Back to skill

Security audit

CodexDelegate

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a transparent Codex CLI wrapper, but it exposes powerful execution modes and has under-scoped output paths that can write outside the intended repository.

Install only if you trust the local Codex CLI on PATH and are comfortable delegating repository content to it. Use read-only by default, approve write tasks explicitly, avoid danger-full-access except in an isolated environment, and keep log/output paths inside the target repository.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:21
Finding

Unverified Global CLI Dependency Installation

Content
View full analysis
/dev/null 2>&1; then echo "codex CLI not found on PATH. Install Codex CLI and authenticate with ChatGPT sign-in." >&2 exit 127 fi cmd=(codex exec --sandbox "$sandbox") ``` Checking only for the executable name does not establish that the binary came from the intended publisher or package. A replaced, compromised, dependency-confused, or otherwise unintended npm package could therefore satisfy the wrapper's check and execute with the user's privileges. ### Attack Path 1. An operator follows the documented `npm i -g codex` installation command. 2. npm retrieves the unscoped and unpinned package available through the configured registry. 3. The package installs an executable named `codex` into the user's global executable path. 4. The wrapper locates that executable using `command -v codex`. 5. A malicious or compromised executable runs when the Skill delegates a task. 6. The executable receives prompts and may access repository data and any resources available to the invoking user. Exploitation depends on the installed package or configured registry being malicious, compromised, or different from the intended Codex CLI. ### Impact Assessment A malicious CLI package would execute with the privileges of the user running OpenClaw. Depending on local perm ...[truncated 418 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/codex-delegate.sh:51
Finding

Unrestricted Output Paths Permit Writes Outside the Target Repository

Content
View full analysis
"$json_log" ``` ### Technical Analysis The values supplied through `--json-log` and `--output` are accepted without canonicalization or validation against `--cwd`. Consequently, callers can provide: - Absolute paths outside the repository. - Relative paths containing `../` traversal components. - Paths whose parent directories or destination files are symbolic links. The wrapper itself executes `mkdir -p` and shell redirection outside the Codex sandbox. Therefore, selecting `--sandbox read-only` does not prevent these filesystem writes. The `--output` destination is also passed directly to Codex, while the JSON log is created or truncated by shell redirection. This behavior conflicts with the documented scope statement that the Skill does not perform actions outside the target repository. Quoting prevents shell metacharacter injection, but it does not prevent path traversal or external file writes. ### Attack Path 1. An attacker or untrusted prompt influences the arguments used for a delegation request. 2. The invocation supplies an external destination, for example: ```bash codex-delegate.sh \ --cwd /path/to/repositor ...[truncated 1481 chars]
Remediation
View remediation
&2 exit 2 ;; esac ``` 3. Reject absolute paths unless external output has been explicitly enabled through a separate, clearly named option. 4. Resolve and validate every existing parent component to prevent symbolic-link escapes. 5. Create output files with restrictive permissions, such as by setting `umask 077`. 6. Avoid predictable check-then-write sequences; use secure file descriptors or atomic file creation where possible. 7. Explicitly document that logging and output creation are write operations, regardless of the Codex sandbox mode. 8. If external destinations are a required feature, require explicit operator confirmation and enforce a configurable allowlist of output directories. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · scripts/codex-delegate.sh (reported line 24)May include surrounding context.

sh
-h, --help                  Show this help.

The wrapper intentionally clears OPENAI_API_KEY and CODEX_API_KEY before running
codex exec so it uses saved Codex CLI authentication instead of an inline API key.
USAGE
}

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "use Codex" / "delegate to Codex" is broad enough to appear in ordinary conversation, issue text, pasted logs, or repository content, which can cause unintended skill activation. In this skill, accidental activation is more concerning because it can hand off coding, file-editing, or command-execution tasks to a local Codex CLI, potentially escalating from benign chat into repository modifications or system actions depending on sandbox mode.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
## Preconditions

- `codex` is installed on `PATH`.
- Codex CLI has already been authenticated by the operator, preferably with ChatGPT sign-in. Do not ask the user for an API key.
- Run inside the target repository or pass `--cwd`.
- OpenClaw must allow this agent to use `exec` for the wrapper script.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

bash
npm test 2>&1 | {baseDir}/scripts/codex-delegate.sh \
  --cwd /path/to/repo \
  --sandbox workspace-write \
  --prompt "Summarize the failing tests and make the smallest safe fix."

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script exposes a danger-full-access sandbox option for codex exec and performs no additional confirmation, policy gate, or risk acknowledgement before invoking it. In the context of a delegation wrapper that forwards prompts and repository context to another agentic coding tool, this materially increases the chance that unsafe prompts, prompt injection from repository files, or operator mistakes lead to unrestricted local file modification or command execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.