52llddzmskkyjbdl80000gn/T/hol-skill-safety-7Rrkhu (lenient mode requires at least one markdown file)

Context Guard — Frequently asked questions

What is Context Guard?
Context Guard is an AI plugin in the HOL registry. Preserves authoritative requirements and verification evidence across long-running Codex tasks and context compaction.
How do I install Context Guard?
Install Context Guard in your harness: Codex — codex plugin marketplace add GreenLv/codex-context-guard; Any agent — npx skills add GreenLv/codex-context-guard. Full step-by-step guidance is on the HOL plugin page.
How do I install Context Guard in Codex?
To install Context Guard in Codex, start with codex plugin marketplace add GreenLv/codex-context-guard. The complete step-by-step install guide for Codex is on the HOL plugin page.
Is Context Guard free?
Pricing for Context Guard is published on its HOL plugin page when the maker schedules a launch.
Who publishes Context Guard?
Context Guard is published by Gerui Lv and listed on HOL.
Is Context Guard available now?
Context Guard availability is listed on its HOL plugin page.

Install Guidance

Install in Codex

Install through the Codex CLI plugin marketplace.

Codex plugin docs
  1. 1

    Register the marketplace

    Run in any terminal. Codex reads the marketplace entry from .agents/plugins/marketplace.json (or the legacy .claude-plugin path) in the repository. If the repository ships none, add the generated entry from the Advanced section below first.

    shell
  2. 2

    Install from the Plugins browser

    Open Codex, open the Plugins browser, choose the codex-context-guard marketplace, and install context-guard.

  3. 3

    Verify the marketplace registration

    shell

Plugin Manifest

{
  "name": "context-guard",
  "version": "0.13.9",
  "description": "Preserve task requirements and verify evidence, scope, surfaces, and multimodal assets across compaction.",
  "author": {
    "name": "Gerui Lv",
    "url": "https://github.com/GreenLv"
  },
  "homepage": "https://github.com/GreenLv/codex-context-guard",
  "repository": "https://github.com/GreenLv/codex-context-guard",
  "license": "Apache-2.0",
  "keywords": [
    "context",
    "compaction",
    "recovery",
    "long-running"
  ],
  "skills": "./",
  "interface": {
    "displayName": "Context Guard",
    "developerName": "Gerui Lv",
    "shortDescription": "Preserve long-task context across Codex compaction.",
    "composerIcon": "./assets/icon.svg",
    "longDescription": "Journals authoritative task requirements locally, records hash-only multimodal assets, enforces deterministic verification contracts when available, falls back audibly when unavailable, restores bounded context after compaction, and exports explicit successor packs.",
    "category": "Productivity",
    "capabilities": [
      "Lifecycle hooks",
      "Local task state",
      "Verification contracts",
      "Hash-only multimodal assets",
      "Compaction recovery",
      "Bounded plan mirror",
      "Delegated-agent provenance",
      "Bounded successor packs"
    ],
    "websiteURL": "https://github.com/GreenLv/codex-context-guard",
    "privacyPolicyURL": "https://github.com/GreenLv/codex-context-guard/blob/main/docs/PRIVACY.md",
    "defaultPrompt": "Use $context-guard to protect this long-running task from context loss."
  },
  "registryIndexVersion": 5
}

Marketplace Source

Repo URL
https://github.com/GreenLv/codex-context-guard
Marketplace path
Unknown
Source path
plugins/GreenLv/codex-context-guard
Install policy
AVAILABLE

Skills

Copy or download the SKILL.md files this plugin ships, then install them with the Skills CLI.

Share
skills-cli

context-guard

skills/context-guard/SKILL.md

Preserve authoritative task requirements, acceptance criteria, multimodal asset contracts, bounded native-plan state, delegated-agent results, and verified evidence across Codex context compaction. Use for long or complex tasks, Goal work, resumed sessions, subagent workflows, explicit context-guard controls, redacted or successor handoff exports, or whenever completion must be checked against an immutable local requirement ledger.

Raw SKILL.md
---
name: context-guard
description: Preserve authoritative task requirements, acceptance criteria, multimodal asset contracts, bounded native-plan state, delegated-agent results, and verified evidence across Codex context compaction. Use for long or complex tasks, Goal work, resumed sessions, subagent workflows, explicit context-guard controls, redacted or successor handoff exports, or whenever completion must be checked against an immutable local requirement ledger.
---

# Context Guard

Use the plugin's private requirement ledger and verified evidence to preserve
correctness across long tasks. Codex owns Plan, Goal, compaction, subagents,
permissions, worktrees, transcripts, and memories; this Skill does not replace
those controllers.

## Preserve the current work unit

- Treat an injected recovery packet as the authoritative recovery index. Keep
  requirement and acceptance IDs in private planning and completion checks.
  Later root-user corrections are explicit supersessions, not silent rewrites.
- A whole completion must cover every non-superseded required item in the
  current work unit and its required descendants. Ancestor requirements remain
  constraints; historical unresolved work does not automatically reopen the
  current unit. Pending, failed, blocked, or unsupported required items remain
  incomplete. A passed child or subagent cannot prove parent completion.
- Cite implementation, execution, artifact creation, and verified results as
  separate facts. Prior authenticated passes carry forward when still valid;
  a new turn invalidates unused completion attempts, not durable evidence.
- Private-state integrity failures block acceptance. Reconstructed requirements
  return to pending and need fresh evidence.
- The recovered Codex plan is a read-only mirror. Update the native plan through
  Codex tools; mirror health is diagnostic and grants no execution authority.
  Memories are recall, not authority. Keep durable repository rules in checked-in
  policy unless the user makes them requirements of the current task.

## End ordinary turns normally

Ordinary verifiable completion needs no commands: the guard binds unique
successful evidence to the current unit. Progress, clarification, status, and
valid waiting/deferred replies end silently without closing unfinished work.
Continue authorized assistant work with tools before ending a turn.

Allow paths are silent. Do not wait for, narrate, or fabricate a receipt. A
Stop correction can interrupt a turn at most once; unresolved work then remains
pending. Never expose private checkpoints, commands, parameter bindings,
requirement maps, tokens, or plugin data paths in the reply.

Read [advanced-completion.md](references/advanced-completion.md) before an
explicit completion audit, ambiguous evidence selection, or an enforced
visual, result-readback, UI, or exact-scope proof. It contains the optional
`checkpoint-status`, `register-proof`, `stage-checkpoint`, and
`stage-disposition` paths. Do not invoke them merely because this Skill loaded.
A visual tool's successful return alone proves no visual fact.

## Respect responsibility boundaries

0.13 splits responsibilities explicitly. The executing agent owns whether an
action is within the user's authorization: it reads the real conversation,
repository rules, and host permissions, and proceeds without re-asking when
the user already said so. Context Guard's default path (`standard`/`strict`)
never vetoes ordinary edits, tests, commits, pushes, or tags; a Guard allow is
not authorization, and Guard never re-asks for an authorization because a
work unit, tool wrapper, or observation changed. `strict` adds enforced
current-unit proof obligations; it is not a Git-approval gate.

Release enforcement activates only through an explicit adoption of a release
execution contract or an explicit `context-guard release` declaration. Loading
Skills, installing the plugin, finding a manifest, or a release-flavored task
text never implies adoption. Under the release profile, tier-A identity
actions (tags, registry publish/yank, GitHub Releases) still need an exact
unexpired one-shot ticket, and opaque runner envelopes or unresolvable targets
fail closed. `observe` records bounded would-results without blocking; `off`
and inactive sessions gate nothing. Platform approvals remain independent,
and tools without Hook events remain outside Hook coverage.

A root-user request to push authorizes an ordinary push: resolve its exact
repository, remote, and ref from the request and unique repository state, and
execute without asking the user to repeat it. A normal push does not
authorize force-push, branch deletion, or release publication; those need
their own explicit user decision. Cleanup does not silently become product
implementation; the user's stated restrictions remain recoverable
requirements that the agent must honor.

For release tickets, profile details, migration, or adoption diagnosis, read
[authority-and-controls.md](references/authority-and-controls.md). The release
profile's exact candidate/readiness/ticket checks remain mandatory.

## Delegated results

A delegation prompt defines delegated scope, not a root-user requirement or
supersession. Its wrapper is authoritative as a delegation only when runtime
metadata or a running subagent corroborates it. Follow the injected bounded
contract and return `Outcome`, `Evidence`, `Validation`, `Limitations`, and
`Next`. Return evidence-bearing conclusions and artifacts, never transcripts
or hidden reasoning. The parent owns integration and whole-task acceptance.

## Controls and privacy

`$context-guard` or `context-guard on` activates protection;
`context-guard off` stops recovery and completion gating while journaling
continues. `context-guard status` and `context-guard diagnose` provide bounded
state and diagnostics. Read [authority-and-controls.md](references/authority-and-controls.md)
for explicit adoption, export, or successor-pack requests; read
[successor-pack.md](references/successor-pack.md) before preparing rollover input.
Creating a successor task always remains a separate authorized action.

The immutable raw prompt ledger is the fact source; summaries and checkpoints
are derived indexes. Never commit raw prompts, transcripts, private plugin
state, proofs, credentials, tokens, or caches. Multimodal state keeps bounded
metadata, hashes, dimensions, availability, and redacted facts, not image bytes.
Export only when explicitly requested, with redaction by default. Do not weaken
the advanced proof, integrity, private-control, or authority rules when moving
between ordinary and advanced paths.

File Inventory

.codex-plugin/plugin.json

plugin-manifest

1,421 bytes

734902baa35eaa50

hooks/hooks.json

file

24,282 bytes

fec4c7fac22cbf5b

skills/context-guard/SKILL.md

skill

6,663 bytes

a5c942b2be979c81

skills/context-guard/agents/openai.yaml

skill

209 bytes

d1c796d059e38392

skills/context-guard/references/advanced-completion.md

skill

4,348 bytes

6ba057a05bef1425

skills/context-guard/references/authority-and-controls.md

skill

7,379 bytes

c847dd4ecd3667d3

skills/context-guard/references/successor-pack.md

skill

1,740 bytes

29775e0a6d131ea8

History, reviews, and alternatives

Latest launch

User reviews

from 0 reviews

The first substantive review can be added on this page.

Read or write reviews

Milestones and alternatives

Makers can publish releases and security milestones after claiming the plugin.