skills/grahama1970/agent-skills/codex/Gen Agent Trust Hub

codex

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes the codex CLI tool using subprocess.Popen in codex.py to facilitate interactions with the OpenAI Codex model.\n- [COMMAND_EXECUTION]: Invokes the run.sh script of a sibling skill (create-walkthrough) in codex.py to process the output of reasoning tasks.\n- [EXTERNAL_DOWNLOADS]: References the @openai/codex npm package as a dependency, which is an official tool from OpenAI, a well-known organization.\n- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it processes untrusted user input that is subsequently passed to an LLM.\n
  • Ingestion points: User-provided prompt string in the reason and extract commands in codex.py.\n
  • Boundary markers: Absent; user prompts are passed directly to the model without delimiters.\n
  • Capability inventory: Execution of the codex CLI and local scripts in codex.py, plus allowed tools run_command and read_file.\n
  • Sanitization: Absent; no input validation or sanitization is applied to the prompt content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — codex