codex-review
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation instructs users to install the extension from an external, untrusted GitHub repository.
- Evidence:
npx skills add -g BenedictKing/codex-reviewinSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting and reviewing code, which creates a vulnerability surface for instructions embedded in the processed data.
- Ingestion points: Untrusted source code files processed during review and changelog generation (SKILL.md).
- Boundary markers: The provided instructions do not specify any delimiters or warnings to ignore instructions embedded in the code being reviewed.
- Capability inventory: The skill has the capability to read local project files and write to a
CHANGELOG.mdfile. - Sanitization: No evidence of input sanitization, filtering, or instruction-override protection is present.
Audit Metadata