codex-cli-bridge
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill interacts with the Codex CLI using the
subprocessmodule. It correctly uses list-based arguments forsubprocess.run, which prevents shell injection vulnerabilities by avoiding the use of a shell interpreter for command execution. - [INDIRECT_PROMPT_INJECTION]: The skill parses project-level documentation (
CLAUDE.md) and skill metadata to generateAGENTS.md. Ingestion points: Files are read from the project root and.claude/skills/directory viaclaude_parser.py. Boundary markers: The skill does not implement specific boundary markers for the generated text, as its primary purpose is documentation generation for human and agent reference. Capability inventory: The skill has the ability to write files to the project root (AGENTS.md,CLAUDE.md) and executecodexcommands viacodex_executor.py. Sanitization: External configuration data is parsed usingyaml.safe_load(), which prevents unsafe object instantiation during parsing. - [DATA_EXPOSURE]: The skill manages project documentation and does not attempt to access sensitive system files (e.g., SSH keys, environment secrets) or exfiltrate data to external domains.
Audit Metadata