Back to skill

Security audit

Codexmonitor

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent monitoring purpose, but it installs an unpinned third-party binary that reads sensitive Codex session history.

Review the CodexMonitor source and Homebrew formula before installing, and treat Codex session logs as confidential. Use the narrowest session directory possible, avoid pointing CODEX_SESSIONS_DIR or CODEX_HOME at shared or synced locations, and do not leave watch running longer than needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SETUP.md:15
Finding

Unpinned Executable Installed from a Third-Party Homebrew Tap

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:34
Finding

Third-Party Binary Receives Access to Sensitive Codex Session History

Content
View full analysis
` - Show with ranges: `codexmonitor show --ranges 1...3,26...28` - Show JSON: `codexmonitor show --json` - Watch all: `codexmonitor watch` - Watch specific: `codexmonitor watch --session ` ``` From `SETUP.md:25-39`: ```markdown ### Sessions Directory By default, CodexMonitor reads from `~/.codex/sessions/`. If your sessions are stored elsewhere, set one of these environment variables: - **`CODEX_SESSIONS_DIR`** — Absolute path to sessions directory (preferred) ```bash export CODEX_SESSIONS_DIR="/path/to/sessions" ``` - **`CODEX_HOME`** — CodexMonitor will use `$CODEX_HOME/sessions` ```bash export CODEX_HOME="/path/to/codex" ``` ``` ### Technical Analysis The Skill intentionally gives an externally installed executable access to local Codex session records. The `show` commands expose session contents, while `watch` continuously observes existing and newly written session data. Codex sessions may contain user prompts, source code, command output, filesystem paths, internal project information, API responses, or secrets accidentally included during an agent interaction. The reviewed documentation does not instruct the tool to exfiltrate this information, and reading these records is necessary for the stated monitoring function. Nevertheless, the implementation is absent from the project, so the audit cannot verify whether the binar ...[truncated 1543 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup explicitly directs the tool to read Codex session logs from ~/.codex/sessions or override paths, but it does not warn that these files may contain sensitive prompts, outputs, file paths, tokens, or other conversation artifacts. Because this skill is specifically designed to inspect and watch local session data, the lack of privacy and data-handling guidance increases the chance of unintentional exposure or misuse of sensitive information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.