acpx-faq
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. Most of the skill is a legitimate operational guide for acpx, and the codex/claude adapter flows align with the stated purpose. The main issue is the agy workflow: it requires a custom local `.par` executable whose provenance is not verified in the provided evidence, yet it participates in authentication and agent execution. That makes the skill's overall footprint higher risk than a normal documentation skill, even though there is no confirmed malicious payload or explicit exfiltration instruction in the text.
Confidence: 86%Severity: 82%
Audit Metadata