skills/xiaolai/nlpm/conventions-codex/Gen Agent Trust Hub

conventions-codex

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves exclusively as an instructional guide for the OpenAI Codex CLI ecosystem. It details the expected layout for project files like AGENTS.md, .codex/config.toml, and .agents/skills/ without providing any malicious directives.
  • [EXTERNAL_DOWNLOADS]: The skill contains multiple links to authoritative documentation and repository sources (e.g., learn.chatgpt.com, github.com/openai/codex). These are reputable sources relevant to the skill's purpose and do not represent a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines conventions for how Codex tools ingest data from project files such as AGENTS.md. While these files represent a surface for indirect prompt injection if they contain untrusted content, the skill itself only provides the schema and discovery rules for such files and does not perform the ingestion or execution.
  • [COMMAND_EXECUTION]: The documentation mentions CLI commands like codex doctor and hook event triggers, but it does so in a descriptive and instructional context rather than instructing the agent to execute arbitrary or dangerous shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:56 PM
Security Audit — agent-trust-hub — conventions-codex