codex-think-about

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core debate workflow is plausible, but the footprint is broadened by a third-party transitive skill install, an authenticated external CLI, and workspace-context forwarding. The main concern is install trust and inherited permissions from npx github:lploc94/codex_skill, which is disproportionate for a reasoning helper unless its provenance is independently verified.

Confidence: 80%Severity: 76%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:38 PM
Package URL
pkg:socket/skills-sh/lploc94%2Fcodex_skill%2Fcodex-think-about%2F@d518f54a07492530708f2fcf6349f66dc6fd14fa