codex-task-to-spec
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a local Node.js script (
scripts/review-gate.mjs) to validate workflow checkpoints and reviewer reports. This execution is confined to the local filesystem and uses only built-in modules.\n- [PROMPT_INJECTION]: The skill handles natural language tasks by isolating them in a dedicated 'authority' log and using a multi-stage architecture to prevent sub-agents from executing instructions found within project evidence files.\n- [SAFE]: All operations are restricted to the local development environment. The skill does not perform network requests, access sensitive system credentials, or use obfuscated code.
Audit Metadata