codex-skill

Fail

Audited by Socket on Jun 23, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The Codex Agent Skill fragment describes a highly capable automation workflow enabling autonomous code changes, dependency installations, and PR-based delivery with strong operational autonomy. While this supports hands-off task execution, the explicit use of security-bypassing flags and automation-heavy patterns introduce non-trivial supply-chain and runtime risks. Data flows include code changes, dependency installation, repository state mutations, and PR propagation, with potential leakage through logs or prompts. Treat as SUSPICIOUS with elevated risk; enforce per-action prompts, sandboxing, restricted network access, and strict secret handling before deployment in real-world environments.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Jun 23, 2026, 09:48 AM
Package URL
pkg:socket/skills-sh/LeoYeAI%2Fopenclaw-master-skills%2Fcodex-skill%2F@18d402d1a68ad45f90925ef1d2324ce7d259213a02131de1328490132f05ddc3
Security Audit — socket — codex-skill