codex-thread-orchestrator

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Security
SecurityMEDIUM
hooks/user-hooks.json

This configuration sets up an automated `SessionStart` hook (gated by matcher `compact`) that executes a Python script from a user-local, hidden directory under `$HOME/.agents/...`. While the snippet alone shows no explicit malware indicators, it creates a high-impact process-execution path into mutable local filesystem content without any visible integrity checks. Treat as suspicious until the referenced Python script and any verification/permissions are confirmed.

Confidence: 62%Severity: 70%
Audit Metadata
Analyzed At
Jul 27, 2026, 10:12 PM
Package URL
pkg:socket/skills-sh/hosmelq%2Fskills%2Fcodex-thread-orchestrator%2F@fe798dd8b89e9509e3343dc7448104dd3a3f37138996917c41d6ff272271eb21
Security Audit — socket — codex-thread-orchestrator