codex-cli-bridge
Audited by Socket on Sep 22, 2026
1 alert found:
AnomalyThis module is not overtly malicious and contains no direct malware behavior (no network exfiltration or credential theft). However, it is a high-impact executor: it forwards arbitrary user-controlled prompts directly to an external `codex` CLI and can run in a write-capable sandbox with optional full automation, applied to a caller-chosen working directory. It also logs the full command and captured output, which can leak sensitive prompt content or tool output. Treat the dependency behavior as supply-chain risk centered on the external `codex` tool and on prompt/workspace trust boundaries; additionally, the provided snippet appears to have a malformed `FileNotFoundError` handler, lowering confidence in completeness of the implementation.