Back to skill

Security audit

恢复 Codex 项目会话

Security checks across malware telemetry and agentic risk

Overview

This skill is a local Codex chat recovery helper that makes disclosed, purpose-aligned changes only when the user invokes repair commands.

Before installing or using it, understand that the repair path can rewrite local Codex history metadata and duplicate sensitive chat/config data into a backup folder. Run diagnosis first, confirm the provider names really refer to the same backend, quit Codex Desktop before repair, and keep the generated backup until recovered chats open correctly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The repair command makes large-scale persistent changes to databases and session files immediately once invoked, without an interactive confirmation, explicit destructive warning, or default dry-run. In a recovery context, users may run suggested commands under stress, and a mistyped provider value or wrong CODEX_HOME could silently rewrite unrelated history despite the backup step.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.