codex-autoresearch-loop

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core purpose matches its code-editing and git capabilities, but its footprint is riskier than typical dev workflow skills: third-party skill installation from a personal repo despite different branding, autonomous unbounded execution, and web-search-driven iteration with write/exec powers. No confirmed malware or credential theft is shown, but the trust chain and unattended autonomy make it high security risk.

Confidence: 90%Severity: 81%
Audit Metadata
Analyzed At
Sep 12, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Fcodex-autoresearch-loop%2F@601d0c965aa85f7d69ab0153530ce625ebbde8da8277eed45f59e2bfbde986ec
Security Audit — socket — codex-autoresearch-loop