Codex: Finish the Task

Security checks across malware telemetry and agentic risk

Overview

The skill appears coherent and clean, with only a caution that its autonomy prompt should not override normal safety confirmations.

Use this only where you want a more autonomous agent workflow. For deleting data, deploying, using credentials, changing external systems, or other irreversible work, keep explicit human confirmation in place.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The default prompt instructs the agent to run a task end-to-end without avoidable confirmations, but it does not define clear boundaries for when autonomy is appropriate or what safety checks must still be preserved. In a skill explicitly designed for uninterrupted execution, this broad trigger increases the chance the agent will take risky actions, continue through ambiguous states, or suppress useful human review in ways that could affect systems, data, or external resources.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal