codex-plusplus-tweak-system

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with its stated goal of patching Codex, but that goal itself requires invasive app modification, re-signing, persistence, and risky same-repo download-and-execute installers from a personal publisher. Data flows are mostly coherent and there is no clear credential harvesting, but install/execution trust and system impact are disproportionate enough to classify this as high-risk rather than benign.

Confidence: 90%Severity: 81%
Audit Metadata
Analyzed At
Sep 12, 2026, 11:45 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Fcodex-plusplus-tweak-system%2F@3571533033ae48dc43b3898ed508c37b104339744d01cb681d9dc62220f81d61
Security Audit — socket — codex-plusplus-tweak-system