opencode-openai-codex-auth
Warn
Audited by Socket on May 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s general purpose matches authentication/configuration, but it relies on a ChatGPT web session token and private backend endpoint rather than a standard documented API flow, while also using direct npx execution from an unpinned package. No clear third-party credential exfiltration is shown, but the install trust and auth model are shaky enough to treat this as medium risk.
Confidence: 82%Severity: 62%
Audit Metadata