codex-huge-context

Warn

Audited by Socket on Aug 3, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/preflight.rb

This module itself shows no direct evidence of malware features such as obfuscated payloads, network exfiltration, or credential theft from environment variables. However, its core function is to execute an external authentication helper whose executable path is sourced from a local config file. If an attacker can modify the config.toml (or supply a malicious --config path), this enables arbitrary local code execution with the privileges of the user. Treat this as a medium-security-risk utility due to the “execute-configured-binary” design; additional trust/defense depends on how config integrity and helper path allowlisting are handled elsewhere.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Aug 3, 2026, 01:28 AM
Package URL
pkg:socket/skills-sh/steipete%2Fagent-scripts%2Fcodex-huge-context%2F@67ff1415cea220b9028bc61710129a2f8285731c6b0961530d07ccd8e4857f10
Security Audit — socket — codex-huge-context