codex
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes the
codexCLI tool usingsubprocess.Popenincodex.pyto facilitate interactions with the OpenAI Codex model.\n- [COMMAND_EXECUTION]: Invokes therun.shscript of a sibling skill (create-walkthrough) incodex.pyto process the output of reasoning tasks.\n- [EXTERNAL_DOWNLOADS]: References the@openai/codexnpm package as a dependency, which is an official tool from OpenAI, a well-known organization.\n- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it processes untrusted user input that is subsequently passed to an LLM.\n - Ingestion points: User-provided
promptstring in thereasonandextractcommands incodex.py.\n - Boundary markers: Absent; user prompts are passed directly to the model without delimiters.\n
- Capability inventory: Execution of the
codexCLI and local scripts incodex.py, plus allowed toolsrun_commandandread_file.\n - Sanitization: Absent; no input validation or sanitization is applied to the prompt content.
Audit Metadata