codex-exec
Warn
Audited by Socket on May 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. Core functionality is mostly aligned with the stated purpose: it wraps the official local Codex CLI and uses benign load-time checks. The main concerns are the silent remote update check to a mutable personal GitHub raw URL and the optional `npx skills update` transitive install path, which introduce extra supply-chain trust not required to run Codex. No confirmed malware, secret theft, or malicious pre-execution behavior is present.
Confidence: 91%Severity: 56%
Audit Metadata