openai-codex-security
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose is plausible, but its install and execution path is not internally consistent with verifiable OpenAI documentation: official sources reference `@openai/codex`, while this skill instructs use of `@openai/codex-security`. Because the unverified CLI would receive both repository contents and API credentials, the main risk is supply-chain compromise and credential forwarding rather than confirmed malware.
Confidence: 91%Severity: 88%
Audit Metadata