exec

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior is broadly aligned with its stated purpose as a plan executor, but its footprint is high-risk: unrestricted Bash, repeated bypassPermissions subagents, autonomous code/review/finalize loops, and optional execution of an unverified external_review_cmd. The default Codex path appears legitimately documented by OpenAI and is not itself a malicious indicator, but the overall skill still grants disproportionate autonomy and exposes prompt-injection and command-execution risk.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
May 13, 2026, 06:12 AM
Package URL
pkg:socket/skills-sh/umputun%2Fcc-thingz%2Fexec%2F@7696129ccf92c0b168b881787bbe2bacbc86e443
Security Audit — socket — exec