oh-my-codex-workflow

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: A thorough review of the skill's instructions, metadata, and scripts found no evidence of prompt injection, data exfiltration, or obfuscation. The behavior aligns with the stated purpose of a developer productivity tool.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the oh-my-codex and @openai/codex packages from the npm registry. These represent the core tool and its dependencies as described in the documentation.
  • [COMMAND_EXECUTION]: The instructions include numerous examples of CLI commands for setting up the environment (omx setup), managing persistent workflows ($ralph), and coordinating parallel agent teams via tmux.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 02:33 PM