codex-review

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs users to install the extension from an external, untrusted GitHub repository.
  • Evidence: npx skills add -g BenedictKing/codex-review in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions by ingesting and reviewing code, which creates a vulnerability surface for instructions embedded in the processed data.
  • Ingestion points: Untrusted source code files processed during review and changelog generation (SKILL.md).
  • Boundary markers: The provided instructions do not specify any delimiters or warnings to ignore instructions embedded in the code being reviewed.
  • Capability inventory: The skill has the capability to read local project files and write to a CHANGELOG.md file.
  • Sanitization: No evidence of input sanitization, filtering, or instruction-override protection is present.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — codex-review