codex-review

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/codex-review

No explicit backdoor/exfiltration malware is evident in this wrapper script. However, it intentionally provides multiple high-impact execution and write capabilities driven by external inputs: (1) arbitrary host command execution via --parallel-tests using bash -lc, (2) arbitrary program execution via CODEX_BIN/--codex-bin without integrity checks, (3) arbitrary file write via --output, and (4) default enabling of a “dangerously-bypass-approvals-and-sandbox” flag unless explicitly disabled. Treat this code as high-risk and only run it in a strictly trusted context where CLI args and environment variables are not attacker-controlled.

Confidence: 72%Severity: 73%
Audit Metadata
Analyzed At
May 19, 2026, 08:24 AM
Package URL
pkg:socket/skills-sh/steipete%2Fagent-scripts%2Fcodex-review%2F@c1a51121532166c7960c4aa1bf8e968ded258e31
Security Audit — socket — codex-review