help

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill/documentation describes a reasonably coherent automatic orchestration tool for OMX with local data analysis. There are legitimate concerns: (1) it reads credential-like local data (token-tracking) which implies sensitive data handling; (2) the first-time setup downloads configuration from an unspecified external source, raising supply-chain risk due to unverifiable provenance; and (3) the tool automates planning and persistence without explicit per-action prompts, which could lead to unintended actions. Overall, the footprint is suspicious enough to warrant caution and stricter provenance checks, but not clearly malicious based on the provided content. Treat as suspicious with mitigations (verify config source, restrict local data access, add per-action user confirmation).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 10:20 PM
Package URL
pkg:socket/skills-sh/yeachan-heo%2Foh-my-codex%2Fhelp%2F@cd64cf842b1729b65ca61357eb4fe9caf28d6a70