codex-worker

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The code fragment is a utility README that reliably documents how to spawn parallel Codex CLI agents using git worktrees and tmux. It does not contain obfuscated or overtly malicious code, nor hard-coded secrets. However, it explicitly recommends disabling safety controls (--dangerously-bypass-approvals-and-sandbox) and automates injection of repository data and arbitrary prompts into networked agents. That operational pattern presents a meaningful supply-chain and data-exfiltration risk: sensitive repo contents or credentials accessible to the worktrees can be transmitted off-host or modified without sufficient review. Treat usage as high-risk unless mitigations (sandboxing, egress restrictions, review gates) are applied.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/moonshotai%2Fkimi-cli%2Fcodex-worker%2F@ce87d6620f789cf189779676926402c146332c09