codex-gateway

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the 'tempo' CLI for managing wallet sessions and performing authenticated HTTP requests. Specifically, it employs 'tempo wallet' for identity management and 'tempo request' to handle the full Machine Payment Protocol challenge cycle automatically.
  • [DATA_EXFILTRATION]: Outbound network activity is scoped to the vendor-owned domain 'graph.codex.io' for GraphQL operations. The skill explicitly forbids the printing or logging of raw credentials or private keys, mitigating accidental exposure.
  • [SAFE]: Analysis of the skill instructions and references revealed no malicious patterns, prompt injections, or unauthorized remote code execution. The implementation relies on a documented payment protocol and uses standard CLI-based authentication flows.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 09:14 AM