codex
Fail
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for using the
codexCLI tool with the--dangerously-bypass-approvals-and-sandboxflag. This flag is explicitly used to disable the tool's built-in sandbox and approval requirements, granting the secondary agent unrestricted access to the host operating system, network, and file system during task execution. - [COMMAND_EXECUTION]: The instructions direct the agent to modify the
~/.codex/config.tomlfile by addingtrust_level = "trusted"for specific paths. This action manually overrides the security model of the CLI tool, forcing it to trust directories that it would otherwise flag as untrusted. - [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of the
codexCLI from OpenAI's official developer website (https://developers.openai.com/codex/cli). - [INDIRECT_PROMPT_INJECTION]: The skill establishes a multi-agent delegation pattern where a primary agent generates prompts to be processed by a secondary agent (
codex exec). - Ingestion points: User-supplied implementation tasks and repository context are ingested through the
SKILL.mdinstructions and passed to thecodexCLI. - Boundary markers: The skill suggests using block-structured XML tags (e.g.,
<task>,<output_contract>,<action_safety>) to delimit instructions sent to the secondary agent. - Capability inventory: The secondary agent has
workspace-writecapabilities and can execute arbitrary code with full system access if the sandbox bypass flag is utilized. - Sanitization: Although the skill advises the agent to use self-authored prompts and avoid relaying third-party text directly, it still permits the interpolation of untrusted user-defined tasks into the execution context of the sub-agent.
- [DATA_EXFILTRATION]: The skill involves reading and monitoring session files stored in
~/.codex/sessions/to track the state and output of the backgrounded CLI processes.
Recommendations
- AI detected serious security threats
Audit Metadata