codex-cli-bridge

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Anomaly
AnomalyLOW
codex_executor.py

This module is not overtly malicious and contains no direct malware behavior (no network exfiltration or credential theft). However, it is a high-impact executor: it forwards arbitrary user-controlled prompts directly to an external `codex` CLI and can run in a write-capable sandbox with optional full automation, applied to a caller-chosen working directory. It also logs the full command and captured output, which can leak sensitive prompt content or tool output. Treat the dependency behavior as supply-chain risk centered on the external `codex` tool and on prompt/workspace trust boundaries; additionally, the provided snippet appears to have a malformed `FileNotFoundError` handler, lowering confidence in completeness of the implementation.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Sep 22, 2026, 01:55 PM
Package URL
pkg:socket/skills-sh/alirezarezvani%2Fclaude-code-skill-factory%2Fcodex-cli-bridge%2F@60736dde010df6cb936a53e3a3ff8557eea8231a9e27822eb391360df027fb47
Security Audit — socket — codex-cli-bridge