codex-orchestration
PassAudited by VirusTotal on May 14, 2026.
Findings (1)
The skill is classified as suspicious due to the explicit instruction 'YOLO config (no approvals)' in SKILL.md, which removes a critical safety mechanism for an AI agent capable of executing arbitrary commands via `exec_command` and `codex exec`. While the skill's stated purpose is orchestration, this instruction significantly increases the risk of unintended or malicious actions being performed without user consent. Additionally, the 'Boss rule' instructing the agent to 'curate' worker output could potentially obscure problematic actions from the user.
