codex
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to generate and execute shell commands using the
codexCLI tool. It documents the use of high-privilege flags such as--yoloand--sandbox danger-full-access, which can bypass standard security restrictions. - [COMMAND_EXECUTION]: The skill includes explicit safety instructions in the 'Assistant Playbook' requiring the agent to explain risks and obtain user consent before using high-impact or dangerous CLI flags.
- [COMMAND_EXECUTION]: Usage instructions suggest suppressing stderr (
2>/dev/null) to optimize the context window. While functional, this practice could hide tool-level warnings or error messages from the user unless they specifically request to see them. - [EXTERNAL_DOWNLOADS]: The README provides standard manual installation instructions using
git cloneto fetch the skill from the author's repository on GitHub.
Audit Metadata