Skip to content

docs(security): Codex independent pre-release audit prompt (anti-anchoring)#30

Merged
blackaxgit merged 1 commit into
mainfrom
docs/codex-audit-prompt
May 20, 2026
Merged

docs(security): Codex independent pre-release audit prompt (anti-anchoring)#30
blackaxgit merged 1 commit into
mainfrom
docs/codex-audit-prompt

Conversation

@blackaxgit
Copy link
Copy Markdown
Owner

2026-research-grounded prompt + AGENTS overlay for an independent Codex CLI audit of CLX v0.8.1 / [Unreleased]. Anti-anchoring design (RED attacks only; GREEN/PURPLE writeups withheld; arxiv 2603.18740 anchoring effect cuts vuln detection 16-93%). 12 ranked recon targets including T1 (audit_chain.rs per-invocation, not chain), T2 (azure transport tenant leak), T4 (stop-hook summary unredacted), T5 (YAML merge-key inert filter gap), T7 (serde_yml parse-time before filter). Evidence-bundle 4-tuple confidence (no bare percentages). Read-only sandbox + no network + no commits + 90 min RoE. Ready to run via codex-rescue subagent or local Codex CLI; invocation example included.

…verlay

- 2026-research-grounded prompt for an INDEPENDENT second-opinion audit by
  OpenAI Codex CLI (gpt-5.1-codex-max), anti-anchoring by design (RED
  attack register only, GREEN/PURPLE writeups deliberately withheld)
- AGENTS.audit.md persistent execution rules (read-only sandbox, no
  network, no commits, 90 min, evidence-bundle 4-tuple confidence)
- 12 adversarial recon targets (T1 audit_chain per-invocation, T2 azure
  transport-error tenant leak, T4 stop-hook summary unredacted, T5 YAML
  merge-key/anchor inert-filter gap, T7 serde_yml parse-time unsoundness)
@blackaxgit blackaxgit merged commit c82ac42 into main May 20, 2026
7 checks passed
@blackaxgit blackaxgit deleted the docs/codex-audit-prompt branch May 20, 2026 02:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant