opencode-openai-codex-auth

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s general purpose matches authentication/configuration, but it relies on a ChatGPT web session token and private backend endpoint rather than a standard documented API flow, while also using direct npx execution from an unpinned package. No clear third-party credential exfiltration is shown, but the install trust and auth model are shaky enough to treat this as medium risk.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
May 19, 2026, 12:59 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Fopencode-openai-codex-auth%2F@926971b1d24684ba2da9c92d50d5e8f9b7870d3e