codex-pr-review

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall suspicious-but-not-malicious. The skill's stated purpose and visible behavior are largely coherent and read-only, and using the official Codex CLI is proportionate. The main risk is the prerequisite third-party `npx github:lploc94/codex_skill` install, which adds supply-chain and transitive-skill trust concerns not justified by strong provenance in the provided content.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Mar 24, 2026, 11:36 AM
Package URL
pkg:socket/skills-sh/lploc94%2Fcodex_skill%2Fcodex-pr-review%2F@7cf44872ebf4557bf4578fc106c1699297f6f490