codex-exec

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. Core functionality is mostly aligned with the stated purpose: it wraps the official local Codex CLI and uses benign load-time checks. The main concerns are the silent remote update check to a mutable personal GitHub raw URL and the optional `npx skills update` transitive install path, which introduce extra supply-chain trust not required to run Codex. No confirmed malware, secret theft, or malicious pre-execution behavior is present.

Confidence: 91%Severity: 56%
Audit Metadata
Analyzed At
May 19, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/abpai%2Fskills%2Fcodex-exec%2F@7651b38bde8cfbaea23dd834a68e5baa75de7a39
Security Audit — socket — codex-exec