creating-codex-environments
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides templates for creating local Python scripts in the
.codex/hooks/directory, which are configured to be executed by the host system to validate commands and assistant output.- [EXTERNAL_DOWNLOADS]: Contains a reference to the OpenAI Model Context Protocol (MCP) server athttps://developers.openai.com/mcpfor use in research tasks.- [PROMPT_INJECTION]: The hook templates inreferences/hook-templates.mdprocess untrusted data from tool inputs and assistant messages using regular expressions, representing an indirect injection surface. This is documented as a mechanism for enforcing security boundaries rather than a vulnerability.
Audit Metadata