codex-task-waves

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent for software-task delegation and it uses mostly official tooling, so there is no strong sign of credential theft or overt malware. Risk is elevated because it chains multiple skills, repeatedly delegates write/review actions to Codex, processes untrusted repo content, and allows autonomous push/PR operations.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 5, 2026, 01:16 AM
Package URL
pkg:socket/skills-sh/ddnetters%2Fhomelab-agent-skills%2Fcodex-task-waves%2F@4653a6e09dc75adc5d7527fca62de3be494482e2
Security Audit — socket — codex-task-waves