codex-image-gen

Warn

Audited by Socket on Aug 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent and routes data only to official OpenAI endpoints, so it does not look malicious. However, it asks the agent to read and reuse raw OAuth credentials from ~/.codex/auth.json via a custom script, including refresh-token handling and token file rewrites, which is more sensitive than necessary and moderately risky.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Aug 17, 2026, 04:43 PM
Package URL
pkg:socket/skills-sh/zjp1997720%2Fzhijian-skills%2Fcodex-image-gen%2F@0d3cff6fbce00f05d3deddfaa770a0c87f3e1ce0254c31f4e1256a6a702f66f3
Security Audit — socket — codex-image-gen