codexloop

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities broadly match its stated purpose, but it grants a durable autonomous execution harness with shell-capable verification and mutable local installation paths that are not fully provenance-documented in the skill. No clear malicious exfiltration or deceptive routing is shown, yet the combination of autonomous repo modification, doctor.sh execution, and weak install-source clarity makes it medium risk rather than benign.

Confidence: 81%Severity: 61%
Audit Metadata
Analyzed At
Apr 12, 2026, 02:59 AM
Package URL
pkg:socket/skills-sh/fmschulz%2Fomics-skills%2Fcodexloop%2F@5fc3dfcdf6af00ead13b8a048efd3d38f127c4fc
Security Audit — socket — codexloop