codex-exec
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a wrapper for executing caller-supplied commands through the
codex_exec_guardedfunction. It captures process output and manages exit statuses. - Evidence: The skill description states it runs "exactly one caller-supplied Codex prompt" and captures the result.
- [DYNAMIC_EXECUTION]: The skill executes code that is provided at runtime via environment variables or stdin piping. It sources local libraries to facilitate this execution.
- Evidence: The script sources
. "$AGENTOPS_ROOT/scripts/lib/codex-exec.sh"and uses theCODEX_EXEC_PROMPT_ARGvariable for execution. - [INDIRECT_PROMPT_INJECTION]: The skill serves as a high-capability sink for processing data generated by other components, which may contain instructions targeting the execution environment.
- Ingestion points: Accepts a "caller-supplied prompt" via the
PROMPTargument or as piped input to the process. - Boundary markers: The skill documentation does not define specific delimiters for untrusted content within the prompt, relying instead on environment-level sandboxing.
- Capability inventory: The skill can execute shell processes with potential workspace-write and network access depending on the sandbox configuration (
CODEX_EXEC_SANDBOX). - Sanitization: There is no explicit sanitization or filtering of the prompt content; security relies on the
read-onlysandbox recommendation and the capture cap (CODEX_EXEC_MAX_OUTPUT_BYTES).
Audit Metadata