codex-first

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for Codex delegation, and the installer appears official, so this is not malware. However, it grants an external CLI broad autonomous execution, explicitly bypasses approvals/sandboxing, and delegates impactful git/CI actions, making it a high-risk workflow skill.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Sep 19, 2026, 06:02 AM
Package URL
pkg:socket/skills-sh/steipete%2Fagent-scripts%2Fcodex-first%2F@cffb69d3a2367f7650a6ff785958276367bdbe70ea68f3b18c39c40167269db1
Security Audit — socket — codex-first