codex-image

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The image-generation purpose is plausible and the data ultimately goes to OpenAI-owned domains, but the skill's core behavior hinges on automatically extracting and caching a ChatGPT browser session token for use with an unofficial internal endpoint. That credential-handling footprint is broader and less proportionate than a normal image API skill, especially with an unspecified browser automation dependency.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
May 16, 2026, 07:11 AM
Package URL
pkg:socket/skills-sh/OpenMinis%2FMinisSkills%2Fcodex-image%2F@778ca742cc7ccb715fea056678774db1e04cc9fe
Security Audit — socket — codex-image