codex-agent-setup
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The scripts
scripts/setup.shandscripts/generate.shresolve the path to the project root dynamically using relative directory navigation (../../../). They then execute Python scripts (install.pyandgenerate.py) located at these computed paths. This mechanism makes the skill's execution dependent on the specific directory structure of the host environment. - [COMMAND_EXECUTION]: The skill provides commands that directly invoke shell scripts. These scripts then spawn subprocesses to run Python installers, performing file system operations related to the installation and management of agent configuration files.
- [INDIRECT_PROMPT_INJECTION]: The skill processes natural language requests from the user to determine installation parameters, creating a potential surface for indirect injection if malformed input is passed to the underlying scripts.
- Ingestion points: User instructions such as "install Anthony in Codex" or "update the Product Skills Codex agents" as defined in
SKILL.mdare used to trigger command execution. - Boundary markers: Absent; the skill does not use specific delimiters to isolate user-provided intents from the command flags passed to the shell scripts.
- Capability inventory: The skill has the capability to execute shell and Python scripts with file-write permissions (used for creating
.tomland.jsonfiles). - Sanitization: Absent; the provided bash wrapper scripts pass all arguments (
$@) directly to the Python scripts without explicit validation or sanitization.
Audit Metadata