team

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core behavior matches its stated tmux orchestration purpose, but its footprint is high risk because it grants a third-party runtime durable control over multiple Codex/Claude sessions, automates commits and cleanup, and explicitly bypasses normal permission prompts with `--dangerously-skip-permissions` and auto-accept behavior. This is not confirmed malware, but it is operationally dangerous and should be treated as a high-risk orchestration skill.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
May 18, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/Yeachan-Heo%2Foh-my-codex%2Fteam%2F@47fcf802dce9a9fed7fa2f3ffe77204407525459
Security Audit — socket — team