codex-auto-register

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install path is relatively ordinary, but the skill’s actual footprint is high risk: it automates mass account creation, collects and stores passwords plus OAuth tokens, depends on proxies to evade service limits, and optionally uploads those credentials to a third-party CPA endpoint. That combination is disproportionate to any legitimate developer-use skill and creates clear credential-handling and exfiltration risks.

Confidence: 92%Severity: 86%
Audit Metadata
Analyzed At
May 17, 2026, 06:11 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Fcodex-auto-register%2F@05e2ff425697d6897397bdf0e0d5fd8803f6d484