codexsaver-cost-router

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core behavior is broadly aligned with cost-aware LLM routing, but its trust chain is weaker than claimed because installation comes from a mutable GitHub repo owned by a different entity than the stated publisher. Data flows and credential use are mostly proportionate, yet the repo-installed MCP tool receives API keys and code context and forwards them to third-party model providers, creating meaningful supply-chain and data exposure risk.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
May 16, 2026, 06:27 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Fcodexsaver-cost-router%2F@47074da97fc300b4cd1f692126d67a446610ca82