πŸͺž GPT Image 2 β€” Image Generation via Your ChatGPT Subscription

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local wrapper for Codex image generation, with a sensitive but purpose-aligned step that reads newly created Codex session logs to recover the generated image.

Install only if you are comfortable with this workflow storing prompts and image-generation artifacts in local Codex session logs under ~/.codex/sessions and then reading the newly created rollout files to extract the image. Avoid using it for highly sensitive prompts or reference images unless that local retention is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The script deliberately disables ephemeral execution and then scans ~/.codex/sessions to recover generated image data from persisted rollout files. That means prompts, attached image references, and model/session artifacts are stored on disk and later parsed without any explicit user consent or prominent privacy warning, increasing the chance of unintended local disclosure to other processes, backups, or shared accounts.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal