codex-runner

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s main workflow matches its stated purpose, and the underlying Codex CLI is official OpenAI tooling, but the default reliance on a third-party lazycodex/OmO harness plus explicit copying of auth.json tokens into an alternate CODEX_HOME makes the credential and execution footprint broader than a simple bounded worker wrapper. No confirmed exfiltration or malware behavior is present, but the credential forwarding and optional full-access execution raise meaningful security risk.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Jul 16, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Fcodex-runner%2F@ce83f992664abd2e75c3e4502e4d333aa880269c9193aa747815835dac6f02b4
Security Audit — socket — codex-runner