codex
Warn
Audited by Socket on Jun 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the Codex integration itself is mostly coherent and uses official OpenAI distribution, but the skill's actual footprint is broader than its stated purpose. It mixes a reasonable external AI review wrapper with local helper-script execution, transitive skill invocation, telemetry/logging, outbound project-content transfer to Codex, and some autonomous file/git changes outside the core review task.
Confidence: 100%Severity: 60%
Audit Metadata