lov-open-codex-session

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of Codex thread UUIDs, session IDs, and user profile fields.\n
  • Ingestion points: SKILL.md (Step 1) identifies thread UUIDs and session IDs as inputs; skill.yaml defines ingestion points for user and brand profile data such as names and site URLs.\n
  • Boundary markers: The instructions do not specify explicit delimiters or "ignore instructions" warnings when interpolating identifiers or profile data into tool calls or context.\n
  • Capability inventory: The skill utilizes the host's navigate_to_codex_page tool and performs local file writes to manage persistent user profiles via scripts/profile_store.py.\n
  • Sanitization: The scripts/profile_store.py script implements a target_parts validation function and a SENSITIVE_PARTS filter to prevent the storage of credential-like fields (tokens, secrets, passwords) in the profile data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:08 PM
Security Audit — agent-trust-hub — lov-open-codex-session