codex-delegation

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of the 'codex exec' command to perform tasks. This command takes prompts as positional arguments and is used for code-related operations.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the '@openai/codex' package from the official npm registry. This is an official tool provided by OpenAI.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data in the form of file content and user prompts which are then passed to an external model for processing. 1. Ingestion points: File context inlined into prompts and the positional prompt argument in SKILL.md. 2. Boundary markers: Not explicitly defined in the command examples provided. 3. Capability inventory: Executes shell commands via the codex binary and uses a delegation executor script. 4. Sanitization: No explicit sanitization or filtering of input data is described in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:05 AM
Security Audit — agent-trust-hub — codex-delegation