jaan-to-codex-pack

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
skills/dev-output-integrate/SKILL.md

SUSPICIOUS. The core behavior mostly matches a code-integration skill, and the documented package-manager/MSW commands point to legitimate ecosystems rather than attacker infrastructure. However, the skill has unusually broad write/edit authority, can execute unpinned install/run commands, relies on opaque local pre-execution protocol documents, and encourages follow-on skill execution. No confirmed credential theft, covert exfiltration, or malicious pre-execution command is visible, so this is not malware, but it carries meaningful workflow and supply-chain risk.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Sep 4, 2026, 09:35 AM
Package URL
pkg:socket/skills-sh/parhumm%2Fjaan-to%2Fjaan-to-codex-pack%2F@ffe2d3b0692eec0a0b8db6f05a01e19199a1cc26ac8e74bbcdcf999fa6c77c7f
Security Audit — socket — jaan-to-codex-pack