sample-app-benchmark
Warn
Audited by Socket on Jun 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The benchmark purpose broadly matches the capabilities, and the verified external trust anchor is the official OpenAI Codex CLI. However, the skill’s real execution depends heavily on unverifiable local orchestration/verifier scripts and a local workflow CLI path with no provenance, version pinning, or integrity checks, while also granting broad autonomous code-edit/test/browser actions. No clear credential theft or malicious exfiltration is visible, but the local-tool trust gap and execution breadth make it medium risk.
Confidence: 100%Severity: 60%
Audit Metadata