<p align="center"><strong>Codex CLI</strong> is a coding agent from OpenAI that runs locally on your computer. <p align="center"> <img src="https://github.com/openai/codex/blob/main/.github/codex-cli-splash.png" alt="Codex CLI splash" width="80%" /> </p
LPM flags this version as an AI-agent control-surface risk. On global npm installation, the postinstall script deletes the existing `codex` launcher and replaces it with a launcher to this package. This hijacks a broad AI-agent CLI control surface without user confirmation.
Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkgPackage identity and bundled dependencies use `@codexed`, while README presents it as OpenAI Codex.
package.jsonView on unpkg · L2Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/codex.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/codex.jsView on unpkgPackage identity and bundled dependencies use `@codexed`, while README presents it as OpenAI Codex.
README.mdView on unpkg · L1Package identity and bundled dependencies use `@codexed`, while README presents it as OpenAI Codex.
package.jsonView on unpkg · L2Tarball package.json differs from the npm registry version manifest for scripts or dependency sets.
package.jsonView on unpkg · L23Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L24Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L24Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/postinstall.mjsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
bin/codex.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/codex.jsView on unpkgPackage identity and bundled dependencies use `@codexed`, while README presents it as OpenAI Codex.
README.mdView on unpkg · L1