Skip to main content

Codex

Enables safe and efficient coding with Codex, ensuring repo-aware execution and verification workflows for developers.

Install this skill

or
86/100

Security score

The Codex skill was audited on May 31, 2026 and we found 6 security issues across 2 threat categories. Review the findings below before installing.

Categories Tested

Security Issues

medium line 8

Access to hidden dotfiles in home directory

SourceSKILL.md
8metadata: {"clawdbot":{"emoji":"🧭","requires":{"bins":["codex"],"bins.optional":["git","rg"],"env.optional":["OPENAI_API_KEY"],"config":["~/codex/","~/.codex/config.toml"]},"os":["linux","darwin","wi
medium line 142

Access to hidden dotfiles in home directory

SourceSKILL.md
142- `~/.codex/config.toml` and the user's local Codex session/config state
low line 5

External URL reference

SourceSKILL.md
5homepage: https://clawic.com/skills/codex
low line 128

External URL reference

SourceSKILL.md
128| https://api.openai.com | prompts, selected repository context, tool results, and execution metadata needed for Codex runs | Codex model execution, cloud tasks, login-linked agent work |
low line 129

External URL reference

SourceSKILL.md
129| https://developers.openai.com/* | doc queries only | Verify current Codex product behavior and configuration details |
low line 130

External URL reference

SourceSKILL.md
130| https://{user-approved-mcp-host} | request payloads required by the specific MCP server | Optional user-approved tool access beyond the local machine |
Scanned on May 31, 2026
View Security Dashboard
Installation guide →