codex-app-mirror-installer
Fail
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides numerous instructions and script examples for downloading Windows (MSIX) and macOS (DMG) installer files from an unofficial third-party GitHub repository (Wangnov/codex-app-mirror) and a custom domain (codexapp.agentsmirror.com).
- [REMOTE_CODE_EXECUTION]: By encouraging the download and execution of binary installers from unverified third-party mirrors, the skill creates a path for potential remote code execution. The provided 'verified checksums' are self-referential, as both the installers and the checksum files are hosted on the same untrusted infrastructure, offering no protection against a compromised mirror.
- [COMMAND_EXECUTION]: The documentation contains multiple shell, PowerShell, and Python scripts designed to automate the download, verification, and inspection of software packages. These scripts involve network requests and file system operations that pose a risk if executed without thorough manual review.
Recommendations
- AI detected serious security threats
Audit Metadata