codex-image-gen
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several shell commands to facilitate its workflow, including
codex execfor image generation,git rev-parsefor identifying project directories, andsipsfor image post-processing on macOS. These are functional requirements for the skill's stated purpose. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface by ingesting and processing session logs that contain outputs from a language model.
- Ingestion points: The script
scripts/extract-codex-image.pyreads JSONL files located within the~/.codex/sessions/directory. - Boundary markers: No specific delimiters are used to separate trusted from untrusted content within the logs, though the script uses string length as a heuristic for identifying image data.
- Capability inventory: The skill possesses the ability to execute shell commands and write files to the
.tmpdirectory within the git repository. - Sanitization: The extraction process relies on
base64.b64decode. It does not perform deep validation of the resulting file content beyond checking if it is a valid PNG using the shellfileutility in the provided instructions.
Audit Metadata