codex-plan-reviewer

Fail

Audited by Socket on Mar 19, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/codex_review.py

The module itself does not contain active malware or obfuscated payloads, but it creates a moderate supply-chain and data-exfiltration risk by forwarding user-supplied plan and prior-context contents to an external, non-audited 'codex' CLI and persisting the raw responses and plan snapshots to disk. Missing prompt templates (empty REVIEW_PROMPT_* variables) are anomalous and suggest incomplete packaging or tampering. Recommend treating the external CLI as untrusted until audited, avoid sending secrets, add redaction/secret-scanning, populate and verify prompt templates, restrict filesystem permissions for output artifacts, and consider embedding or vetting the review implementation rather than delegating to an external third-party CLI.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 19, 2026, 12:52 PM
Package URL
pkg:socket/skills-sh/mkdir700%2Fmyskills%2Fcodex-plan-reviewer%2F@a727339c2c5bf0bfacec982858a8ebbda66d177c