Back to skill

Security audit

codex-orchestration

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate Codex orchestration guide, but it should be reviewed because it encourages no-approval background workers with command execution, web use, and possible file edits.

Install only if you are comfortable with Codex spawning background workers that can run commands, use web search, and make scoped file edits. For sensitive repositories or private data, add explicit approval gates for web searches, destructive commands, writes outside intended workspace paths, and any long-running or persistent worker process.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly authorizes implementer workers to edit specific files or write new artefacts, but it provides no safety constraints around which files are permissible, how to avoid sensitive/system paths, or how to prevent destructive side effects. In an orchestration skill with autonomous background workers and no approvals, this increases the chance of unintended overwrites, persistence changes, or modifications to security-relevant files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The research worker template instructs sub-agents to use web search and collect external information, but it omits any warning against sending sensitive project details, secrets, internal URLs, or proprietary data to external services. Because this skill is meant for general-purpose orchestration, workers may perform research in contexts where prompts or queries could leak confidential information.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
92% confidence
Finding

The 'YOLO config (no approvals)' default removes human review for actions taken by the orchestrator and its spawned workers, including command execution, web access, and possible file edits. In combination with parallel background sessions, this materially raises the risk of unsafe autonomous actions, especially on ambiguous or high-impact tasks.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
This guide is steering, not bureaucracy. Use common sense. If something is simple, just do it.

## Default assumptions
- YOLO config (no approvals); web search enabled.
- PTY execution available via `exec_command` and `write_stdin`.
- Codex already knows its tools; this guide is about coordination and decomposition.

Static analysis

No suspicious patterns detected.