codex-task-waves

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent for software-task delegation and it uses mostly official tooling, so there is no strong sign of credential theft or overt malware. Risk is elevated because it chains multiple skills, repeatedly delegates write/review actions to Codex, processes untrusted repo content, and allows autonomous push/PR operations.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 5, 2026, 01:16 AM
Package URL
pkg:socket/skills-sh/ddnetters%2Fhomelab-agent-skills%2Fcodex-task-waves%2F@4653a6e09dc75adc5d7527fca62de3be494482e2