openai-codex-security
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and requested capabilities are broadly coherent for a security scanning integration, and the install path uses npm rather than a raw download-execute chain. However, the exact package and CLI workflow described here could not be confirmed from the retrieved official OpenAI documentation, while the skill is third-party published and encourages forwarding code and credentials to that package. That mismatch creates medium supply-chain and data exposure risk even without direct evidence of malware.
Confidence: 85%Severity: 58%
Audit Metadata