codex-control-plane-mcp

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the 'codex-control-plane-mcp' package from an unverified GitHub repository ('github.com/aresyn/codex-control-plane-mcp.git') and via 'pipx'. These sources do not match the trusted organization list or the expected vendor naming patterns.\n- [REMOTE_CODE_EXECUTION]: The installation instructions for the MCP server involve cloning and executing code from an untrusted GitHub repository, which poses a risk of remote code execution during the setup process.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user prompts and task descriptions without boundary markers or sanitization, creating an attack surface where malicious input could influence the Codex Desktop environment.\n
  • Ingestion points: Prompt fields in the 'codex_submit_task' and 'codex_start_plan_workflow' tools.\n
  • Boundary markers: No delimiters are specified to isolate user input from agent instructions.\n
  • Capability inventory: Includes executing operations in Codex Desktop, approving workflows, and repairing system issues.\n
  • Sanitization: No input sanitization is performed on prompts before they are sent to the control plane.\n- [DYNAMIC_EXECUTION]: The 'codex_repair_issue' tool enables the agent to apply automated repairs to the host environment, representing a capability for dynamic modification of system state.\n- [DATA_EXFILTRATION]: The skill allows the agent to access sensitive project data, including full chat transcripts and diagnostics, which could be exposed or exfiltrated if the agent's behavior is manipulated.\n- [METADATA_POISONING]: The skill contains conflicting attribution between the reported author 'reason-machines' and the external links to 'ara.so' and the 'aresyn' repository, which may obscure the true origin of the software.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 10:43 PM
Security Audit — agent-trust-hub — codex-control-plane-mcp