codex-review
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill performs code reviews by analyzing external project files, which is a surface for indirect prompt injection attacks where instructions hidden in code could influence agent behavior.
- Ingestion points: Project source code files analyzed during the review process (SKILL.md).
- Boundary markers: None identified in the instructions to delimit or ignore instructions within reviewed code.
- Capability inventory: Automated generation of a CHANGELOG.md file (file system write) and interaction with an external Codex CLI tool.
- Sanitization: No sanitization or validation methods are described for the analyzed content.
- [EXTERNAL_DOWNLOADS]: The documentation references an installation command and repository under the GitHub account 'BenedictKing', which is not listed as a trusted organization or well-known service, and differs from the provided author context.
- [NO_CODE]: The analyzed skill consists entirely of markdown documentation and lacks any functional source code, scripts, or tool configurations.
Audit Metadata