codex-plusplus-tweak-system

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its stated purpose as an unofficial Codex patch/tweak system, but it uses high-risk installation patterns (curl|bash and PowerShell iex from raw GitHub), patches and re-signs a local app, installs an auto-repair watcher, and executes tweak code with full Electron renderer privileges. These behaviors are coherent for this kind of app-modding tool, so this is not confirmed malware, but the install and execution trust profile is materially risky and broader than a normal documentation skill.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 17, 2026, 03:54 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Fcodex-plusplus-tweak-system%2F@f916b5d65a7224416b78d2db855d35dfd872e3f6