product-analysis
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core repo-audit purpose broadly matches the capabilities, and the Codex CLI appears to be an official OpenAI tool rather than an unverifiable binary. Risk comes from the skill's autonomy footprint: it can launch an external CLI in full-auto mode over the working directory and can delegate to another skill, creating transitive trust and potential credential/data exposure beyond what a simple product-analysis guide needs.
Confidence: 90%Severity: 61%
Audit Metadata