codexplusplus-launcher

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated goal of enhancing Codex, but the trust chain is weak: it asks the agent to clone, install, and run a third-party repo that is not verifiably operated by OpenAI or the skill publisher, then grants it deep control over local Codex sessions and UI via CDP injection. That combination is disproportionate enough to classify as high security risk, though not confirmed malware.

Confidence: 86%Severity: 83%
Audit Metadata
Analyzed At
May 16, 2026, 03:29 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Fcodexplusplus-launcher%2F@d1f178c52acaa0c91d9fd71e4a333de3eadeabfd