offload

Warn

Audited by Socket on Jun 16, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md
AnomalyLOW
dispatch.sh

This is primarily an orchestrator/launcher for codex. It shows no clear standalone malware indicators (no network activity, no exfiltration routines, no persistence/backdoors). The main supply-chain security concern is intentional execution with --dangerously-bypass-approvals-and-sandbox and direct injection of the entire BLOCK file contents into codex inputs (tmux/Terminal/headless). If BLOCK or REPO can be influenced by an attacker, this wrapper materially increases the likelihood of high-impact actions by codex. If inputs are fully trusted, risk is lower but still nontrivial due to the bypass flag.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 06:53 AM
Package URL
pkg:socket/skills-sh/borkweb%2Fskills%2Foffload%2F@db4b5983c3dbd99d99b345395fff319af6a03c22e59fa8d52bb49f815abd0c33
Security Audit — socket — offload