pluginstaller

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but it imports arbitrary GitHub plugin content into a trusted Codex plugin path and can trigger loading of untrusted instructions/code. No credential theft, proxy routing, or overt malware is shown, but the combination of remote plugin intake, local persistence, and agent/plugin activation makes this a meaningful supply-chain and prompt-injection risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 27, 2026, 12:23 PM
Package URL
pkg:socket/skills-sh/am-will%2Fcodex-skills%2Fpluginstaller%2F@a7121e2903c667c0b47ca0ba39d0b77d6d207db9