codex-deep-search

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose broadly matches deep research, and the Codex CLI dependency is plausibly official, but the skill's actual footprint is wider than necessary because it routes outputs through Telegram and relies on an unseen local wrapper script. The main risk is third-party data flow and unattended background execution, not confirmed malware.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Mar 24, 2026, 04:19 PM
Package URL
pkg:socket/skills-sh/yanyang1116%2Fskills%2Fcodex-deep-search%2F@68e1f7fe24cfaca95edd12dbe5b6f9ca8f74db2b