codex-orange-book-guide

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly a documentation/reference guide, but it contains notable trust and scope issues. The largest concerns are inaccurate OpenAI install details, transitive installation of third-party skills from URLs, and credential forwarding into external MCP tooling. Not confirmed malware, but higher-risk than a normal product guide.

Confidence: 90%Severity: 68%
Audit Metadata
Analyzed At
May 19, 2026, 12:59 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Fcodex-orange-book-guide%2F@7df8c887c888937aece161480953c3f11504350f