codex-subagent

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s purpose matches subagent orchestration, and the Codex CLI appears first-party, but it normalizes launching unsandboxed, approval-bypassing autonomous agents that may process untrusted web/codebase content. The main risk is excessive execution freedom and prompt-injection exposure, not confirmed malware or credential theft.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:49 PM
Package URL
pkg:socket/skills-sh/am-will%2Fcodex-skills%2Fcodex-subagent%2F@39e6b56d36c29330d3468adf88b0a61860a8b69f