codex-cli-bridge

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with the Codex CLI using the subprocess module. It correctly uses list-based arguments for subprocess.run, which prevents shell injection vulnerabilities by avoiding the use of a shell interpreter for command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill parses project-level documentation (CLAUDE.md) and skill metadata to generate AGENTS.md. Ingestion points: Files are read from the project root and .claude/skills/ directory via claude_parser.py. Boundary markers: The skill does not implement specific boundary markers for the generated text, as its primary purpose is documentation generation for human and agent reference. Capability inventory: The skill has the ability to write files to the project root (AGENTS.md, CLAUDE.md) and execute codex commands via codex_executor.py. Sanitization: External configuration data is parsed using yaml.safe_load(), which prevents unsafe object instantiation during parsing.
  • [DATA_EXPOSURE]: The skill manages project documentation and does not attempt to access sensitive system files (e.g., SSH keys, environment secrets) or exfiltrate data to external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 01:54 PM
Security Audit — agent-trust-hub — codex-cli-bridge