codex-review
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides templates for executing the
codexcommand-line tool to analyze source code changes. These commands are standard for the intended purpose of code review. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted code content, which is a standard surface for indirect prompt injection in analysis tools.
- Ingestion points: Source code accessed via
--uncommitted,--base, and--commitflags inSKILL.md. - Boundary markers: Absent; instructions do not specify delimiters to separate code from commands.
- Capability inventory: Shell execution of the
codexcommand inSKILL.md. - Sanitization: Not specified in the instructions.
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The functionality is consistent with the stated purpose of the skill.
Audit Metadata