skills/andiedie/skills/codex-executor/Gen Agent Trust Hub

codex-executor

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to invoke the codex CLI tool using shell commands. This includes support for running new tasks and resuming existing sessions using session identifiers returned by the tool.
  • [COMMAND_EXECUTION]: The agent is directed to explore the user's local directory (specifically ~/.codex or a custom CODEX_HOME path) to identify and list configuration profiles stored as .config.toml files.
  • [PROMPT_INJECTION]: The skill manages a boundary where user-provided task descriptions are interpolated into shell commands. The instructions recommend safe quoting as a mitigation strategy for potential injection at this entry point.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 06:59 AM
Security Audit — agent-trust-hub — codex-executor