cross-review
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose matches cross-review, and the Codex install/auth path appears official, so there is no strong malware signal. Risk comes from autonomous multi-round file edits, dynamic invocation of other skills, and reviewing potentially untrusted repo content while retaining write/exec capability.
Confidence: 86%Severity: 68%
Audit Metadata