continue-codex-work
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The file
.security-scan-passedcontains text claiming the skill is safe and has passed security validation. This is identified as a self-referential pattern designed to impact the behavior of security analysis tools. - [INDIRECT_PROMPT_INJECTION]: The instructions direct the agent to process data from external files (
AGENTS.md,CLAUDE.md) and tool output (read-codex-history) without defining boundary markers or sanitization procedures. - Ingestion points:
SKILL.mdreferences readingAGENTS.md,CLAUDE.md, and output fromdaymade-claude-code:read-codex-history. - Boundary markers: The instructions do not specify the use of delimiters or "ignore" instructions for ingested data.
- Capability inventory: The skill allows for executing actions to advance business goals, which involves file modifications and command execution.
- Sanitization: No sanitization or validation steps are outlined for the ingested text.
Audit Metadata