HOTL Plugin icon

HOTL Plugin

Human-on-the-Loop AI coding workflow plugin for Codex, Claude Code, and Cline with structured planning, review, and verification guardrails.

yiming-wu/hotl · v2.22.0 · Development & Workflow

Yiming WuOwner verifiedreview

Trust Score

66

Security

71

Surfaces

20

What is HOTL Plugin?

HOTL Plugin is a published development & workflow plugin for AI coding agents in the claude-code ecosystem, developed by Yiming Wu and distributed through the HOL AI plugin registry. Human-on-the-Loop AI coding workflow plugin for Codex, Claude Code, and Cline with structured planning, review, and verification guardrails.

Canonical slug
yiming-wu/hotl
Version
v2.22.0 · updated Sep 20, 2026

Trust & Reputation

HOL Trust Score
66

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
76pts
Maintenance
30pts
MCP Posture
100pts
Plugin Security
71pts
Provenance
70pts
Publisher Quality
75pts

Registry Snapshot

Publisher verification
No
Marketplace source
Unknown
Scanner
Broker fallback
Safety label
review
Digest verified
Yes
20 bundled skills — copy or download SKILL.mdOpen skills

Trust & reputation

Trust & Reputation

HOL Trust Score
66

Factor Analysis

Per-metric points (0–100 each) combined via a weighted average into the overall score.

Installability
76pts
Maintenance
30pts
MCP Posture
100pts
Plugin Security
71pts
Provenance
70pts
Publisher Quality
75pts

Provenance

Plugin root
.
Source repo
https://github.com/yimwoo/hotl-plugin
Source commit
d86bf87181ad…
Publisher verified
No
Owner verified
@yimwoo

Continuous scanner CI not detected

This plugin remains listed. Its overall trust score is reduced by 10% because security checks are not maintained in the source repository's CI.

Optional: maintain the scanner in the source repository's CI to receive the full trust score. Listing does not require that change.

Verified badge not detected

Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.

Security Posture

review
Safety label
71
Security score
0
High findings
Provider
registry-broker-fallback
Grade
C · review
Version
Unknown
cisco-skill-scanner: unknown

Findings

mediumpublishabilitypublishability.link.missing.privacyPolicyURL

privacyPolicyURL should be present for marketplace readiness.

mediumpublishabilitypublishability.link.missing.termsOfServiceURL

termsOfServiceURL should be present for marketplace readiness.

lowoperational-securitysupply-chain.lockfile-missing

Repository snapshot does not include a lockfile.

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

infoskill-securityskill-scan.unavailable

Cisco skill scanner timed out after 60000 ms

HOTL Plugin — Frequently asked questions

What is HOTL Plugin?
HOTL Plugin is an AI plugin in the HOL registry. Human-on-the-Loop AI coding workflow plugin for Codex, Claude Code, and Cline with structured planning, review, and verification guardrails.
How do I install HOTL Plugin?
Install HOTL Plugin in your harness: Codex — codex plugin marketplace add yimwoo/hotl-plugin; Claude Code — /plugin marketplace add yimwoo/hotl-plugin; Cursor — npx skills add yimwoo/hotl-plugin. Full step-by-step guidance is on the HOL plugin page.
How do I install HOTL Plugin in Codex?
To install HOTL Plugin in Codex, start with codex plugin marketplace add yimwoo/hotl-plugin. The complete step-by-step install guide for Codex is on the HOL plugin page.
How do I install HOTL Plugin in Claude Code?
To install HOTL Plugin in Claude Code, start with /plugin marketplace add yimwoo/hotl-plugin. The complete step-by-step install guide for Claude Code is on the HOL plugin page.
How do I install HOTL Plugin in Cursor?
To install HOTL Plugin in Cursor, start with npx skills add yimwoo/hotl-plugin. The complete step-by-step install guide for Cursor is on the HOL plugin page.
Is HOTL Plugin free?
Pricing for HOTL Plugin is published on its HOL plugin page when the maker schedules a launch.
Who publishes HOTL Plugin?
HOTL Plugin is published by Yiming Wu and listed on HOL.
Is HOTL Plugin available now?
HOTL Plugin availability is listed on its HOL plugin page.

Install Guidance

Install in Claude Code

Install through the Claude Code plugin marketplace.

Claude Code plugin docs
  1. 1

    Add the marketplace

    Run this inside a Claude Code session.

    claude code
  2. 2

    Install the plugin

    Use the plugin name and the marketplace name shown by the previous command.

    claude code
  3. 3

    Scripted alternative

    Non-interactive equivalent for scripts and CI pipelines. Add --scope project to pin the install to one repository.

    shell

Plugin Manifest

{
  "name": "hotl",
  "description": "Structured guardrails for AI coding: brainstorm, plan, execute, review, and verify.",
  "version": "2.22.0",
  "author": {
    "name": "Yiming Wu"
  },
  "homepage": "https://github.com/yimwoo/hotl-plugin",
  "repository": "https://github.com/yimwoo/hotl-plugin",
  "license": "MIT",
  "keywords": [
    "hotl",
    "human-on-the-loop",
    "codex-plugin",
    "claude-code",
    "ai-coding-assistant",
    "code-review",
    "pr-review",
    "developer-tools",
    "guardrails",
    "workflows",
    "ai-native",
    "tdd",
    "verification",
    "skills"
  ],
  "skills": "./",
  "interface": {
    "displayName": "HOTL",
    "developerName": "Yiming Wu",
    "shortDescription": "Plan, execute, review, and verify AI-generated code changes.",
    "longDescription": "HOTL adds structure to AI coding work. Use it to clarify intent, generate a workflow plan, execute with verification, review the result, and prove the change is ready before it lands on main. Includes skills for brainstorming, plan execution, PR review, code review, and final verification.",
    "category": "Productivity",
    "capabilities": [
      "Interactive",
      "Read",
      "Write"
    ],
    "defaultPrompt": [
      "Design and plan this feature before coding",
      "Review this pull request",
      "Run this hotl-workflow file"
    ],
    "websiteURL": "https://github.com/yimwoo/hotl-plugin",
    "brandColor": "#0F6E56",
    "composerIcon": "./docs/assets/codex/hotl-icon.png",
    "logo": "./docs/assets/codex/hotl-logo.png"
  },
  "registryIndexVersion": 5
}

Marketplace Source

Repo URL
https://github.com/yimwoo/hotl-plugin
Marketplace path
Unknown
Source path
plugins/yimwoo/hotl-plugin
Install policy
AVAILABLE

Skills

20 SKILL.md files ship with this plugin. Preview, copy, or download each one, then install them with the Skills CLI.

Share
skills-cli
  • brainstorming

    skills/brainstorming/SKILL.md

    Use before any feature work — explores intent, requirements, and design. Produces HOTL contracts (intent, verification, governance) before implementation.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • code-review

    skills/code-review/SKILL.md

    Use after completing implementation steps and before merging — reviews against plan and HOTL contracts.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • dispatch-agents

    skills/dispatch-agents/SKILL.md

    Use when you have 2+ independent tasks with no shared state — dispatches parallel subagents for each task.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • document-review

    skills/document-review/SKILL.md

    Optional utility for reviewing existing docs, external specs, hand-authored notes, or non-HOTL documents. HOTL design docs and workflows get structural lint + AI review; other documents get AI-only review with a generic rubric.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • executing-plans

    skills/executing-plans/SKILL.md

    Use when executing an implementation plan linearly with explicit human checkpoints between batches of tasks.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • finishing-a-development-branch

    skills/finishing-a-development-branch/SKILL.md

    Use after execution is complete or intentionally stopped — decide whether to merge back, publish a PR branch, keep the execution checkout, or discard it, and record that disposition in HOTL state.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • governed-execution

    skills/governed-execution/SKILL.md

    Use when executing an accepted HOTL workflow through the best available host or fallback driver.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • loop-execution

    skills/loop-execution/SKILL.md

    Use when executing an existing HOTL workflow file — reads steps, loops until success criteria met, auto-approves low-risk gates, pauses at high-risk gates.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • pr-reviewing

    skills/pr-reviewing/SKILL.md

    Review a PR across multiple dimensions — description, code changes, code scan, unit tests — using parallel subagents. Supports GitHub, GitLab, and enterprise platforms.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • receiving-code-review

    skills/receiving-code-review/SKILL.md

    Use when review findings arrive — verify each claim against the codebase and HOTL contracts before making changes. Governs how agents respond to review feedback.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • requesting-code-review

    skills/requesting-code-review/SKILL.md

    Use at executor review checkpoints to dispatch the code-reviewer agent with structured context — git range, workflow contracts, and verification evidence.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • resuming

    skills/resuming/SKILL.md

    Resume an interrupted workflow run with verify-first strategy — loads sidecar state, verifies the last step, and continues execution.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • setup-project

    skills/setup-project/SKILL.md

    Use to generate HOTL adapter files for the current project — creates AGENTS.md, .clinerules, cursor rules, or copilot instructions depending on tools the team uses.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • skill-authoring

    skills/skill-authoring/SKILL.md

    Use when creating, editing, or reviewing HOTL skills, agents, command prompts, or other behavior-shaping instruction files.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • subagent-execution

    skills/subagent-execution/SKILL.md

    Delegated step runner over the HOTL execution state machine — delegates eligible steps to fresh subagents while the controller keeps governance, verification, and stop conditions.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • systematic-debugging

    skills/systematic-debugging/SKILL.md

    Use when encountering any bug, test failure, or unexpected behavior — before proposing fixes.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • tdd

    skills/tdd/SKILL.md

    Use before writing any implementation code — enforces RED-GREEN-REFACTOR cycle.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • using-hotl

    skills/using-hotl/SKILL.md

    Use when the user explicitly asks for HOTL routing or needs guidance choosing the right HOTL workflow skill.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • verification-before-completion

    skills/verification-before-completion/SKILL.md

    Use before claiming any work is complete, fixed, or passing — runs verification commands and confirms output before making success claims.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

  • writing-plans

    skills/writing-plans/SKILL.md

    Use after design approval to create a dated executable workflow file with bite-sized tasks, exact file paths, and loop/gate definitions.

    SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.

File Inventory

.claude-plugin/plugin.json

file

521 bytes

5a1955426839e33c…

.codex-plugin/plugin.json

plugin-manifest

1,343 bytes

e1c3af214360fa9a…

.cursor-plugin/plugin.json

file

578 bytes

04f70264ef19a4fe…

agents/code-reviewer.md

file

5,924 bytes

4fc1a18b6037fe9f…

commands/brainstorm.md

file

194 bytes

689e8a9fb195283a…

commands/check-update.md

file

408 bytes

a844e893a6d15305…

commands/execute-plan.md

file

189 bytes

93c52a16b2dc953e…

commands/loop.md

file

195 bytes

ed756182cd1d98da…

commands/pr-review.md

file

313 bytes

6a2ae2a02a23e41a…

commands/resume.md

file

166 bytes

f605d09e57fb0494…

commands/setup.md

file

225 bytes

a0d85d25a35e9c3b…

commands/subagent-execute.md

file

251 bytes

1d6e6921b237ef80…

commands/write-plan.md

file

228 bytes

af16a0a6a1bfbc4a…

docs/assets/codex/hotl-icon.png

file

18,072 bytes

dbd666bca74f3b33…

docs/assets/codex/hotl-logo.png

file

17,556 bytes

440e29694345e481…

hooks/hooks-cursor.json

file

137 bytes

53d8ceb3ff5d8bb1…

hooks/hooks.json

file

305 bytes

01616c57b96cc234…

README.md

file

19,684 bytes

1bdc06f70376097b…

skills/brainstorming/SKILL.md

skill

11,703 bytes

e76db7491a418c83…

skills/code-review/SKILL.md

skill

6,584 bytes

c3d1f99336dfe339…

skills/dispatch-agents/SKILL.md

skill

1,058 bytes

6c4072e961f9db37…

skills/document-review/SKILL.md

skill

8,967 bytes

6189c6d9bc8f37df…

skills/executing-plans/SKILL.md

skill

13,562 bytes

0ce9ded0721e6f29…

skills/finishing-a-development-branch/SKILL.md

skill

5,554 bytes

60a17109540d5726…

skills/governed-execution/SKILL.md

skill

4,335 bytes

225fda9d67a0e596…

skills/loop-execution/SKILL.md

skill

27,117 bytes

762d8633d78c31ee…

skills/pr-reviewing/SKILL.md

skill

11,694 bytes

74566b343002b48f…

skills/receiving-code-review/SKILL.md

skill

3,421 bytes

26516fda8327b9e4…

skills/requesting-code-review/SKILL.md

skill

3,969 bytes

5b4d8884bb353b40…

skills/resuming/SKILL.md

skill

8,833 bytes

65e8e9d4436f7021…

skills/setup-project/SKILL.md

skill

6,254 bytes

8ed085c18ccef1ec…

skills/skill-authoring/SKILL.md

skill

3,300 bytes

679ba5c6b5f41b9b…

skills/subagent-execution/SKILL.md

skill

9,466 bytes

2f1416a66938c7ee…

skills/systematic-debugging/SKILL.md

skill

1,033 bytes

cb5421eab7949c6d…

skills/tdd/SKILL.md

skill

966 bytes

b285f5fb86b39a52…

skills/using-hotl/agents/openai.yaml

skill

266 bytes

15a4e654c8077e47…

skills/using-hotl/SKILL.md

skill

3,977 bytes

1fafde6a32b6ab76…

skills/verification-before-completion/SKILL.md

skill

866 bytes

87b76468dcbdcac8…

skills/writing-plans/SKILL.md

skill

11,975 bytes

269f7090f26057d3…