skills/garrytan/gstack/codex/Gen Agent Trust Hub

codex

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from git diffs and plan files in the review, challenge, and consult modes. These files could contain malicious instructions designed to influence the agent's behavior. While the skill employs boundary markers like DIFF_START and DIFF_END and provides instructions to the model to ignore system-specific files, the ingestion of external content combined with high-privilege tools like Bash and Write constitutes a vulnerability surface.
  • Ingestion points: Git diff output and Read tool for plan files.
  • Boundary markers: DIFF_START/DIFF_END delimiters and prose instructions to ignore ~/.claude directories.
  • Capability inventory: Bash, Write, Read, Glob, Grep.
  • Sanitization: Delimiters are used, but no automated sanitization of the embedded content is performed.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool extensively to run the codex CLI and various helper scripts such as gstack-skill-start, gstack-review-log, and gstack-question-log. It also invokes python3 to parse JSONL output from the Codex CLI.
  • [DYNAMIC_EXECUTION]: The skill utilizes eval to execute the output of internal configuration scripts (gstack-slug and gstack-paths) to dynamically set environment variables. Additionally, it generates and executes Python logic as string literals within shell commands to handle streaming data processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:03 AM
Security Audit — agent-trust-hub — codex