skills/dzhng/jevgrep/codex/Gen Agent Trust Hub

codex

Fail

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for using the codex CLI tool with the --dangerously-bypass-approvals-and-sandbox flag. This flag is explicitly used to disable the tool's built-in sandbox and approval requirements, granting the secondary agent unrestricted access to the host operating system, network, and file system during task execution.
  • [COMMAND_EXECUTION]: The instructions direct the agent to modify the ~/.codex/config.toml file by adding trust_level = "trusted" for specific paths. This action manually overrides the security model of the CLI tool, forcing it to trust directories that it would otherwise flag as untrusted.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of the codex CLI from OpenAI's official developer website (https://developers.openai.com/codex/cli).
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a multi-agent delegation pattern where a primary agent generates prompts to be processed by a secondary agent (codex exec).
  • Ingestion points: User-supplied implementation tasks and repository context are ingested through the SKILL.md instructions and passed to the codex CLI.
  • Boundary markers: The skill suggests using block-structured XML tags (e.g., <task>, <output_contract>, <action_safety>) to delimit instructions sent to the secondary agent.
  • Capability inventory: The secondary agent has workspace-write capabilities and can execute arbitrary code with full system access if the sandbox bypass flag is utilized.
  • Sanitization: Although the skill advises the agent to use self-authored prompts and avoid relaying third-party text directly, it still permits the interpolation of untrusted user-defined tasks into the execution context of the sub-agent.
  • [DATA_EXFILTRATION]: The skill involves reading and monitoring session files stored in ~/.codex/sessions/ to track the state and output of the backgrounded CLI processes.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 26, 2026, 10:59 PM
Security Audit — agent-trust-hub — codex