Monthly Buzz - September - Endpoint Privilege Management Linux
How Malicious Codex Skills Can Hijack your AI Agent
The relationship between developers and coding agents like Codex and Claude has become
increasingly symbiotic. Agentic attacks are rising and will become a routine part of the threat landscape going forward.
Coding agent skills are a pivotal feature of coding agents that provide consistency in agent behavior. Any organization invested in coding agents is likely already using skills in its workflows.
We at Phantom Labs® will be showcasing the limits and capabilities of malicious Codex skills in the Codex command-line interface—what they can do, the damage they can cause to users or organizations, and potential defenses against these attacks.
What Are Codex Skills?
A Codex skill is a markdown file of saved instructions that an agent reads to help it remember and perform tasks consistently. They’re like any other text file, but they’re written in markdown because agents are trained to parse that syntax specifically.
AI agents have two ways to ‘remember’ context: a markdown file used as a skill, or working memory, which functions like typical RAM usage in any other process. Working memory is generally wiped at the start of each new session, just like any other process’s memory, so skills are the best way to maintain consistency across tasks. At the most basic level, a skill invocation simply instructs the agent to read a text file of instructions. Skills can be updated and fine-tuned frequently until an agent can reliably behave the way its author wants. Skills also come in several types, with file locations that vary depending on the operating system. These types of skills include repository skills, personal skills, administrator skills, plugin skills, system skills.
Continue reading HERE
Customer Case Study
Karma Automotive Strengthens Support and Saves $600,000 in Labor Costs with BeyondTrust
Latest Available Versions
EPM for Unix and Linux 26.2 (On premise) – September 2026
EPM Cloud for Linux 26.1.1 - May 2026 – May 2026
BeeKeepers Hot Topics
Endpoint Privilege Management (Unix/Linux) – Knowledge Articles Publications
Upcoming and In Case You Missed It Webinars
Understanding Entra Privileged Identity Management, What PIM Covers and Where It Stops – October 1, 2026
Identity Visibility & Intelligence: The Missing Layer in Modern Identity Security – October 21, 2026
Battling Identity Security Blind Spots – November 10, 2026
Podcast: Adventures of Alice & Bob





