codex-exec
Warn
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a Node.js wrapper (
scripts/codex-wrapper.cjs) to execute thecodexbinary viachild_process.spawn. While the wrapper correctly uses an argument array to prevent shell injection, the underlying purpose is to execute commands generated by an external AI model. - [COMMAND_EXECUTION]: The
--full-autoargument enables the Codex CLI's automatic approval mode (codex -a full-auto). This significantly increases risk by allowing the tool to execute generated code or system modifications without user confirmation. - [PROMPT_INJECTION]: The skill takes a raw
<prompt>input which is passed directly to the Codex execution engine. This creates a surface for indirect prompt injection, where malicious instructions hidden in data processed by the agent could be forwarded to and executed by Codex. - [PRIVILEGE_ESCALATION]: The
SKILL.mdfile contains instructions for the agent to usemode: "bypassPermissions"when writing artifacts to.claude/outputs/. This platform-specific feature allows the agent to write files silently without user interaction, which could be abused to plant scripts or configuration files if the agent is compromised. - [REMOTE_CODE_EXECUTION]: By design, the skill facilitates the execution of code generated by a remote model (OpenAI Codex) on the local system. When combined with the
--full-autoflag, this constitutes an automated remote code execution pipeline. - [CREDENTIALS_UNSAFE]: The wrapper script identifies that it utilizes the
OPENAI_API_KEYenvironment variable for authentication, though it does not appear to exfiltrate it. It also relies on the local environment's existing authentication state for thecodexCLI.
Audit Metadata