codex-first-customer-finder-skill
Warn
Audited by Socket on Jul 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the install/execution trust is not: the skill executes remote npm code at install time and references a personal GitHub repo that is not clearly verifiable as the same publisher as ara.so. No obvious credential harvesting is described, and outreach is manual-only, so this is not confirmed malware; the main concern is supply-chain trust and the inability to verify actual package behavior from the provided material.
Confidence: 83%Severity: 72%
Audit Metadata