codex-agent

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using the codex CLI. This includes various subcommands like exec, resume, and review. It documents powerful flags such as --sandbox workspace-write and --dangerously-bypass-approvals-and-sandbox, though it explicitly warns that the latter is extremely dangerous and should be avoided in normal use.
  • [EXTERNAL_DOWNLOADS]: The documentation requires the installation of the @openai/codex npm package. This package belongs to a trusted organization scope (@openai), although it appears to be a fictional or private tool reference rather than a standard public package.
  • [DATA_EXFILTRATION]: The browser research recipes in references/browser-research-prompt-recipes.md instruct the agent to use 'Computer Use' capabilities to access external websites like Reddit and summarize content. This allows the agent to retrieve and process data from the external internet into the local context.
  • [PROMPT_INJECTION]: The skill references fictional AI models like gpt-5.4 and gpt-5.3-codex-spark and includes purported 'playbooks' for these models. While this content is likely speculative or hallucinated, it could be used in a role-play context to influence the agent's perceived capabilities or constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 03:34 AM
Security Audit — agent-trust-hub — codex-agent