debate
Fail
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
codexcommand-line tool via a bash block to facilitate architectural critiques. - [DATA_EXFILTRATION]: The skill gathers sensitive codebase context, specifically including authentication patterns and API surfaces, and transmits this data to an external service (GPT-5.4) via the
codexCLI command. - [PROMPT_INJECTION]: The skill aggregates untrusted codebase files and architectural proposals into the critique prompt template without using boundary markers or sanitization techniques, creating a surface for indirect prompt injection.
Recommendations
- AI detected serious security threats
Audit Metadata