invoking-codex-exec
Warn
Audited by Socket on May 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally aligned with its stated purpose and uses an officially sourced Codex tool, so it does not look malicious or exfiltrative. However, it normalizes running a coding agent with sandbox/approval bypass, allows autonomous edits/tests/commits, and enforces reviewer read-only behavior only by prompt plus cleanup, creating medium-high operational risk.
Confidence: 87%Severity: 66%
Audit Metadata