claude-to-codex-coordinator

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/probe.py script executes system commands to check versions of node, claude, and codex. These operations are limited to environment verification and do not involve user-supplied input flowing into shell commands.\n- [EXTERNAL_DOWNLOADS]: The skill documentation references the openai/codex-plugin-cc plugin from OpenAI's official GitHub repository as a required runtime component.\n- [DATA_EXFILTRATION]: The skill provides instructions for managing Claude session transcripts during handoffs to Codex. The documentation includes specific privacy guidelines to prevent the exposure of account labels or private history during this process.\n- [PROMPT_INJECTION]: The skill manages the interface with an external AI system, creating a surface for indirect prompt injection. This risk is addressed through explicit requirements for manual verification of diffs, mandatory test execution, and independent reviews of all changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 08:14 AM
Security Audit — agent-trust-hub — claude-to-codex-coordinator