codex-skill

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated purpose of orchestrating Codex for coding tasks, and the install paths appear normal. However, it materially increases risk by promoting approval bypass, long-running autonomous execution, automatic git push/PR actions, and sending diffs to external model tooling. This looks like a powerful automation skill rather than malware, but its operational scope is high-risk for an AI agent.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:20 PM
Package URL
pkg:socket/skills-sh/feiskyer%2Fopenclaw-kubernetes%2Fcodex-skill%2F@0692d75dc12f35bee8c24eb6e5f06954a19243cf