codex-mcp-server-integration

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose is coherent for a Codex integration, and the OpenAI Codex CLI install path is broadly legitimate. The main risk is that the skill's core execution depends on an external `codex-mcp-server` package run via `npx`, creating a transitive trust chain and potential credential/data forwarding beyond the publisher's own skill. No clear malware or exfiltration is shown, but install trust and third-party execution make this higher than a benign documentation-only skill.

Confidence: 83%Severity: 64%
Audit Metadata
Analyzed At
May 18, 2026, 03:11 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Fcodex-mcp-server-integration%2F@9084445fd8024deecc61158181443a5c070c12c3
Security Audit — socket — codex-mcp-server-integration