codex-oauth-automation-extension

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s footprint is coherent with its stated purpose, but that purpose is high-risk: automating batch OpenAI account creation, harvesting OTPs from mailboxes, capturing OAuth callback data, and submitting it to an arbitrary CPA panel. No strong malware evidence or hidden payloads are shown, but the autonomous account-registration workflow and third-party callback routing make the skill high security risk.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Apr 11, 2026, 06:32 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fcodex-oauth-automation-extension%2F@32cf3d04cd0b91f6e0a94695b23f418cea333ab2