codex-exec

Warn

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a Node.js wrapper (scripts/codex-wrapper.cjs) to execute the codex binary via child_process.spawn. While the wrapper correctly uses an argument array to prevent shell injection, the underlying purpose is to execute commands generated by an external AI model.
  • [COMMAND_EXECUTION]: The --full-auto argument enables the Codex CLI's automatic approval mode (codex -a full-auto). This significantly increases risk by allowing the tool to execute generated code or system modifications without user confirmation.
  • [PROMPT_INJECTION]: The skill takes a raw <prompt> input which is passed directly to the Codex execution engine. This creates a surface for indirect prompt injection, where malicious instructions hidden in data processed by the agent could be forwarded to and executed by Codex.
  • [PRIVILEGE_ESCALATION]: The SKILL.md file contains instructions for the agent to use mode: "bypassPermissions" when writing artifacts to .claude/outputs/. This platform-specific feature allows the agent to write files silently without user interaction, which could be abused to plant scripts or configuration files if the agent is compromised.
  • [REMOTE_CODE_EXECUTION]: By design, the skill facilitates the execution of code generated by a remote model (OpenAI Codex) on the local system. When combined with the --full-auto flag, this constitutes an automated remote code execution pipeline.
  • [CREDENTIALS_UNSAFE]: The wrapper script identifies that it utilizes the OPENAI_API_KEY environment variable for authentication, though it does not appear to exfiltrate it. It also relies on the local environment's existing authentication state for the codex CLI.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — codex-exec