ccdwyer/inline-tribunal

ccdwyer/inline-tribunal

提供 second_opinion 工具和 /tribunal [--base <ref>] [focus] 命令,將目前的 git diff 傳給 Codex 和 Grok,並排進行審查,給出 SHIP / SHIP AFTER FIXES / REWORK 判定。審查者會在沙箱中執行:每個席位都會取得空的暫存 HOME;Codex 使用 -s read-only、--ephemeral、--ignore-user-config 和 --ignore-rules 執行,Grok 使用 --deny '*'、--no-subagents 和 --disable-web-search 執行;兩者都在全新的 /tmp 資料夾中操作。敏感檔案(.env*、金鑰、憑證)不會送出,憑證形狀的值也會在送出 diff 前遮罩。需要 PATH 中有 codex 和/或 grok;模型、effort、diff 大小與逾時都可設定。
請先查看作者 README,確認 marketplace 與外掛名稱;指令可能隨儲存庫結構而變動。
claude plugin marketplace add ccdwyer/inline-tribunal claude plugin install inline-tribunal

A Claude Code mod that has your current change reviewed by Codex and Grok side by side, without leaving the session.
second_opinion tool. Claude can call it itself, for example before declaring risky work done. It takes an optional focus, and an optional base, such as main, to review the branch since its merge base. The tool returns each reviewer's findings and verdict (SHIP / SHIP AFTER FIXES / REWORK) as its result, so Claude can act on them./tribunal [--base <ref>] [focus]. The same review, run by you. It runs immediately, even mid-turn. If the working tree is clean, it reviews the branch against origin's default branch, or against defaultBase if you set it.The reviewers see the diff and nothing else. Testing showed that a temp working directory and the CLIs' usual flags were not enough: both CLIs could still read arbitrary files. So each seat is locked down explicitly:
HOME (and CODEX_HOME / GROK_HOME) points at a fresh temp home that holds only a link to that CLI's login. None of your MCP servers, plugins, hooks, skills, global rules, memories or always-approve settings load.-s read-only, --ephemeral, --ignore-user-config and --ignore-rules.--deny '*', which refuses every tool call.--no-subagents and --disable-web-search, and reads the prompt from a file, never from argv.--always-approve or --cwd./tmp that is deleted afterwards. git diff runs with --no-ext-diff --no-textconv and no pager, so no configured helper programs run..env* (but not .env.example/.sample/.template), .envrc, .pgpass, *.pem, *.key, SSH keys, .npmrc/.netrc and credentials files are withheld from the reviewers. They are excluded by exact path before git reads any content, and any diff section whose header can't be parsed is withheld too./tribunal shows both reviews side by side:

Claude then fixes what both reviewers agreed on:

codex and/or grok on your PATH, already logged in.
/config)| Field | Default |
|---|---|
| codexEnabled / grokEnabled | true |
| codexModel / codexEffort | gpt-6-astra / medium |
| grokModel / grokEffort | grok-4.7 / high |
| maxDiffKb | 120 (200 max) |
| defaultBase | empty (the remote's default branch) |
| timeoutMinutes | 8 (10 max) |
/plugin marketplace add ccdwyer/claude-mods
/plugin install inline-tribunal@ccdwyer-mods
/reload-plugins
claude plugin validate .
claude plugin test .
Events this mod hooks, as claude plugin validate reads the module:
session.starttool.call{tool=mcp__inline-tribunal__second_opinion}command.run{command=tribunal}ui.render{component=PanerequestId=tribunal}Engine calls it makes: $.clock.now (via collectDiff, convene), $.command.register, $.fs.read (via runCodex), $.fs.write (via runGrok), $.process.run (via collectDiff, isolatedHome, realHome, runCodex, runGrok, tempDir), $.state.get, $.state.set, $.tool.register, $.ui.open (via convene), $.ui.resolve, $.ui.toast (via convene).
A tool.call hook sits in the middle of every tool call: it can see the call, refuse it, or add context to its result. This mod uses that only for the behaviour described above.
When you run /tribunal or Claude calls second_opinion, it sends your current git diff (with secret-looking values redacted and sensitive files left out) to the reviewer CLIs you have installed: OpenAI's codex and xAI's grok. Those requests go to OpenAI and xAI under your own accounts and are covered by their terms. Nothing is sent unless you or Claude starts a review, and either reviewer can be turned off in the plugin settings.
The mod collects no analytics or telemetry, and its author receives no data from it.
Full policy: PRIVACY.md.
MIT