codex-plusplus-tweak-system
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent with its stated goal of patching Codex, but that goal itself requires invasive app modification, re-signing, persistence, and risky same-repo download-and-execute installers from a personal publisher. Data flows are mostly coherent and there is no clear credential harvesting, but install/execution trust and system impact are disproportionate enough to classify this as high-risk rather than benign.
Confidence: 90%Severity: 81%
Audit Metadata