codex
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose broadly matches coding delegation, and upstream Codex CLI has official distribution channels, but this skill inserts an unverifiable local wrapper and explicitly blocks inspection of the trust-critical code. The main risk is black-box execution with full workspace access and possible hidden credential/data forwarding through the wrapper.
Confidence: 84%Severity: 78%
Audit Metadata