codex-cn-bridge

Security checks across malware telemetry and agentic risk

Overview

This appears to be a purpose-aligned model-provider bridge, with the main user risk being external handling of prompts rather than malicious behavior.

Install only if you are comfortable sending Codex conversation content and related request data to the configured third-party model providers. Avoid using it with secrets, regulated data, or proprietary code unless you have approved provider terms, retention settings, and data-handling controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This skill routes Codex prompts through a local bridge to third-party domestic model providers, but the documentation does not clearly warn users that their prompts, responses, and possibly related metadata will be transmitted outside the local Codex environment. That omission can lead users to unknowingly expose sensitive source code, credentials, proprietary data, or regulated information to external providers under different retention and privacy policies.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal