codex-agent-setup

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The scripts scripts/setup.sh and scripts/generate.sh resolve the path to the project root dynamically using relative directory navigation (../../../). They then execute Python scripts (install.py and generate.py) located at these computed paths. This mechanism makes the skill's execution dependent on the specific directory structure of the host environment.
  • [COMMAND_EXECUTION]: The skill provides commands that directly invoke shell scripts. These scripts then spawn subprocesses to run Python installers, performing file system operations related to the installation and management of agent configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes natural language requests from the user to determine installation parameters, creating a potential surface for indirect injection if malformed input is passed to the underlying scripts.
  • Ingestion points: User instructions such as "install Anthony in Codex" or "update the Product Skills Codex agents" as defined in SKILL.md are used to trigger command execution.
  • Boundary markers: Absent; the skill does not use specific delimiters to isolate user-provided intents from the command flags passed to the shell scripts.
  • Capability inventory: The skill has the capability to execute shell and Python scripts with file-write permissions (used for creating .toml and .json files).
  • Sanitization: Absent; the provided bash wrapper scripts pass all arguments ($@) directly to the Python scripts without explicit validation or sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 09:00 PM