codex-essentials

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose fits a beginner setup skill, and the GitHub MCP server appears broadly consistent with official MCP distribution, but the skill also recommends installing a separate browser tool with unclear provenance and no version pinning or verification. This is not confirmed malware, but it expands agent capabilities through external installs in a way that is only partly justified and only partly verifiable.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/mathruffian-dot%2Fcodex-lazy-packs%2Fcodex-essentials%2F@5b9c26cf52feee28423da3b6b4fa6714079babc4adb76a614420769a4de32de0
Security Audit — socket — codex-essentials