T09 · Insecure Skill Coding Practices
- Location
codex-quota.py:207- Finding
Authentication State May Not Be Restored After Account Switching
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This quota checker is mostly transparent about what it does, but its all-accounts mode can temporarily replace your Codex login file and may fail to restore it safely.
Use the default cached quota mode or --fresh for a single active account when possible. Treat --all --yes as a higher-risk mode: it temporarily changes your live Codex authentication file, can leave the wrong account active if interrupted, and stores account quota metadata in /tmp. Before using it, close other Codex activity and verify your active account afterward.
codex-quota.py:207Authentication State May Not Be Restored After Account Switching
codex-quota.py:278Predictable Shared Temporary File Allows Symlink-Based File Overwrite
The skill documentation describes capabilities to read local session data, invoke the codex CLI, and temporarily overwrite ~/.codex/auth.json, but it does not declare any permissions. This creates a real security issue because users or platforms may grant the skill more trust than warranted, while the skill can access sensitive local files and modify authentication state in ways that could expose credentials or disrupt account integrity.
This code reads and overwrites ~/.codex/auth.json to impersonate other locally stored accounts, then writes aggregated account quota data to /tmp/codex-quota-all.json. Modifying credentials and storing multi-account activity data in a world-accessible temporary location exceeds a simple quota-checking function and can expose sensitive account context or leave the user in a broken authentication state if restoration fails.
The skill claims to check quota status from local session logs, but ping_codex() actively invokes codex exec with a prompt to produce fresh data. That gives the skill an external execution/networking capability beyond passive inspection, increasing trust requirements and the chance of unintended side effects such as account activity, remote requests, or session creation.
switch_account() directly copies a selected account file over ~/.codex/auth.json, changing live credentials on disk. Even with a later best-effort restore, failures, interruption, concurrent Codex use, or partial writes can leave the wrong account active or corrupt authentication state, making this a risky credential-handling pattern.
No suspicious patterns detected.