codex-cli-delegate
Warn
Audited by Socket on Jul 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Suspicious but not clearly malicious. The skill’s behavior is mostly coherent with its stated purpose of delegating work to Codex CLI, and it includes sensible safeguards, but it requires transitive installation from a personal GitHub repo and forwards potentially sensitive local context to an external model via the Codex CLI. Main concerns are supply-chain trust and expanded autonomous action scope, not confirmed credential theft or hidden exfiltration.
Confidence: 84%Severity: 62%
Audit Metadata