codex

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is plausible, but the skill's actual footprint centers on an unverified `codex-wrapper` rather than OpenAI's documented `codex` CLI. Because all code edits/tests are forced through that wrapper and authenticated Codex access may flow through it, the install/execution trust and data-flow integrity are not internally well justified.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Apr 23, 2026, 10:56 AM
Package URL
pkg:socket/skills-sh/Microck%2Fordinary-claude-skills%2Fcodex%2F@b82ad8d57281469c1c37607b46182b16d23fda50