codex-task

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose and official Codex install path are coherent, and it includes a real shell-injection safeguard, but its default behavior is high risk because it delegates to an external CLI with full filesystem and network access, no approval prompts, and optional proxy routing. This looks like a legitimately purposed but dangerously over-permissive delegation skill, not confirmed malware.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
May 19, 2026, 07:40 AM
Package URL
pkg:socket/skills-sh/jiahao-shao1%2Fsjh-skills%2Fcodex-task%2F@3709181dbb66fd0ed8f167d9c0b978d003160e61
Security Audit — socket — codex-task