openai-codex-security

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is plausible, but its install and execution path is not internally consistent with verifiable OpenAI documentation: official sources reference `@openai/codex`, while this skill instructs use of `@openai/codex-security`. Because the unverified CLI would receive both repository contents and API credentials, the main risk is supply-chain compromise and credential forwarding rather than confirmed malware.

Confidence: 91%Severity: 88%
Audit Metadata
Analyzed At
Jul 30, 2026, 12:37 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fsecurity-skills%2Fopenai-codex-security%2F@0c99c4e5048449d727c0c57a583a7f6e2303b9bcd6f85bf4fc48820a108ec8b5
Security Audit — socket — openai-codex-security