codexmcp-claude-codex-collaboration

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's general purpose is coherent, but its trust chain is not: an ara.so skill instructs the agent to execute a GitHub-hosted MCP server from a different publisher via `uvx`, then route project data and possibly credential-backed Codex activity through it. The capability belongs to the stated purpose, but the install provenance, auto-approval guidance, and optional high-autonomy modes make the overall skill medium-high risk rather than benign.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 17, 2026, 08:23 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Fcodexmcp-claude-codex-collaboration%2F@69f510d4a66b36cbd16addbe4b192462071652a0