JFrog plugin for OpenAI Codex: artifact management, security scanning, supply-chain best practices, and Agent Guard.
The JFrog plugin provides the following capabilities, grouped by component:
| Component | Feature | Description |
|---|---|---|
| MCP | JFrog MCP server | Bundled jfrog MCP server (.mcp.json) at https://<JFROG_PLATFORM_URL>/mcp; this server signs in via OAuth (codex mcp login jfrog), so it needs no API key. |
| Skill | JFrog Platform | Interact with Artifactory repositories, builds, permissions, users, access tokens, projects, release bundles, and platform administration via the JFrog CLI and REST/GraphQL APIs. Also covers security audits, CVE lookups, and Advanced Security exposure queries. |
| Skill | Package safety & download | Check whether npm, Maven, PyPI, Go, and other packages are safe, curated, or allowed, then download them through Artifactory remote caches or curation-aware package managers. |
| Skill | Agent Guard | Codex manages MCPs through the JFrog Agent Guard. Through the Agent Guard you can discover, install, configure, update, and remove MCP servers from the JFrog AI Catalog approved for your project, and authenticate to remote HTTP MCPs via OAuth, API key, or bearer token. |
Before installing, make sure you have:
- JFrog host URL and access token — Your JFrog platform URL and a valid access token.
- OpenAI Codex — Installed, with plugin support (
codex pluginCLI commands available). - Node.js (≥ 18) — with
npxon yourPATH(used by the Agent Guard). - Skill runtime requirements —
jfCLI,jq, andcurlonPATH, plus a configured JFrog instance. For the minimum versions, see the upstream skillsRequirements. Configure the CLI withjf config add— see Authentication. - JFrog AI Catalog (optional) — If you want to use the Agent Guard feature, your JFrog subscription needs to include the AI Catalog entitlement. Contact your JFrog account team if you're unsure whether it's enabled.
- JFrog CLI ≥ 2.105.0 (optional) — If you want the Agent Guard to auto-resolve the credentials/server ID from the JFrog CLI configuration.
- JFrog project (optional) — If you want to use the Agent Guard feature.
Add the JFrog marketplace and install the plugin with the Codex CLI:
codex plugin marketplace add jfrog/codex-plugin
codex plugin add jfrog@codex-pluginBrowse installed plugins in the Codex TUI with /plugins.
Test an uncommitted checkout without publishing. From (or pointing at) your clone
— the repo root is the marketplace root; .agents/plugins/marketplace.json
registers the jfrog plugin:
codex plugin marketplace add /path/to/codex-plugin
codex plugin add jfrog@codex-pluginConfigure the JFrog CLI so the skills and Agent Guard can reach your platform. Run
jf login for browser-based setup, or if you have never configured the JFrog CLI
on this machine:
-
Open your terminal.
-
Run:
jf config add
-
Follow the interactive prompts to enter your JFrog platform URL and access token.
The plugin bundles the jfrog MCP server (.mcp.json). After
installing, do two things:
- Set your host. Find the install path with
codex plugin list(thejfrog@codex-pluginrow) and edit<PATH>/.mcp.json. Replace<JFROG_PLATFORM_URL>in theurlwith your full JFrog Platform host — e.g.mycompany.jfrog.io(or your self-hosted / custom domain). - Log in (OAuth). Run
codex mcp login jfrogand finish the browser sign-in.
Restart Codex; the jfrog MCP server and its tools are now available (verify with
codex mcp list).
Once configured, interact with the JFrog plugin through natural language. Examples are grouped by capability.
| Ask the agent… | What happens |
|---|---|
| "List my Artifactory repositories." | Returns repositories via the JFrog CLI. |
| "Upload this build to Artifactory." | Publishes build artifacts and metadata. |
| "Run a security audit on this project." | Runs an Xray / Advanced Security audit and summarizes findings. |
| "Show me details on CVE-2021-23337." | Looks up CVE details in JFrog Advanced Security. |
| "Create a scoped access token for CI." | Creates an access token with the requested scope. |
| "Promote this release bundle to production." | Uses Lifecycle / Distribution APIs to promote the bundle. |
| Ask the agent… | What happens |
|---|---|
"Is lodash@4.17.21 safe to install?" |
Checks JFrog Public Catalog signals and curation policy for the package. |
| "Is this Maven package approved for use?" | Checks curation entitlement and policy for the requested package. |
"Download requests via JFrog." |
Resolves the package through an Artifactory remote cache or curation-aware package manager. |
| Ask the agent… | What happens |
|---|---|
| "Which MCP servers can I install?" | Returns all MCP servers approved for your current project that you can install. |
| "What MCP servers do I already have?" | Returns only the MCP servers already installed on your machine. |
| "Show me the details for the filesystem MCP server." | Returns detailed metadata, required configuration (environment variables, runtime arguments), and active tool policies for a given server. |
| "Add the GitHub MCP server." | Installs an approved MCP server and syncs its tool policies locally. Secrets are requested via a CLI command — never in chat. |
| "Update the environment variables for the Slack MCP." | Replaces the configuration for an already-installed server without removing and reinstalling it. |
| "Remove the Slack MCP server." | Removes the server and its stored credentials from your local setup. Changes apply immediately. |
| "Log in to the remote Jira MCP server using OAuth." | Authenticates with a remote HTTP-based MCP server (OAuth, API key, or bearer token). |
When an MCP server requires a sensitive configuration value, the agent cannot set it directly. Instead, it returns a CLI command for you to copy and run in your terminal. Secrets such as API keys, tokens, and connection strings are never exposed in the agent chat history.
See the JFrog MCP Registry troubleshooting guide.
The skills/ tree is vendored from
jfrog/jfrog-skills at the version
pinned in scripts/sync-skills-vendor.json.
To pull a newer upstream release into this repo:
-
Bump
pininscripts/sync-skills-vendor.jsonto the new tag (e.g.v0.23.0). -
Re-sync and commit the refreshed tree:
node scripts/sync-skills.mjs
It downloads the pinned tarball from
codeload.github.comand replaces the directories listed inpaths(today:skills/). -
Bump
versionin both.codex-plugin/plugin.jsonandpackage.json(they must match — CI enforces this) so the published plugin reflects the new skills bundle. -
Update the pinned-version link in the Prerequisites section so the skill runtime requirements point at the new tag.
-
Commit the pin bump, the regenerated
skills/tree, the version bump, and the README link bump together, and open a PR whose merge commit subject carries a[patch]/[minor]/[major]marker (see Releasing).
See VENDOR.md for the full picture.
Releases are cut automatically by .github/workflows/release.yml
when a commit lands on main whose subject line contains a
[major] / [minor] / [patch] marker. The workflow reads the version from
.codex-plugin/plugin.json (cross-checked against package.json), refuses to
re-release an existing tag, and publishes a GitHub Release v<version> with a
zipped artifact. A version is released only when both a manifest bump and a
marker commit reach main.
npm test # unit tests for the validator
npm run validate # lint manifests + skill frontmatter
See CONTRIBUTING.md for development workflow and
pull-request expectations.
See SECURITY.md for how to report vulnerabilities.
Licensed under the Apache License 2.0.