codex
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Installs the @openai/codex package from npm, which is a resource from a trusted organization.
- [COMMAND_EXECUTION]: Uses the terminal tool to run the Codex CLI for code generation and refactoring tasks. This includes flags like --yolo which bypasses approvals, representing an intended but high-capability feature.
- [INDIRECT_PROMPT_INJECTION]: Processes data from external git repositories and pull requests. This content is untrusted and could potentially contain instructions designed to manipulate the agent's behavior.
Audit Metadata