Back to skill

Security audit

Codex Sessions

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local Codex session-management tool with destructive capabilities, but it scopes them to Codex session storage and requires previews or explicit confirmation for writes.

Before installing, understand that this tool can modify or permanently remove local Codex session history when confirmed. Use preview mode first, prefer trash over permanent delete, verify the selected Codex root, and review npm dependency updates as you would for any globally installed CLI.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest advertises destructive capabilities such as delete, trash, restore, purge, and cleanup without any user-facing warning that these actions may permanently remove or alter local session data. In combination with implicit invocation, this increases the chance of accidental data loss because users are not alerted to the consequences before the skill is selected or used.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The default prompt is broad enough to match generic 'session' requests and automatically route them to a skill that can inspect, delete, purge, or otherwise modify local Codex session data. Because the manifest does not constrain invocation to clearly local/session-store-specific tasks, users may trigger sensitive filesystem-affecting operations without realizing this skill is being applied.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

该文件整体内容为中文,仅在 L006 提供英文 README 的链接,但文件本身未说明这是可选语言版本,也未在面向 AI Agent 的说明中提供语言偏好选择。按规则,若技能以自然语言强制特定语言而无用户 opt-in,可视为语言/locale 政策风险。

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 43)May include surrounding context.

json
"test": "vitest run"
  },
  "dependencies": {
    "@modelcontextprotocol/sdk": "^1.17.5",
    "better-sqlite3": "^12.6.2",
    "zod": "^4.1.12"
  },

Unverifiable Dependency: @modelcontextprotocol/sdk has 3 known advisory(ies) (CVE-2026-25536 (@modelcontextprotocol/sdk has cross-client data leak via shared server/transport); CVE-2026-0621 (Anthropic's MCP TypeScript SDK has a ReDoS vulnerability); CVE-2025-66414 (Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protec)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 44)May include surrounding context.

json
},
  "dependencies": {
    "@modelcontextprotocol/sdk": "^1.17.5",
    "better-sqlite3": "^12.6.2",
    "zod": "^4.1.12"
  },
  "devDependencies": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 45)May include surrounding context.

json
"dependencies": {
    "@modelcontextprotocol/sdk": "^1.17.5",
    "better-sqlite3": "^12.6.2",
    "zod": "^4.1.12"
  },
  "devDependencies": {
    "@types/better-sqlite3": "^7.6.13",

Unverifiable Dependency: zod has 1 known advisory(ies) (CVE-2023-4316 (Zod denial of service vulnerability)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 48)May include surrounding context.

json
"zod": "^4.1.12"
  },
  "devDependencies": {
    "@types/better-sqlite3": "^7.6.13",
    "@types/node": "^24.3.0",
    "typescript": "^6.0.2",
    "vitest": "^4.1.2"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 49)May include surrounding context.

json
},
  "devDependencies": {
    "@types/better-sqlite3": "^7.6.13",
    "@types/node": "^24.3.0",
    "typescript": "^6.0.2",
    "vitest": "^4.1.2"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 50)May include surrounding context.

json
"devDependencies": {
    "@types/better-sqlite3": "^7.6.13",
    "@types/node": "^24.3.0",
    "typescript": "^6.0.2",
    "vitest": "^4.1.2"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 51)May include surrounding context.

json
"@types/better-sqlite3": "^7.6.13",
    "@types/node": "^24.3.0",
    "typescript": "^6.0.2",
    "vitest": "^4.1.2"
  }
}

Unverifiable Dependency: vitest has 3 known advisory(ies) (CVE-2026-47429 (When Vitest UI server is listening, arbitrary file can be read and executed); CVE-2026-84373 (Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock); CVE-2025-24964 (Vitest allows Remote Code Execution when accessing a malicious website while Vit)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.