codex-app-mirror-installer

Fail

Audited by Snyk on Jun 13, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). These URLs are suspicious: they point to direct installers (.dmg/.msix) served from a third‑party GitHub repo and a private R2 CDN (codexapp.agentsmirror.com / Wangnov/codex-app-mirror) and include checksum files hosted on the same mirror—an effective delivery vector for malware unless you can independently verify the checksums against an upstream trusted source (while some endpoints like api.github.com and persistent.oaistatic.com look legitimate, the use of an unknown mirror and personal CDN raises significant risk).

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 13, 2026, 12:03 AM
Issues
1
Security Audit — snyk — codex-app-mirror-installer