codex
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
codexCLI to perform various tasks, including local edits and network operations. It instructs the agent to use profiles such as--profile edit(workspace-write) and--profile full(danger-full-access), which grants broad filesystem and network permissions to the sub-process. The skill consistently mandates the use of2>/dev/nullin all commands, which suppresses standard error output and may conceal operational warnings or security-related failures from the user. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to delegate complex reasoning and code generation to external models, then ingest the resulting output, creating a surface for indirect instructions.
- Ingestion points: Results from the
codexworkers are written to a temporary file created viamktempand subsequently read into the agent's context. - Boundary markers: The instructions do not define specific delimiters or instructions for the agent to ignore potential malicious prompts embedded in the external model's output.
- Capability inventory: The agent is authorized to execute
go test,go build, and perform workspace writes based on the task delegation, providing a path for instructions in the output to be executed. - Sanitization: While the skill provides a best practice of verifying output via
git diff --statto catch unexpected file modifications, it lacks explicit sanitization or filtering of the text content returned by the external model before the agent processes it.
Audit Metadata