codex-workspace

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The visible skill is mostly coherent for project setup, but it delegates meaningful behavior to undisclosed local skills and includes potentially autonomous external actions like repo creation, push, and chezmoi sync. Risk comes more from transitive trust and workflow side effects than from confirmed malicious behavior.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/mathruffian-dot%2Fcodex-lazy-packs%2Fcodex-workspace%2F@b1b2b2aadd84cfcfa0e4a9bf9626f9b2373ca4ce845fe94e17fa317cddf5d311
Security Audit — socket — codex-workspace