codex

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the @openai/codex package from npm, which is a resource from a trusted organization.
  • [COMMAND_EXECUTION]: Uses the terminal tool to run the Codex CLI for code generation and refactoring tasks. This includes flags like --yolo which bypasses approvals, representing an intended but high-capability feature.
  • [INDIRECT_PROMPT_INJECTION]: Processes data from external git repositories and pull requests. This content is untrusted and could potentially contain instructions designed to manipulate the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 07:01 PM
Security Audit — agent-trust-hub — codex