Skip to content
Back to skills

Marginal

ASecurity

Use when inspecting, reviewing, promoting, demoting, or explaining MARGINAL governance in Codex, especially for repeated tool work, token-saving claims, and Earned Enforcement readiness.

  • 17 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
ai-agentspythonrustgo

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 19, 2026

npx -y skills add SignalLayerLabs/Marginal --skill marginal --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Marginal?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Marginal
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/signallayerlabs-marginal/badge)](https://www.skillsdirectory.com/skills/signallayerlabs-marginal)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: marginal
description: Use when inspecting, reviewing, promoting, demoting, or explaining MARGINAL governance in Codex, especially for repeated tool work, token-saving claims, and Earned Enforcement readiness.
---

# MARGINAL

Treat compute as scarce and claims as evidence-bound. The plugin starts globally in Shadow Mode;
it may exercise repository-scoped Tool Enforcement only after a valid Earned Enforcement receipt
and explicit promotion.

## Native control

Do not require a global `marginal` executable or a pip installation. Resolve the native plugin:

1. Run `codex plugin list --json`.
2. Select the exact `pluginId` `marginal@marginal` and read its `source.path` as the plugin root.
3. On macOS/Linux, run `python3 <plugin-root>/scripts/marginal_control.py COMMAND`; on Windows,
   run `py -3 <plugin-root>\scripts\marginal_control.py COMMAND`.

Pass `--workspace <repository>` and `--json` when inspecting repository-scoped state. The launcher
uses Codex's native plugin data directory, so hook evidence and control commands share one state.
It automatically replaces an older `python3` with an available Python 3.10–3.13 interpreter. If
none is installed, report that exact runtime requirement and do not claim hooks are operational.

## Workflow

1. Run the native `status` command before describing the active mode.
2. Read live operation, prior evidence, and enforcement as separate facts:
   - `hooks_active: true` attests a live authenticated MARGINAL lifecycle service for this
     repository. It is the strongest available operational signal, but does not expose or prove a
     raw chat session identity.
   - `hooks_observed: true` proves lifecycle evidence exists for this repository, even when no
     session is currently live.
   - `hooks_observed: false` means not yet observed, not that hooks are disabled. Use `/hooks` to
     review and trust the exact definitions, perform a tool action, then run `status` again.
   - `mode` reports `shadow` or repository-scoped `enforce`; installation alone never implies
     enforcement.
3. Run `doctor` when hooks, coverage, or compatibility remain uncertain.
4. Run `review`, then label each local redacted candidate with
   `--candidate HASH --verdict waste|helpful` before promotion.
5. Run `promote` only when the evidence receipt is ready.
6. Run `demote` whenever identity, coverage, outcome observability, or policy drifts.

## Claims contract

- Say **Tool Enforcement**, never Full Compute Enforcement.
- Describe recommendations as counterfactual until an enforced run measures them.
- Never claim token savings without a matched benchmark that reports quality and governance tax.
- Treat `PostToolUse` as completion, not success; prose-only outcomes remain unknown.
- Never read Codex auth files, prompts, source, raw commands, raw outputs, or transcripts for evidence.

## Quick reference

| Need | Command |
| --- | --- |
| Current mode and hook evidence | `python3 <plugin-root>/scripts/marginal_control.py status --workspace <repo> --json` |
| Capability diagnosis | `python3 <plugin-root>/scripts/marginal_control.py doctor --json` |
| Unreviewed evidence | `python3 <plugin-root>/scripts/marginal_control.py review --workspace <repo> --json` |
| Evidence-gated enforcement | `python3 <plugin-root>/scripts/marginal_control.py promote --workspace <repo> --json` |
| Immediate fail-open reset | `python3 <plugin-root>/scripts/marginal_control.py demote --workspace <repo> --json` |

If evidence is incomplete or contradictory, keep Shadow Mode and report the exact blocking reason.

Files in this skill

  • SKILL.md3.5 KB
  • agents/openai.yaml234 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…