simplify-pr-codex

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the skill outsources its entire function to an unpinned third-party npm package executed via `bunx @latest` with Bash access and a forced 1-hour runtime. Without strong same-org verification and transparent data-flow limits, this is a high supply-chain and execution-trust risk disproportionate to a simple PR-simplification workflow.

Confidence: 86%Severity: 81%
Audit Metadata
Analyzed At
Apr 11, 2026, 12:50 AM
Package URL
pkg:socket/skills-sh/WillBooster%2Fagent-skills%2Fsimplify-pr-codex%2F@539e15e9fb1e0381359346b44a6f415782e64c55
Security Audit — socket — simplify-pr-codex