codex

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s main purpose and Codex CLI usage are broadly legitimate and consistent with OpenAI’s official tooling, so it is not fundamentally malicious. However, it weakens safeguards (`--skip-git-repo-check`), encourages potentially autonomous high-impact runs, suppresses stderr by default, and introduces an unnecessary third-party update check plus ambiguous transitive update command outside OpenAI’s trust boundary.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Mar 22, 2026, 04:03 PM
Package URL
pkg:socket/skills-sh/abpai%2Fskills%2Fcodex%2F@9ed397cbfbb68fb70fd12cf84a5c6b6cb9787710