openai-codex-security

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and requested capabilities are broadly coherent for a security scanning integration, and the install path uses npm rather than a raw download-execute chain. However, the exact package and CLI workflow described here could not be confirmed from the retrieved official OpenAI documentation, while the skill is third-party published and encourages forwarding code and credentials to that package. That mismatch creates medium supply-chain and data exposure risk even without direct evidence of malware.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Jul 30, 2026, 12:39 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fcodex-skills%2Fopenai-codex-security%2F@d0960c2469a5aeca4fbbe9037cb8038d05e8a9ac21fbe50028cce417713c3513
Security Audit — socket — openai-codex-security