codex-review

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the @openai/codex CLI and the use of the openai/codex-action GitHub Action, both of which are managed by a trusted organization.
  • [COMMAND_EXECUTION]: Documentation describes standard environment setup tasks, including the installation of Node.js and the modification of shell profiles to support CLI completions and environment variable persistence.
  • [DATA_EXFILTRATION]: The skill is designed to transmit source code and git diffs to OpenAI's API for the purpose of code analysis and review, which constitutes the primary intended functionality of the tool.
  • [SAFE]: The skill advocates for security best practices, such as the use of the --sandbox read-only flag to prevent unauthorized file modifications and the management of API keys through secure environment variables or repository secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 07:27 PM