codex-essentials

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches installing beginner integrations, so there is no strong purpose mismatch, but it broadens trust by instructing the agent to install unpinned third-party npm and pip packages. The main risk is supply-chain exposure and possible credential forwarding to the GitHub MCP server, not confirmed malware.

Confidence: 87%Severity: 54%
Audit Metadata
Analyzed At
Sep 8, 2026, 05:58 AM
Package URL
pkg:socket/skills-sh/mathruffian-dot%2Fcodex-lazy-packs%2Fcodex-essentials%2F@6499c28a328453c48754efa57668640bfd8810e2717ac53d7a24b7d28519db7b
Security Audit — socket — codex-essentials