codex

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for operating the codex CLI tool, which includes capabilities for modifying the local workspace (--sandbox workspace-write) and accessing external networks (--sandbox danger-full-access, --search) based on user-supplied parameters. \n- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks as it is configured to ingest and analyze untrusted data from local repositories.\n
  • Ingestion points: Files within the directory specified via the -C or --cd flags.\n
  • Boundary markers: The skill does not define specific markers or instructions to isolate the ingested codebase content from the agent's core instructions.\n
  • Capability inventory: The codex tool can perform file writes, network operations, and code interpretation based on analyzed content.\n
  • Sanitization: There is no documentation of sanitization or validation steps for the repository content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 10:37 AM
Security Audit — agent-trust-hub — codex