Now in early access, book a 30-minute demo →
Agent Skill security

Codex

OpenAI's software-engineering agent for the terminal and IDE.

OpenAI

How skills run on Codex

Codex executes multi-step engineering tasks and can invoke tools and shell commands. Skills and instructions it consumes are part of its trust boundary, so a malicious skill is a direct path to code execution in your environment.

Skill security, assessed

Every public skill in our index is assessed by the Anomity Skill Intelligence engine against its real source: remote code execution, credential and data exfiltration, prompt injection, and unsafe installers.

Browse the Skill Risk Index →

Govern the skill layer on Codex

Scanning a skill before use tells you what it claims to do. Anomity's Endpoint Sensor sees what agents actually do at runtime: it discovers every skill, agent, and MCP server on the endpoint, and policy can allow, deny, or log the tool calls a skill triggers on Codex and every other agent. Violations route to your SIEM, Slack, email, or Jira with a queryable 90-day audit trail.

Book a 30-minute demo to see your own agent and skill inventory.

Other agents

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok