Back to skill

Security audit

codex-export

Security checks for vulnerabilities and agentic risk

Overview

This looks like a legitimate Codex session exporter, but it needs Review because it can read and export sensitive past transcripts and some safeguards are incomplete.

Install only if you are comfortable with the skill reading local Codex history. Use explicit session IDs, avoid wildcard-like values, prefer --brief and --redact, and manually review exported files before sharing because metadata such as session IDs and workspace paths may remain. Pin install versions or inspect the source package instead of relying on npx/latest commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/export.py:47
Finding

Glob Injection Allows Unintended Cross-Session Transcript Selection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/export.py:497
Finding

Redaction Mode Leaves Sensitive Session Header Metadata Unmasked

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
python3 scripts/export.py --list

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
python3 scripts/export.py --list

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · docs/DEVELOPMENT.md (reported line 65)May include surrounding context.

md
改动以“小步提交”落在功能分支上,每一条提交都是独立回滚单元:

1. **功能分支回滚**(未合并):直接 `git reset --hard <合并前基线>`,或删除分支重建。
2. **合并后回滚**:`git revert <提交号>` 逐个还原;提交按需求映射可精确定位(见上文表格)。
3. **对照原版**:已配置 upstream(`jinghan23/codex-export`),可用 `git diff upstream/main` 查看与官方版本的差异。
4. **数据安全**:导出文件与检查点(`*.state.json`)均为生成物,不进入代码库;回滚不影响已导出的对话文件。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation appears to require Chinese comprehension for installation, usage, and safety-relevant behavior such as redact/export options. Under the natural-language policy rule, forcing a specific language without user opt-in is a policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run npx codex-export-more without pinning a specific package version. This causes execution of whatever version is current in the registry at install time, increasing supply-chain risk if a malicious or compromised release is published later. In a skill context, users may copy-paste this command directly, making the exposure more practical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The command npx clawhub@latest install codex-export-more explicitly tracks the latest version, which is unpinned and can change over time. If the upstream package is hijacked, compromised, or releases a malicious update, users following the README could execute attacker-controlled code during installation. Because this is framed as a recommended install path for a skill, the context makes the supply-chain risk more actionable.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill appears to require environment access plus file read/write capabilities, but it does not declare an explicit tool scope or permissions boundary. That increases the chance the agent invokes the skill with broader-than-expected access, especially because the skill exports local session transcripts that may contain secrets, file paths, and tool outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The invocation description is broad enough to match common requests such as save, share, review, or export a past chat, which can trigger the skill in situations where the user did not intend transcript extraction. In this context, accidental activation is meaningful because the skill handles historical conversation data that may include sensitive content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation promotes exporting session contents without a prominent warning that transcripts may include secrets, personal data, internal system/developer messages remnants, tool outputs, or local paths. Even though a --redact option exists, making it optional rather than strongly recommended or default increases the risk of users sharing sensitive data unintentionally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file begins with a Chinese-only title and the entire development guidance is written in Chinese, with no indication that language selection is optional or that the locale is intentionally restricted for a region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The publish instructions use npx clawhub@latest install codex-export-more, which resolves and executes the latest package from the registry at install time rather than a pinned, reviewed version. If the upstream package is compromised, typo-squatted, or publishes a malicious update, users following the docs could execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTML renderer hard-codes Chinese UI strings such as "会话信息", "用户", and sets the document language to "zh-CN". This imposes a specific locale on all users without offering a language choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The note says the skill works on "Windows/zh-CN," which references a specific locale, but it does not actually require or force output in that locale. Because this appears to be compatibility documentation rather than a mandated locale setting, the concern is limited and lower confidence.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: setuptools has 10 known advisory(ies) (CVE-2013-1633 (Setuptools vulnerable to Man-in-the-middle attacks); CVE-2025-47273 (setuptools has a path traversal vulnerability in PackageIndex.download that lead); CVE-2024-6345 (setuptools vulnerable to Command Injection via package URL) +7 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
bin/codex-export-more.js:11