codex-exec

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Codex-exec skill description and workflow are coherent with its stated purpose of facilitating non-interactive Codex prompts via a CLI. The installation and authentication steps reference official sources (npm registry and Codex CLI) and rely on environment-based credentials, which is standard. The data flows to OpenAI and back, with optional local output. The main security considerations are the use of an external CLI (potentially enabling autonomous actions when --full-auto is used) and the handling of credentials for API access. Overall, the footprint is proportionate to the stated purpose, with no evident malicious data exfiltration or credential harvesting patterns observed in the provided fragment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 03:16 AM
Package URL
pkg:socket/skills-sh/baekenough%2Fbaekenough-skills%2Fcodex-exec%2F@2a66a32bfea18236033473a21998f784a88c3c5c