codex-subagent
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS: the skill’s purpose matches subagent orchestration, and the Codex CLI appears first-party, but it normalizes launching unsandboxed, approval-bypassing autonomous agents that may process untrusted web/codebase content. The main risk is excessive execution freedom and prompt-injection exposure, not confirmed malware or credential theft.
Confidence: 88%Severity: 68%
Audit Metadata