cc-codex-spec-bootstrap

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but it materially broadens trust by chaining multiple external CLIs/MCP servers and delegating work to Codex agents. Main concerns are transitive tool trust and prompt-injection risk from analyzing untrusted repo content while retaining file-write capability; there is no clear evidence of credential theft, covert behavior, or malicious exfiltration.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Mar 13, 2026, 10:02 AM
Package URL
pkg:socket/skills-sh/mindfold-ai%2FTrellis%2Fcc-codex-spec-bootstrap%2F@fe403e7fa1c0579a7681973b9c5a6fa3edd5e3b6