ccdwyer/inline-tribunal

ccdwyer/inline-tribunal

提供 second_opinion 工具和 /tribunal [--base <ref>] [focus] 命令,将当前 git diff 发送给 Codex 和 Grok,进行并排审查,并给出 SHIP / SHIP AFTER FIXES / REWORK 判定。审查者在沙箱中运行:每个席位都会得到一个空的临时 HOME;Codex 使用 -s read-only、--ephemeral、--ignore-user-config 和 --ignore-rules 运行,Grok 使用 --deny '*'、--no-subagents 和 --disable-web-search 运行;二者都在全新的 /tmp 目录中操作。敏感文件(.env*、密钥、凭据)不会被发送,形似凭据的值也会在发送 diff 前被脱敏。需要 PATH 中存在 codex 和/或 grok;模型、effort、diff 大小和超时均可配置。
请先查看作者 README 确认 marketplace 和插件名称;命令可能随仓库结构改变。
claude plugin marketplace add ccdwyer/inline-tribunal claude plugin install inline-tribunal

A Claude Code mod that has your current change reviewed by Codex and Grok side by side, without leaving the session.
second_opinion tool. Claude can call it itself, for example before declaring risky work done. It takes an optional focus, and an optional base, such as main, to review the branch since its merge base. The tool returns each reviewer's findings and verdict (SHIP / SHIP AFTER FIXES / REWORK) as its result, so Claude can act on them./tribunal [--base <ref>] [focus]. The same review, run by you. It runs immediately, even mid-turn. If the working tree is clean, it reviews the branch against origin's default branch, or against defaultBase if you set it.The reviewers see the diff and nothing else. Testing showed that a temp working directory and the CLIs' usual flags were not enough: both CLIs could still read arbitrary files. So each seat is locked down explicitly:
HOME (and CODEX_HOME / GROK_HOME) points at a fresh temp home that holds only a link to that CLI's login. None of your MCP servers, plugins, hooks, skills, global rules, memories or always-approve settings load.-s read-only, --ephemeral, --ignore-user-config and --ignore-rules.--deny '*', which refuses every tool call.--no-subagents and --disable-web-search, and reads the prompt from a file, never from argv.--always-approve or --cwd./tmp that is deleted afterwards. git diff runs with --no-ext-diff --no-textconv and no pager, so no configured helper programs run..env* (but not .env.example/.sample/.template), .envrc, .pgpass, *.pem, *.key, SSH keys, .npmrc/.netrc and credentials files are withheld from the reviewers. They are excluded by exact path before git reads any content, and any diff section whose header can't be parsed is withheld too./tribunal shows both reviews side by side:

Claude then fixes what both reviewers agreed on:

codex and/or grok on your PATH, already logged in.
/config)| Field | Default |
|---|---|
| codexEnabled / grokEnabled | true |
| codexModel / codexEffort | gpt-6-astra / medium |
| grokModel / grokEffort | grok-4.7 / high |
| maxDiffKb | 120 (200 max) |
| defaultBase | empty (the remote's default branch) |
| timeoutMinutes | 8 (10 max) |
/plugin marketplace add ccdwyer/claude-mods
/plugin install inline-tribunal@ccdwyer-mods
/reload-plugins
claude plugin validate .
claude plugin test .
Events this mod hooks, as claude plugin validate reads the module:
session.starttool.call{tool=mcp__inline-tribunal__second_opinion}command.run{command=tribunal}ui.render{component=PanerequestId=tribunal}Engine calls it makes: $.clock.now (via collectDiff, convene), $.command.register, $.fs.read (via runCodex), $.fs.write (via runGrok), $.process.run (via collectDiff, isolatedHome, realHome, runCodex, runGrok, tempDir), $.state.get, $.state.set, $.tool.register, $.ui.open (via convene), $.ui.resolve, $.ui.toast (via convene).
A tool.call hook sits in the middle of every tool call: it can see the call, refuse it, or add context to its result. This mod uses that only for the behaviour described above.
When you run /tribunal or Claude calls second_opinion, it sends your current git diff (with secret-looking values redacted and sensitive files left out) to the reviewer CLIs you have installed: OpenAI's codex and xAI's grok. Those requests go to OpenAI and xAI under your own accounts and are covered by their terms. Nothing is sent unless you or Claude starts a review, and either reviewer can be turned off in the plugin settings.
The mod collects no analytics or telemetry, and its author receives no data from it.
Full policy: PRIVACY.md.
MIT