Back to skill

Security audit

Codex Quota

Security checks for vulnerabilities and agentic risk

Overview

This quota checker is mostly transparent about what it does, but its all-accounts mode can temporarily replace your Codex login file and may fail to restore it safely.

Use the default cached quota mode or --fresh for a single active account when possible. Treat --all --yes as a higher-risk mode: it temporarily changes your live Codex authentication file, can leave the wrong account active if interrupted, and stores account quota metadata in /tmp. Before using it, close other Codex activity and verify your active account afterward.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
codex-quota.py:207
Finding

Authentication State May Not Be Restored After Account Switching

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
codex-quota.py:278
Finding

Predictable Shared Temporary File Allows Symlink-Based File Overwrite

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill documentation describes capabilities to read local session data, invoke the codex CLI, and temporarily overwrite ~/.codex/auth.json, but it does not declare any permissions. This creates a real security issue because users or platforms may grant the skill more trust than warranted, while the skill can access sensitive local files and modify authentication state in ways that could expose credentials or disrupt account integrity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code reads and overwrites ~/.codex/auth.json to impersonate other locally stored accounts, then writes aggregated account quota data to /tmp/codex-quota-all.json. Modifying credentials and storing multi-account activity data in a world-accessible temporary location exceeds a simple quota-checking function and can expose sensitive account context or leave the user in a broken authentication state if restoration fails.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill claims to check quota status from local session logs, but ping_codex() actively invokes codex exec with a prompt to produce fresh data. That gives the skill an external execution/networking capability beyond passive inspection, increasing trust requirements and the chance of unintended side effects such as account activity, remote requests, or session creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

switch_account() directly copies a selected account file over ~/.codex/auth.json, changing live credentials on disk. Even with a later best-effort restore, failures, interruption, concurrent Codex use, or partial writes can leave the wrong account active or corrupt authentication state, making this a risky credential-handling pattern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.