codex-cli-delegate

Warn

Audited by Socket on Jul 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Suspicious but not clearly malicious. The skill’s behavior is mostly coherent with its stated purpose of delegating work to Codex CLI, and it includes sensible safeguards, but it requires transitive installation from a personal GitHub repo and forwards potentially sensitive local context to an external model via the Codex CLI. Main concerns are supply-chain trust and expanded autonomous action scope, not confirmed credential theft or hidden exfiltration.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Jul 1, 2026, 03:24 PM
Package URL
pkg:socket/skills-sh/DevBD1%2Fskills%2Fcodex-cli-delegate%2F@d5d0f692b55b23a9f24ff144d45727bdb4302079dee286f9182dbd5fb0e1cc2b
Security Audit — socket — codex-cli-delegate