codex-dev-g
Fail
Audited by Snyk on Feb 19, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E004: Prompt injection detected in skill instructions.
- Potential prompt injection detected (high risk: 0.90). The prompt explicitly instructs users to "NEVER" call the underlying CLI and to "Do NOT read or inspect the script source code" (treat it as a black box), which is a hidden/deceptive constraint that prevents scrutiny and is outside the skill's stated purpose of safely delegating coding tasks.
Audit Metadata