codex-app-mirror-installer
Fail
Audited by Snyk on Jun 13, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). These URLs are suspicious: they point to direct installers (.dmg/.msix) served from a third‑party GitHub repo and a private R2 CDN (codexapp.agentsmirror.com / Wangnov/codex-app-mirror) and include checksum files hosted on the same mirror—an effective delivery vector for malware unless you can independently verify the checksums against an upstream trusted source (while some endpoints like api.github.com and persistent.oaistatic.com look legitimate, the use of an unknown mirror and personal CDN raises significant risk).
Issues (1)
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata