I maintain Context Guard, an open-source Codex plugin whose core behavior depends on eight lifecycle Hooks. The official public plugin submission documentation describes Skills, MCP servers, and their combination, but I have not found a clear statement that submitted plugins may distribute lifecycle Hooks or how users review and trust them. Is the official public submission path intended to support Hook-bearing plugins? If yes, what additional review, privacy, and test-case requirements apply? I do not want to submit a degraded skills-only package that omits the core runtime.
Repository: GreenLv/codex-context-guard on GitHub
The complete plugin is also listed as Context Guard by the independent Codex Plugin Marketplace and passed its automated clean scan.
If Hooks are core to the plugin, I’d recommend confirming this with the official submission team before submitting. The public documentation should clarify whether lifecycle Hooks are supported in submitted plugins and what additional security, privacy, and review requirements apply. An automated marketplace scan wouldn’t necessarily establish eligibility for the official submission process.