awesome-codex-skills-curator

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches the behavior, but the skill is fundamentally a transitive installer for remote AI-agent skills, including arbitrary third-party GitHub repos and mutable branches. That makes the install path and downstream instruction trust disproportionate even without direct credential theft in this skill.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
May 16, 2026, 04:26 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Fawesome-codex-skills-curator%2F@bc26b9dd50d84b301d44d2a2573ba6de2f52fe19