codex-task
Warn
Audited by Socket on May 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose and official Codex install path are coherent, and it includes a real shell-injection safeguard, but its default behavior is high risk because it delegates to an external CLI with full filesystem and network access, no approval prompts, and optional proxy routing. This looks like a legitimately purposed but dangerously over-permissive delegation skill, not confirmed malware.
Confidence: 87%Severity: 78%
Audit Metadata