codex — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited codex (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
--sandbox read-only unless edits or network access are necessary.codex --version first. Stop and report the failure if Codex is unavailable.-m, --model <MODEL>--config model_reasoning_effort="<xhigh|high|medium|low>"--sandbox <read-only|workspace-write|danger-full-access>; only use other modes when codex exec --help lists them-C, --cd <DIR>--add-dir <DIR>--skip-git-repo-check--dangerously-bypass-approvals-and-sandbox--skip-git-repo-check by default. Use it only when the user explicitly asks to run outside a Git repository or has approved that boundary bypass for this command.codex exec resume --last via stdin. Do not add model, reasoning, or sandbox flags on resume unless the user explicitly requests an override.2>/dev/null to codex exec commands to suppress thinking tokens (stderr). Only show stderr if the user explicitly requests it or if debugging is needed.Do not build Codex commands with echo "user prompt" | ...; user text can contain quotes, substitutions, or newlines. Prefer a quoted heredoc so the shell never reinterprets prompt contents:
codex exec resume --last 2>/dev/null <<'EOF'
Your follow-up prompt goes here.
EOF| Use case | Sandbox mode | Key flags |
|---|---|---|
| Read-only review or analysis | read-only | --sandbox read-only 2>/dev/null |
| Apply local edits | workspace-write | --sandbox workspace-write 2>/dev/null |
| Apply edits that need network access | workspace-write plus config | --sandbox workspace-write -c 'sandbox_workspace_write.network_access=true' 2>/dev/null |
| Permit extra write scope | Prefer --add-dir | Ask before adding extra writable directories |
| Permit broad file access | danger-full-access only after approval | Ask before adding --sandbox danger-full-access |
| Resume recent session | Inherited from original | codex exec resume --last 2>/dev/null <<'EOF' + prompt + EOF |
| Run from another directory | Match task needs | -C <DIR> plus other flags 2>/dev/null |
codex command, use the available user-question mechanism to confirm next steps, collect clarifications, or decide whether to resume with codex exec resume --last.codex --version or a codex exec command exits non-zero; request direction before retrying.--sandbox danger-full-access, --dangerously-bypass-approvals-and-sandbox, --dangerously-bypass-hook-trust, --skip-git-repo-check) ask the user for permission using AskUserQuestion unless it was already given.AskUserQuestion.--skip-git-repo-check bypasses an important cwd/worktree guard. Treat it like a boundary exception, not a default.danger-full-access and the --dangerously-* bypass flags are high-impact modes. Prefer read-only, then workspace-write, then modes explicitly listed by the installed CLI, then specific --add-dir grants before considering full access.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.