
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
DevCodex — AI-powered development workflow rules for Copilot, Claude Code, Codex, Gemini CLI and Grok
DevCodex 是面向 AI 编程宿主的工作流运行时和宿主适配包。它通过 npm 安装到用户环境,将同一套任务路由、Skill 加载、Hook / 指令适配、报告和记忆写入机制接入 Codex、Claude Code、GitHub Copilot、Gemini CLI 和 Grok。
安装完成后,DevCodex 在新会话中按用户请求的意图进入开发、修复、分析、审计等流程,并按需加载内置 Skill 或工作区 Skill。不同宿主的 Hook、指令和插件能力不完全相同;DevCodex 会按宿主能力使用可用的执行方式,并在能力不足时退回指令约束。
DevCodex 不替代业务框架、GitHub CI、安全审计或人工评审。它也不接管 Codex、Claude Code 等宿主原有的个人 Skill、项目指令或配置文件。
DevCodex 给五个宿主提供同一套开发工作流入口:
它主要处理四件事:
>=18先确认本机是否已有 Node.js 和 npm:
node -v
npm -v
如果命令不存在,安装 Node.js LTS:
安装后重新打开终端,再确认:
node -v
npm -v
如果 Node.js 版本低于 18,请先升级 Node.js。
安装前请确认 npm registry 上的版本与本文档对应;如果 registry 上的版本不是当前文档对应版本,不要把下面命令当作当前版本安装。
npm install -g devcodex
devcodex --version
安装完成后,重新打开 Codex、Claude Code、GitHub Copilot、Gemini CLI 或 Grok 的新会话。
npm update -g devcodex
devcodex --version
更新完成后,重新打开宿主的新会话。
npm uninstall -g devcodex
安装或更新 DevCodex 后,npm 会在安装生命周期中刷新用户级宿主适配。已打开的宿主会话通常不会回读刚更新的配置,因此需要重新打开一个新会话。
DevCodex 内置 Skill 随安装包一起提供。普通使用者不需要手动配置内置 Skill;新会话开始后,DevCodex 会按请求意图自动选择需要的 Skill。
如果你希望为某个项目增加自己的流程、检查清单或团队约定,在这个项目根目录下创建工作区 Skill。
这里的“项目根目录”就是你用 Codex、Claude Code、GitHub Copilot、Gemini CLI 或 Grok 打开的业务项目目录。
<你的项目根目录>/
.devcodex/
workspace/
skills/
<id>/
SKILL.md
intent.json
例如:
my-app/
.devcodex/
workspace/
skills/
release-check/
SKILL.md
intent.json
SKILL.md:
---
name: release-check
description: >
当用户准备发布版本、检查 changelog、tag、npm publish 或 GitHub release 时使用。
---
# release-check
## 步骤
1. 检查版本号、变更记录和发布分支。
2. 运行项目约定的测试与打包命令。
3. 输出发布前风险和下一步。
intent.json:
{
"schemaVersion": "SkillIntentV1",
"skillId": "release-check",
"intents": [
{
"id": "release",
"label": "发布检查",
"include": ["发布", "release", "tag", "npm"]
}
],
"examples": {
"positive": ["帮我发版前检查", "准备 npm publish"],
"negative": ["修复登录 bug", "解释这个函数"]
},
"summary": "发布前检查版本、changelog、tag、测试、打包和发布风险。"
}
新建或修改后,重新打开会话,或在后续请求中自然触发相关意图。
Codex、Claude Code 等宿主自己的项目指令、个人 Skill 和配置文件继续按宿主原有规则生效。
DevCodex 不扫描、复制、合并、覆盖或删除这些用户资产。即使名称相同,宿主原生 Skill 也不视为 DevCodex 所有。
如果希望五个宿主通过 DevCodex 使用同一套能力,写 DevCodex 工作区 Skill:
<你的项目根目录>/.devcodex/workspace/skills/<id>/SKILL.md
如果只希望某个宿主单独使用,继续使用该宿主自己的 Skill 或指令机制。
FAQs
DevCodex — cross-host AI coding engineering harness for Codex, Claude Code, GitHub Copilot, Gemini CLI, Grok, and Cursor
The npm package devcodex receives a total of 250 weekly downloads. As such, devcodex popularity was classified as not popular.
We found that devcodex demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.