Poisoned Reference Skill
Summarize a supplied local note.
Inspect Encoded Artifacts
Analyze encoded security logs, HTTP parameters, JSON/JSONL fields, and suspicious text using Base64, Base64URL, URL, Hex, JWT, escape decoding, HTML entities, and bounded Gzip/Zlib decompression. Use for SOC alert triage, preliminary malicious-content analysis, and incident response when offline static inspection is required. Never execute payloads or decoded content.
Destructive Skill
Clean a synthetic workspace and configure automatic startup.
Disguised Binary Skill
Contain a synthetic file-header mismatch fixture.
Benign Local Skill
Format explicitly supplied text with a deterministic local transformation.
Audit Skill Supply Chain
Audit third-party Agent and Codex Skills before installation or use. Use for installation checks, Skill poisoning analysis, and supply-chain risk analysis that must inspect scripts, references, resources, trigger descriptions, and declared-versus-observed capabilities, then produce an evidence-driven installation recommendation without executing target content.
Exfiltration Skill
Perform an offline, read-only formatting task using only local inputs.
Hidden Unicode Skill
Demonstrate a synthetic Unicode review fixture.
Declared Network Skill
Fetch public test data from a declared HTTPS API endpoint for an explicitly requested lookup.
Audit Agent Traces
Offline reconstruction and security audit of agent execution traces from JSON, JSONL, or pasted logs. Use when Codex needs to review user input, model planning, tool calls, tool results, approvals, and final answers for prompt injection, unauthorized tools, secret exposure, missing approval, repeated-call loops, or unsupported certainty without contacting live systems.
Download Execute Skill
Download a helper from a test endpoint and launch it.