Skip to content

Latest commit

 

History

18 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

TruVerifAI panel-review for OpenAI Codex

⚙️ This repository is MACHINE-WRITTEN. It is generated and force-pushed by CI from the TruVerifAI product repo (plugin-core/). Hand edits are overwritten on the next release. To contribute or file issues, use the issue tracker here — but code changes happen upstream.

Multi-model second-opinion review for high-stakes code changes, with proactive review gates: a local classifier (running entirely on your machine) watches risky writes and git commits, and blocks them with a routing message until a four-frontier-model review covers the change.

Install

codex plugin marketplace add TruVerifAI/codex-plugins
codex plugin add panel-review@truverifai

Then connect your account by running the installer, which writes the working MCP entry into ~/.codex/config.toml and verifies the gates actually fire end-to-end:

npx @truverifai/init

The installer step is required, not optional: on current Codex releases (verified on codex-cli 0.146.0) a plugin's bundled MCP server definition is not activated, so the plugin alone cannot connect the review tools — the installer-written config.toml entry is what connects them. To do that part by hand instead: generate a tvai_… key at https://truverif.ai/settings/api-keys, then

codex mcp add truverifai --url https://mcp.truverif.ai/mcp --bearer-token-env-var TVAI_API_KEY

Type TVAI_API_KEY literally there: it is the NAME of an environment variable, not your key. The key itself goes only into the environment Codex runs in:

export TVAI_API_KEY="tvai_your_key_here"        # macOS / Linux
$env:TVAI_API_KEY = "tvai_your_key_here"        # Windows PowerShell

Codex reads the variable at connection time, so the secret never lands in config.toml. (bearer_token_env_var is Codex's supported way to read a token from the environment; a ${TVAI_API_KEY} placeholder inside a header value is NOT interpolated by Codex and would be sent to the server literally.)

What ships

  • MCP server connection — audit_coding, deliberate_coding, synthesize_coding, confirm_floor, record_outcome, record_gate_skip (plus the financial profile).
  • Review gates (PreToolUse hooks, beta on Codex): the write gate fires before a risky apply_patch/edit, the commit gate before a risky git commit. Both fail OPEN on any error — the gate never traps the agent.
  • Skills — when to audit, when to deliberate, when a fast synthesize is enough, outcome reporting, and gate-skip etiquette.

Privacy

The gates send TruVerifAI only a repo fingerprint + per-hunk content hashes — never source code, never file paths, never diffs. Reviews you invoke explicitly (audit_coding etc.) receive exactly what the agent passes them.

Notes for Codex users

  • Codex hooks are beta upstream; if a Codex update changes hook behavior, the gates fail open (never closed) until we ship a compatible release.
  • The gates deny via structured JSON with a routing message the model reads; a denied action is an instruction to run one review, not a dead end.

Docs: https://truverif.ai/settings/mcp · Changelog: ./CHANGELOG.md

About

TruVerifAI panel-review plugin for OpenAI Codex CLI - multi-model AI code-review gates over MCP.

Topics

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors