lov-open-codex-session
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of Codex thread UUIDs, session IDs, and user profile fields.\n
- Ingestion points:
SKILL.md(Step 1) identifies thread UUIDs and session IDs as inputs;skill.yamldefines ingestion points for user and brand profile data such as names and site URLs.\n - Boundary markers: The instructions do not specify explicit delimiters or "ignore instructions" warnings when interpolating identifiers or profile data into tool calls or context.\n
- Capability inventory: The skill utilizes the host's
navigate_to_codex_pagetool and performs local file writes to manage persistent user profiles viascripts/profile_store.py.\n - Sanitization: The
scripts/profile_store.pyscript implements atarget_partsvalidation function and aSENSITIVE_PARTSfilter to prevent the storage of credential-like fields (tokens, secrets, passwords) in the profile data.
Audit Metadata