codex-mcp-server-integration
Warn
Audited by Socket on May 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The stated purpose is coherent for a Codex integration, and the OpenAI Codex CLI install path is broadly legitimate. The main risk is that the skill's core execution depends on an external `codex-mcp-server` package run via `npx`, creating a transitive trust chain and potential credential/data forwarding beyond the publisher's own skill. No clear malware or exfiltration is shown, but install trust and third-party execution make this higher than a benign documentation-only skill.
Confidence: 83%Severity: 64%
Audit Metadata