codex

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected This skill's stated purpose and most of its capabilities are consistent: handing a task to a local Codex CLI that can read git state and modify files is coherent. However, the skill defaults to an automatic 'full-auto' mode that enables workspace-write and auto-approval, and it invokes an external 'codex' binary whose origin and network behavior are unspecified. Those two facts make this skill SUSPICIOUS for supply-chain risk: it grants powerful file-modifying and execution privileges to an external agent without clear provenance or mandatory human approval. Recommend treating the skill as high-risk unless the codex CLI's source is verified, the default is changed to read-only or require explicit approval, and network endpoints used by the CLI are audited.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 20, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/NeverSight%2Fskills_feed%2Fcodex%2F@887d5907e480145e74b17d8c1d96386f9276097a