
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@codragraph/codex
Advanced tools
OpenAI Codex CLI integration for CodraGraph — graph-aware context for Codex commands via codex.config.json hooks.
OpenAI Codex CLI integration for CodraGraph. Enriches every Codex tool call with graph-aware context (callers, impact, process participation) and FeatureCluster packs for product areas like Settings/Auth/AI, so Codex doesn't blindly grep its way through the codebase.
# 1) Install the codragraph CLI
npm install -g @codragraph/cli
# or: bun add -g @codragraph/cli --trust
codragraph setup
# 2) Install this integration globally
npm install -g @codragraph/codex
# or: bun add -g @codragraph/codex --trust
# 3) Wire it into Codex. Merges the bundled hooks into ~/.codex/config.json
# (substituting the absolute install path so Codex finds the hook script)
# and registers an mcpServer entry whose launcher is platform-correct:
# `codragraph mcp` on macOS/Linux, `cmd /c codragraph mcp` on Windows
# (Node 22's spawn can't launch `.cmd` shims directly).
codragraph-codex
The
codragraph-codexcommand is idempotent — re-run it after upgrades. A sidecar~/.codex/.codragraph-managed.jsontracks which entries the installer owns, so user-managed hooks/mcpServers are never overwritten.
codragraph augment <pattern> and prepends the graph
context to Codex's next prompt. The hook reads bounded output from stdout or
stderr because augment may write graph context on either stream.detect-changes, and never starts analyze in the background.codragraph Codex MCP server (launching
codragraph mcp, or cmd /c codragraph mcp on Windows) so Codex can
call query / context / impact / feature_clusters / feature_context / cypher directly.API keys live in ~/.codragraph/config.json — the unified file the CLI,
harness, and web app all use.
codragraph config set openai --api-key sk-...
Apache-2.0. You can use, modify, redistribute, bundle, and host this integration commercially, subject to the Apache-2.0 notice and attribution requirements.
FAQs
OpenAI Codex CLI integration for CodraGraph — graph-aware context for Codex commands via codex.config.json hooks.
We found that @codragraph/codex demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.