codex-security

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: this router skill is internally consistent and shows no direct credential theft, exfiltration, or supply-chain abuse, but it enables AI-agent security review activity and likely processes untrusted code through an external MCP path. The main concern is category risk and unseen delegated behavior in the parent skill, not confirmed malicious intent in this file.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 20, 2026, 07:24 PM
Package URL
pkg:socket/skills-sh/sd0xdev%2Fsd0x-dev-flow%2Fcodex-security%2F@30d8ee119db52adcb68966f0266ce231b7e553d5