codex-claude-cursor-loop
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s behavior is broadly aligned with its stated purpose, and the external tools appear to be official OpenAI and Cursor CLIs rather than unknown payloads. The main risk is proportionality and trust: it delegates implementation and review to external vendor agents, sending code/task data off-host and allowing autonomous local code changes through third-party CLIs. No clear credential-harvesting or deceptive data-routing is shown, but the workflow meaningfully expands execution and data exposure.
Confidence: 84%Severity: 58%
Audit Metadata