codex
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for operating the
codexCLI tool, which includes capabilities for modifying the local workspace (--sandbox workspace-write) and accessing external networks (--sandbox danger-full-access,--search) based on user-supplied parameters. \n- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection risks as it is configured to ingest and analyze untrusted data from local repositories.\n - Ingestion points: Files within the directory specified via the
-Cor--cdflags.\n - Boundary markers: The skill does not define specific markers or instructions to isolate the ingested codebase content from the agent's core instructions.\n
- Capability inventory: The
codextool can perform file writes, network operations, and code interpretation based on analyzed content.\n - Sanitization: There is no documentation of sanitization or validation steps for the repository content before it is processed by the agent.
Audit Metadata