codex-pr-review

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The review workflow is broadly aligned with the stated PR-review purpose, and use of the official Codex CLI is plausible. However, the required installation of `codex-review` via unpinned `npx github:lploc94/codex_skill` from a personal repo creates a transitive trust and supply-chain risk inconsistent with a high-trust review helper. Because that third-party skill pack likely mediates prompts and runner behavior while the user is authenticated to Codex and exposing local repo content, the overall risk is medium-high even without direct evidence of exfiltration or overtly malicious behavior.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 13, 2026, 02:55 PM
Package URL
pkg:socket/skills-sh/lploc94%2Fcodex_skill%2Fcodex-pr-review%2F@2f158f7f6d49f896e2c2299e6a285f1556833b48