codex-bridge
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting data from a local desktop application (Codex Desktop) through tools like
read_codex_threadandread_codex_request. This creates a surface where the agent could process untrusted instructions embedded in the external content. - Ingestion points:
read_codex_request,read_codex_thread,list_codex_projects, andlist_codex_threadsinSKILL.md. - Boundary markers: The instructions do not define specific delimiters or warn the agent to ignore instructions within the retrieved content.
- Capability inventory: The skill can write back to the desktop application via
start_codex_threadandsend_to_codex_thread. - Sanitization: No sanitization of the retrieved content is mentioned in the provided workflow.
Audit Metadata