Agent Plugins Marketplace
← All plugins

verify-dependency-exists

v0.0.4

Block hallucinated or unknown dependencies before they enter the repo. Watches requirements.txt, pyproject.toml, package.json, and go.mod, and blocks any newly added dependency not present in the allowlist file. Opt-in: disabled by default because it requires a curated allowlist. Enable with `chock enable verify-dependency-exists` after populating .chock/dependency-allowlist.txt. Runs at commit and at agent tool-use (a manifest edit is judged against the file on disk, and at the turn's end against HEAD). [Session-enforced via PreToolUse and Stop hooks; needs git and a Python 3.11+. PreToolUse judges the file a tool call would write; Stop re-reads what the turn actually left on disk, so a file written through a shell heredoc is judged too. With no working Python the hook exits 2; without git, fail-open clients allow silently. A gate that cannot reach a decision refuses rather than allowing one it never judged. Enforcement at every commit and in CI still needs chock installed in the repo. Codex requires a one-time trust review per hook -- the plugin is ADVISORY until you approve its hook, and a plugin update voids that trust until re-approved.]

Codex1 Skill

By chock-coreLicense: Apache-2.00 GitHub starsUpdated 6 days ago

Directory evidence

Runtimes
Codex
Parsed components
1 skill or MCP entry
Source updated
Sep 30, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install verify-dependency-exists for Codex

Installs for the current user
codex plugin marketplace add IchenDEV/agent-plugin-mkt
codex plugin marketplace upgrade agent-plugin-marketplace
codex plugin add verify-dependency-exists@agent-plugin-marketplace

Paste and run these commands in a terminal with Codex. They add and refresh the PluginsMP catalog, then install this plugin.

Compatibility: the page URL and API slug “verify-dependency-exists-4” remain stable.

  • Codex: verify-dependency-exists-4@agent-plugin-marketplace → verify-dependency-exists@agent-plugin-marketplace

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/open-coder-ai/chock-codex-plugins

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is codex/verify-dependency-exists/.

Plugin files

codex/verify-dependency-exists/
├── .codex-plugin/plugin.json
└── skills/verify-dependency-exists/SKILL.md

Included Skills1

verify-dependency-existsskills/verify-dependency-exists/SKILL.md

Block hallucinated or unknown dependencies before they enter the repo. Watches requirements.txt, pyproject.toml, package.json, and go.mod, and blocks any newly added dependency not present in the allowlist file. Opt-in: disabled by default because it requires a curated allowlist. Enable with `chock enable verify-dependency-exists` after populating .chock/dependency-allowlist.txt. Runs at commit and at agent tool-use (a manifest edit is judged against the file on disk, and at the turn's end against HEAD).

Plugin manifests1

codex/verify-dependency-exists/.codex-plugin/plugin.json
{
  "name": "verify-dependency-exists",
  "version": "0.0.4",
  "description": "Block hallucinated or unknown dependencies before they enter the repo. Watches requirements.txt, pyproject.toml, package.json, and go.mod, and blocks any newly added dependency not present in the allowlist file. Opt-in: disabled by default because it requires a curated allowlist. Enable with `chock enable verify-dependency-exists` after populating .chock/dependency-allowlist.txt. Runs at commit and at agent tool-use (a manifest edit is judged against the file on disk, and at the turn's end against HEAD). [Session-enforced via PreToolUse and Stop hooks; needs git and a Python 3.11+. PreToolUse judges the file a tool call would write; Stop re-reads what the turn actually left on disk, so a file written through a shell heredoc is judged too. With no working Python the hook exits 2; without git, fail-open clients allow silently. A gate that cannot reach a decision refuses rather than allowing one it never judged. Enforcement at every commit and in CI still needs chock installed in the repo. Codex requires a one-time trust review per hook -- the plugin is ADVISORY until you approve its hook, and a plugin update voids that trust until re-approved.]",
  "author": {
    "name": "chock-core"
  },
  "repository": "https://github.com/open-coder-ai/chock",
  "license": "Apache-2.0",
  "keywords": [
    "chock",
    "policy-as-code",
    "hook",
    "block",
    "{'control': 'asi04', 'coverage': 'partial', 'note': 'allowlist gate over newly-added dependencies in requirements.txt, pyproject.toml, package.json, go.mod at commit entry; it checks membership in a curated allowlist, not existence in the upstream registry'}"
  ],
  "interface": {
    "displayName": "Verify Dependency Exists",
    "shortDescription": "Block hallucinated or unknown dependencies before they enter the repo.",
    "composerIcon": "./assets/icon.svg"
  },
  "skills": "./skills",
  "hooks": "./hooks/hooks.json"
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[verify-dependency-exists on Agent Plugins Marketplace](https://pluginsmp.com/plugins/verify-dependency-exists-4)