AGENT LAB: SKILLS

codex-subagent

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill/package is functionally coherent and implements the documented capability to spawn background subagents and capture outputs. It does not contain direct obfuscated malware or hard-coded credentials in the provided text. However, it intentionally promotes disabling sandbox/approval safeguards and autonomous, non-interactive operation — decisions that materially increase the risk of credential leakage, data exfiltration, uncontrolled network activity, and runaway costs. Treat this as an operationally risky component: acceptable only with strict controls (no sandbox bypass, explicit approvals, secrets redaction, endpoint whitelists, rate-limits, and monitoring). Recommended mitigations: remove or disable dangerous flags from examples, add clear warnings about never embedding secrets in prompts, require explicit human approval before launching subagents, add endpoint whitelisting, and log/monitor subagent activity.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:19 PM
Package URL
pkg:socket/skills-sh/am-will%2Fcodex-skills%2Fcodex-subagent%2F@39e6b56d36c29330d3468adf88b0a61860a8b69f