worker

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior mostly matches a team-worker orchestration role and does not request obvious secrets or exfiltrate arbitrary files, but it relies on an unverified `omx` CLI and opaque API path. That unverifiable required executable is the main reason for the elevated risk.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:01 PM
Package URL
pkg:socket/skills-sh/yeachan-heo%2Foh-my-codex%2Fworker%2F@517c4fc3701d646dce2fb4a65b70d77ad35814ad