sync-codex

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The orchestrator script scripts/run-codex-sync.mjs manages the execution of internal project scripts using the node runtime. It sequentially spawns subprocesses for migration, synchronization, and verification tasks, ensuring that each stage passes before proceeding.
  • [DYNAMIC_EXECUTION]: The skill dynamically identifies and executes unit test files located in the .claude/scripts/tests/ and .claude/scripts/codex/tests/ directories. This is a standard procedure for ensuring the integrity of the project's maintenance scripts across different environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions mandate reading local project configuration and reference documents (docs/project-config.json, docs/project-reference/*) to guide the synchronization process. While this represents a data ingestion surface, it is constrained to local repository content and is integral to the tool's function.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — sync-codex