codex

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The instructions focus on legitimate development workflows and repository management using official OpenAI surfaces. It explicitly warns against guessing model IDs or SDK methods.
  • [PROMPT_INJECTION]: The skill contains an indirect prompt injection surface as it is designed to follow repository-level instructions from AGENTS.md and other repo files. 1. Ingestion points: Reads instructions from AGENTS.md and repository codebase. 2. Boundary markers: Absent. 3. Capability inventory: File system writes, MCP tool usage, and platform tools (web search, computer use). 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 12:33 PM
Security Audit — agent-trust-hub — codex