codex-thread-orchestrator

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Security
SecurityMEDIUM
hooks/user-hooks.json

This configuration sets up an automated `SessionStart` hook (gated by matcher `compact`) that executes a Python script from a user-local, hidden directory under `$HOME/.agents/...`. While the snippet alone shows no explicit malware indicators, it creates a high-impact process-execution path into mutable local filesystem content without any visible integrity checks. Treat as suspicious until the referenced Python script and any verification/permissions are confirmed.

Confidence: 62%Severity: 70%
Audit Metadata
Analyzed At
Aug 20, 2026, 09:03 PM
Package URL
pkg:socket/skills-sh/hosmelq%2Fskills%2Fcodex-thread-orchestrator%2F@df6abf81c370894269ddf6defd64919c1c9fca1335529065f2fd4ac8f9871a54
Security Audit — socket — codex-thread-orchestrator