Skip to main content
Community Manager
September 30, 2026
Sticky

Monthly Buzz - September - Endpoint Privilege Management

  • September 30, 2026
  • 0 replies
  • 16 views

How Malicious Codex Skills Can Hijack your AI Agent

The relationship between developers and coding agents like Codex and Claude has become
increasingly symbiotic. Agentic attacks are rising and will become a routine part of the threat landscape going forward. 

Coding agent skills are a pivotal feature of coding agents that provide consistency in agent behavior. Any organization invested in coding agents is likely already using skills in its workflows.  

We at Phantom Labs® will be showcasing the limits and capabilities of malicious Codex skills in the Codex command-line interface—what they can do, the damage they can cause to users or organizations, and potential defenses against these attacks. 

What Are Codex Skills?

A Codex skill is a markdown file of saved instructions that an agent reads to help it remember and perform tasks consistently. They’re like any other text file, but they’re written in markdown because agents are trained to parse that syntax specifically. 

AI agents have two ways to ‘remember’ context: a markdown file used as a skill, or working memory, which functions like typical RAM usage in any other process. Working memory is generally wiped at the start of each new session, just like any other process’s memory, so skills are the best way to maintain consistency across tasks. At the most basic level, a skill invocation simply instructs the agent to read a text file of instructions. Skills can be updated and fine-tuned frequently until an agent can reliably behave the way its author wants. Skills also come in several types, with file locations that vary depending on the operating system. These types of skills include repository skills, personal skills, administrator skills, plugin skills, system skills. 
Continue reading HERE

Customer Case Study

Karma Automotive Strengthens Support and Saves $600,000 in Labor Costs with BeyondTrust

Latest Available Versions

EPM for Windows and Mac (Cloud and Pathfinder)  v26.2.1697 – June 2026
EPM for Windows 26.2.1 - June 2026
EPM for Mac v26.2.1 – June 2026

 

BeeKeepers Community


CrowdStrike & ServiceNow Integration with Endpoint Privilege Management Using Risk Scores
 

Description of Integration: The integration described in this guide uses webhooks and API requests to allow users to approve EPM BeyondTrust application access request tickets in ServiceNow using risk and severity scores from CrowdStrike, which eliminates manual intervention and delays, helping organizations improve their overall security posture. 

Disclaimer This integration is an example of a working prototype and will not be supported by BeyondTrust. Any sample or proof of concept code (“Code”) provided on the Community is provided “as is” and without any express or implied warranties. This means that we do not promise that it will work for your specific needs or that it is error-free. Such Code is community supported and not officially supported by BeyondTrust. BeyondTrust and its contributors are not liable for any damage you or others might experience from using the Code, including but not limited to, loss of data, loss of profits, or any interruptions to your business, no matter what the cause is, even if advised of the possibility of such damage. 
 

The required permissions in the BeyondTrust Product to be able to configure the integration:
 

Access to a Privilege Management tenant is required and an account with the Administrator role. The required permissions/access level in ServiceNow to be able to configure the integration:

  • An active BeyondTrust Privilege Management (EPM) API account

    • The API account will require Full Access to the Command API. 

    • OAuth Provider (BeyondTrust EPM OAuth) in the ServiceNow Application Registry configured with your Endpoint Privilege Management settings: 

    • Client ID and Secret of your Endpoint Privilege Management (EPM) Access API account 

    • For the token URL, add your Endpoint Privilege Management (EPM) instance 

  • ServiceNow instance with Flow Designer and Security Incident Response application enabled.

  • CrowdStrike API credential alias named crowdstrike_api already configured in ServiceNow (Connection & Credential Aliases). This is the same alias used by the existing identity risk score action.

  • An active license for the EPM Servicenow Integration app - BeyondTrust Privilege Management JIT Integration - ServiceNow 

To view Video and Continue Reading Check HERE

 
Upcoming and In Case You Missed It Webinars

Understanding Entra Privileged Identity Management, What PIM Covers and Where It Stops – October 1, 2026
Identity Visibility & Intelligence: The Missing Layer in Modern Identity Security – October 21, 2026
Battling Identity Security Blind Spots – November 10, 2026
User Group: Q3-Americas EPM
Podcast: Adventures of Alice & Bob

This topic has been closed for replies.