codex-autoresearch

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the main external dependency appears to be the official OpenAI Codex CLI. The major risk is operational: it enables long-running autonomous background sessions with `danger_full_access`, bypassed approvals, no mid-run confirmations, persistent state, and optional outward actions like git push or deploy. That makes it high-risk but not confirmed malicious.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Jul 16, 2026, 04:49 PM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Fcodex-autoresearch%2F@dee2c66bc5292e9a9c867a8fdc2824dcfb975eb922a19cd8bee84f2b781cb98a
Security Audit — socket — codex-autoresearch