codex-image-gen
Warn
Audited by Socket on Aug 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally coherent and routes data only to official OpenAI endpoints, so it does not look malicious. However, it asks the agent to read and reuse raw OAuth credentials from ~/.codex/auth.json via a custom script, including refresh-token handling and token file rewrites, which is more sensitive than necessary and moderately risky.
Confidence: 88%Severity: 58%
Audit Metadata