codex-profiles

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing the codex-profile utility from a community repository using standard package managers like npm and Homebrew. It includes specific warnings against the use of automated remote install scripts, advising user inspection instead.
  • [DATA_EXFILTRATION]: The instructions include clear safety notes that prohibit the agent from copying, printing, or migrating sensitive auth.json tokens between profiles, which effectively mitigates the risk of credential exposure.
  • [COMMAND_EXECUTION]: The skill facilitates profile selection and task execution via the codex-profile CLI. It mandates user approval for commands that might affect the state of running Desktop applications or perform local cloning operations, ensuring user control over the environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 04:43 PM
Security Audit — agent-trust-hub — codex-profiles