codex-autoresearch-skill

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core behavior largely matches its stated purpose, but it normalizes high-risk autonomy by recommending bypassed approvals, background execution, persistent hooks, inferred shell command execution, and optional web-search-driven iteration. The install path is transparent source code from GitHub rather than an opaque binary, so this is not confirmed malware, but it is a high-risk autonomous agent skill.

Confidence: 88%Severity: 79%
Audit Metadata
Analyzed At
May 16, 2026, 08:24 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Fcodex-autoresearch-skill%2F@65c89514b0889491a778b3c035b2cfdc3f38d15b