codex-cli-model-bridge

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONPERSISTENCE
Full Analysis
  • [COMMAND_EXECUTION]: The main bridge script utilizes subprocess.run to interact with local development tools, including the Codex CLI, Node.js, and system service managers like launchctl for macOS, to verify model routes and manage environment configurations.
  • [DYNAMIC_EXECUTION]: The tool generates and executes local Python and Node.js scripts at runtime to implement a credential helper and a transparent header-rewriting proxy, ensuring that model routing is managed dynamically without hardcoding sensitive information.
  • [PERSISTENCE]: The skill ensures that its proxy service remains active by creating a LaunchAgent on macOS and initiating detached background processes on Windows and Linux systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 01:29 AM
Security Audit — agent-trust-hub — codex-cli-model-bridge