codex-test-gen

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted source code to generate unit tests, which introduces a risk where malicious instructions embedded in the code could be executed by the agent. \n- [INDIRECT_PROMPT_INJECTION]: Mandatory Evidence Chain: \n
  • Ingestion points: The skill reads user-specified functions and source code through tools such as Read, Grep, and Glob. \n
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded prompts in the analyzed entry-point file. \n
  • Capability inventory: The skill uses the Write tool to modify the file system and calls external MCP tools for processing. \n
  • Sanitization: There is no evidence of input sanitization or validation of the ingested source code content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 01:43 PM
Security Audit — agent-trust-hub — codex-test-gen