codex-agent
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands using the
codexCLI. This includes various subcommands likeexec,resume, andreview. It documents powerful flags such as--sandbox workspace-writeand--dangerously-bypass-approvals-and-sandbox, though it explicitly warns that the latter is extremely dangerous and should be avoided in normal use. - [EXTERNAL_DOWNLOADS]: The documentation requires the installation of the
@openai/codexnpm package. This package belongs to a trusted organization scope (@openai), although it appears to be a fictional or private tool reference rather than a standard public package. - [DATA_EXFILTRATION]: The browser research recipes in
references/browser-research-prompt-recipes.mdinstruct the agent to use 'Computer Use' capabilities to access external websites like Reddit and summarize content. This allows the agent to retrieve and process data from the external internet into the local context. - [PROMPT_INJECTION]: The skill references fictional AI models like
gpt-5.4andgpt-5.3-codex-sparkand includes purported 'playbooks' for these models. While this content is likely speculative or hallucinated, it could be used in a role-play context to influence the agent's perceived capabilities or constraints.
Audit Metadata