Codex All-in-One for ArkClaw

PassAudited by VirusTotal on May 16, 2026.

Findings (1)

The skill bundle automates the installation and configuration of the Codex CLI, performing several high-risk operations including modifying `~/.bashrc` for persistence, installing global packages via `npm` and `pip`, and running background relay services. It handles sensitive API keys for multiple AI providers (AgentPlan, Kimi, DeepSeek) and stores them in local configuration files and environment variables. While these actions are consistent with the stated purpose of a 'one-click' setup utility, the modification of shell startup scripts and the handling of credentials represent a significant security surface. Legitimate endpoints used include ark.cn-beijing.volces.com and api.moonshot.cn.