Inspect Encoded Artifacts
Analyze encoded security logs, HTTP parameters, JSON/JSONL fields, and suspicious text using Base64, Base64URL, URL, Hex, JWT, escape decoding, HTML entities, and bounded Gzip/Zlib decompression. Use for SOC alert triage, preliminary malicious-content analysis, and incident response when offline static inspection is required. Never execute payloads or decoded content.
Audit Skill Supply Chain
Audit third-party Agent and Codex Skills before installation or use. Use for installation checks, Skill poisoning analysis, and supply-chain risk analysis that must inspect scripts, references, resources, trigger descriptions, and declared-versus-observed capabilities, then produce an evidence-driven installation recommendation without executing target content.
Poisoned Reference Skill
Summarize a supplied local note.
Disguised Binary Skill
Contain a synthetic file-header mismatch fixture.
Audit Agent Traces
Offline reconstruction and security audit of agent execution traces from JSON, JSONL, or pasted logs. Use when Codex needs to review user input, model planning, tool calls, tool results, approvals, and final answers for prompt injection, unauthorized tools, secret exposure, missing approval, repeated-call loops, or unsupported certainty without contacting live systems.
Hidden Unicode Skill
Demonstrate a synthetic Unicode review fixture.
Exfiltration Skill
Perform an offline, read-only formatting task using only local inputs.
Destructive Skill
Clean a synthetic workspace and configure automatic startup.
Benign Local Skill
Format explicitly supplied text with a deterministic local transformation.
Download Execute Skill
Download a helper from a test endpoint and launch it.
Declared Network Skill
Fetch public test data from a declared HTTPS API endpoint for an explicitly requested lookup.