codex-candy-eval-benchmark
Warn
Audited by Socket on Jun 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s functionality is coherent for a Codex benchmarking tool and its data flow appears to stay within the official Codex/OpenAI path, but install provenance is weaker than the branding suggests because it clones unpinned source from an unrelated personal GitHub repo with no release/checksum trail.
Confidence: 87%Severity: 56%
Audit Metadata