Security audit
Clean Codex Archives
Security checks for vulnerabilities and agentic risk
Overview
This skill is a narrowly scoped local cleanup tool for archived Codex history, with deletion gated behind an explicit apply flag.
Install only if you want an assistant to help clean archived local Codex history. Run the dry run first and review the reported counts before authorizing --apply, because the cleanup deletes archived conversations and related local metadata.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
