codexcont-middleware
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s proxy behavior broadly matches its stated purpose, but its trust model is elevated. It asks users to clone and run third-party source code from a personal repo, then route API credentials and prompts through that middleware, with a default upstream endpoint that is not clearly documented as a public API. This is not confirmed malware, but the install provenance and credential-routing footprint are higher risk than a typical API integration skill.
Confidence: 86%Severity: 62%
Audit Metadata