codex

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The document is legitimate product documentation describing a high-privilege autonomous CLI for code tasks. It is not itself executable malware, but it prescribes dangerous operational modes (full-auto, danger-full-access) and flags that remove safety checks (skip-git-repo-check, resume) which, in implementation or misuse, could enable data exfiltration, credential disclosure, or destructive system/git actions. Treat this as a high-risk tool configuration: require conservative defaults, explicit confirmation for privileged actions, endpoint whitelisting, and strict secret-handling policies before enabling elevated modes.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:07 PM
Package URL
pkg:socket/skills-sh/eyadsibai%2Fltk%2Fcodex%2F@a801532867b271b727bd4035c827a2e18e92efc4