codex-image-gen

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes several shell commands to facilitate its workflow, including codex exec for image generation, git rev-parse for identifying project directories, and sips for image post-processing on macOS. These are functional requirements for the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface by ingesting and processing session logs that contain outputs from a language model.
  • Ingestion points: The script scripts/extract-codex-image.py reads JSONL files located within the ~/.codex/sessions/ directory.
  • Boundary markers: No specific delimiters are used to separate trusted from untrusted content within the logs, though the script uses string length as a heuristic for identifying image data.
  • Capability inventory: The skill possesses the ability to execute shell commands and write files to the .tmp directory within the git repository.
  • Sanitization: The extraction process relies on base64.b64decode. It does not perform deep validation of the resulting file content beyond checking if it is a valid PNG using the shell file utility in the provided instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 08:30 AM
Security Audit — agent-trust-hub — codex-image-gen