configuring-codex

Warn

Audited by Gen Agent Trust Hub on Mar 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides explicit instructions to configure config.toml with approval_policy = "never" and sandbox_mode = "danger-full-access". These settings are designed to bypass user confirmation prompts and disable the security sandbox of the Codex CLI tool, which are patterns associated with bypassing safety guidelines and removing execution constraints.
  • [COMMAND_EXECUTION]: The skill recommends executing a local shell script ./scripts/ai/verify-ai-compat.sh and utilizing the codex exec command for environment and skill discovery verification. It also suggests a shell loop to verify symlink structures on the local filesystem.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 14, 2026, 05:20 PM