codex-dev-g

Fail

Audited by Snyk on Feb 19, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 0.90). The prompt explicitly instructs users to "NEVER" call the underlying CLI and to "Do NOT read or inspect the script source code" (treat it as a black box), which is a hidden/deceptive constraint that prevents scrutiny and is outside the skill's stated purpose of safely delegating coding tasks.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Feb 19, 2026, 03:58 PM