← Plugin catalog
Productivity

QuarryFi R&D Tracker

Smashed Studios LLC v0.4.7

Publisher description

From the marketplace listing

Records active Codex session time and privacy-minimized project metadata in QuarryFi so businesses can review potential R&D activity alongside other evidence. Supports multiple company profiles, project-to-key routing, and bounded local audit logging. It does not determine tax-credit eligibility and is not tax advice.

Language: English · Automatically detected from descriptions.

Files & skills

File archives

Plugin package20 files · 50.3 KBBrowse files →
Skill instructions
quarryfi-status3.61 KB

View saved version →

---
name: quarryfi-status
description: Check QuarryFi R&D tracking status across all configured company profiles
---

Show the user's QuarryFi tracking status across all configured profiles, plus the currently installed Codex plugin version and whether hooks have fired recently on this machine.

## What to do

1. Read `~/.quarryfi/config.json` without displaying any full `api_key`. If it doesn't exist, tell the user to run setup from the verified source clone in a regular terminal, not in the Codex conversation:
   ```
   cd ~/plugins/quarryfi-time-tracker && bash setup.sh
   ```
   Never ask the user to paste a tracker key into Codex, and never invent a credential.

2. Detect the config format:
   - **Multi-profile** (has `"profiles"` array): iterate each profile.
   - **Legacy** (has top-level `"api_key"`): treat as a single unnamed profile.

3. For each profile, display:
   - Profile name
   - Masked key identifier only (for example, `qf_abcd…1234`)
   - API destination: `https://quarryfi.com` (legacy custom `api_url` values are ignored)
   - Mapped project directories (or "all projects" if empty)
   - Whether the current working directory matches this profile

4. Read the local plugin version:
   - Check `~/plugins/quarryfi-time-tracker/.codex-plugin/plugin.json` first
   - If the plugin is installed elsewhere, read the version from that install's `.codex-plugin/plugin.json`

5. For each profile, query only QuarryFi's production status endpoint. Do not use a configured `api_url` value:
   ```bash
   curl --proto '=https' --tlsv1.2 -s -H "Authorization: Bearer $API_KEY" "https://quarryfi.com/api/status"
   ```
   Keep the key inside the command environment. Do not echo it, include the full value in the response, or write it to the audit log.

6. If the API responds successfully, display per profile:
   - Last heartbeat timestamp
   - Last accepted heartbeat receipt
   - Last authenticated contact
   - Health state
   - Plugin version / runtime channel / hook mode / install revision
   - Last 24 hours tracked minutes
   - Last 7 days tracked minutes
   - Active projects from the last 7 days
   - Recent sessions

7. If the API request fails, fall back to the local audit log instead of stopping.

8. Show audit log summary:
   - Check if `~/.quarryfi/audit.log` exists
   - Show the count of recent entries and last heartbeat timestamp
   - Specifically note whether there is any `hook_fired` entry from the current session/day
   - If the user asks for details, show the last 10 lines of the audit log

9. If any API returns an error, show the HTTP status and suggest verifying the API key.
10. Tell the user the dashboard remains the source of truth for deduped activity blocks and qualification review. Tracker activity is supporting evidence, not a determination of tax-credit eligibility or tax advice.

## Response format

```
QuarryFi R&D Tracking Status
═════════════════════════════

Profile: Acme Corp
  API:       https://quarryfi.com
  Projects:  /Users/me/work/acme-api, /Users/me/work/acme-frontend
  Match:     ✓ (current directory matches)
  Today:     2h 34m
  This week: 12h 15m
  Sessions:  3 today

Profile: Personal Projects
  API:       https://quarryfi.com
  Projects:  all (catch-all)
  Match:     ✗
  Today:     0h 45m
  This week: 3h 20m

─────────────────────────────
Audit log: 142 entries, last heartbeat 2 min ago
Source: Codex CLI
```

Adapt based on actual API response fields. Keep it concise. If the API is unavailable, use the audit log plus the current directory/profile match as the fallback status.
quarryfi-update4.78 KB

View saved version →

---
name: quarryfi-update
description: Refresh the local QuarryFi plugin install from GitHub
---

Refresh the local QuarryFi time tracking plugin install by pulling the latest changes from GitHub into the folder Codex is currently using.

## Safety invariant

The local plugin checkout must not change during ordinary Codex use. Runtime hooks, status checks, and background heartbeats may write only to `~/.quarryfi/`. This update skill is the only sanctioned workflow that changes files under the plugin directory, and it should make that explicit in its response.

Keep three locations distinct:

- Upstream development repo: where maintainers author, commit, and push product changes to GitHub.
- Local install source: the clone referenced by the Codex marketplace; this is what the updater may fast-forward.
- Codex runtime cache: `~/.codex/plugins/cache/...`; Codex owns this copy. Never run `git pull`, `git reset`, or repair commands inside the cache.

## What to do

1. Find the plugin installation directory. Check these locations in order:
   - `~/plugins/quarryfi-time-tracker` (home-local install)
   - Marketplace source paths in `~/.agents/plugins/marketplace.json` and `<repo>/.agents/plugins/marketplace.json`, resolving relative `source.path` entries from the marketplace file's parent directory
   - Search for a directory containing `.codex-plugin/plugin.json` with `"name": "quarryfi-time-tracker"` under `~/plugins/`, `~/.codex/plugins/` excluding `~/.codex/plugins/cache/`, or the current repo's `plugins/` directory
   - If the only discovered copy is under `~/.codex/plugins/cache/`, do not update it. Tell the user:
     ```
     Found only Codex's runtime cache copy of quarryfi-time-tracker.
     The updater must run against the marketplace source clone, not the cache.
     Reinstall or restore the local source clone, then run the update again.
     ```

2. If the plugin directory is not found, tell the user:
   ```
   Could not find the quarryfi-time-tracker plugin.
   Install it first: https://github.com/quarryFi/codex-plugin#install
   ```

3. Check for updates:
   ```bash
   cd <plugin-dir>
   git fetch origin main 2>/dev/null
   LOCAL=$(git rev-parse HEAD)
   REMOTE=$(git rev-parse origin/main)
   STATUS=$(git status --short)
   ```

4. Before pulling, protect against dirty or half-updated checkouts:
   - If `$STATUS` is non-empty and `git diff --quiet origin/main` succeeds, the files on disk already match the remote but git metadata is stale. Tell the user:
     ```
     QuarryFi plugin files already match GitHub, but the local git branch is stale.
     This indicates an out-of-band file sync or interrupted update.
     Repairing git metadata only; file contents will not change.
     ```
     Then run:
     ```bash
     git reset --mixed origin/main
     ```
     After that, recompute `LOCAL`, `REMOTE`, and `STATUS`.
   - If `$STATUS` is non-empty and the worktree does not match `origin/main`, do not pull and do not stash automatically. Show `git status --short` and tell the user:
     ```
     QuarryFi plugin update blocked because the plugin checkout has local edits.
     Review or stash those edits, then run the update again.
     ```
     If they want to preserve those edits, suggest:
     ```bash
     cd <plugin-dir>
     git stash push -m quarryfi-plugin-local-edits
     git pull --ff-only origin main
     git stash pop
     ```

5. If `$LOCAL` equals `$REMOTE` and `$STATUS` is empty, tell the user:
   ```
   QuarryFi plugin is already up to date (version X.Y.Z).
   ```
   Read the version from `.codex-plugin/plugin.json`.

6. If there are updates available, show what's changed:
   ```bash
   git log --oneline HEAD..origin/main
   ```

7. Pull the update with fast-forward only:
   ```bash
   git pull --ff-only origin main
   ```

8. Read the new version from `.codex-plugin/plugin.json` and show:
   ```
   ✓ QuarryFi plugin updated to vX.Y.Z

   Restart the Codex App to load the new version.
   ```

9. Be explicit that this updates the local plugin folder on disk. The current Codex session may still be running the previously cached copy until restart.

10. Suggest verifying with `quarryfi-status` after restart so the user can confirm:
   - the installed version
   - the latest local audit timestamp
   - whether a hook has fired in the new session

11. If `git pull --ff-only` fails, do not try a merge. Report the failure and show the user the current `git status --short`.

## Error handling

- If the directory exists but is not a git repo, tell the user to re-clone.
- If there's no network, say the update check failed and to try again later.
- Never delete or overwrite the user's `~/.quarryfi/config.json` — that's separate from the plugin code.
- Be explicit that this updates the local plugin folder on disk; the current Codex session still needs a restart before the new version is active.
Package details

Publisher declarations from the archived package. These are separate from our research and the live service's terms.

Package license
MIT
Package author
Smashed Studios LLC
Keywords
time-tracking, r&d, tax-credits, quarryfi

Declared capabilities

  • time-tracking
  • session-monitoring
  • multi-company
  • audit-logging

Package observed Oct 2, 2026.

Technical details
First seen
Sep 30, 2026 · 22:02 UTC
Last seen
Oct 2, 2026 · 12:00 UTC
Collection status
Collected

plugins_6a7adacb0bbc8191b326b6d54a2a7745

Download plugin data (JSON)