codex-usage-api
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
codex-usage-trackerCLI for tasks such as refreshing indices, generating usage summaries in JSON format, and starting a local dashboard server via theserve-dashboardcommand.- [EXTERNAL_DOWNLOADS]: Includes instructions for standard tool maintenance, such as reinstalling the CLI viapipxif the command is not detected in the environment path.- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes usage logs which may contain user-influenced content. However, the instructions mandate the use of aggregate data and strict privacy modes to prevent the exposure of raw transcript snippets or secrets, aligning with security best practices.
Audit Metadata