codex-autoresearch
Warn
Audited by Socket on Jul 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the main external dependency appears to be the official OpenAI Codex CLI. The major risk is operational: it enables long-running autonomous background sessions with `danger_full_access`, bypassed approvals, no mid-run confirmations, persistent state, and optional outward actions like git push or deploy. That makes it high-risk but not confirmed malicious.
Confidence: 85%Severity: 74%
Audit Metadata