run-codex-bridge
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but its trust model is weak because it asks the agent to install and rely on a third-party codex-worker CLI via curl|bash from a personal GitHub publisher. The main risk is supply-chain and opaque credential/data handling inside the external tool, not obvious malicious instructions in the skill itself.
Confidence: 84%Severity: 80%
Audit Metadata