Skip to content

Security: Maoxin1/codex-agents

SECURITY.md

Security Policy

Reporting

Do not open a public issue for vulnerabilities, leaked credentials, private vault paths, holdings, or note content. Use GitHub private vulnerability reporting.

Include the affected commit, files, reproduction steps, impact, and any safe remediation you have identified. Use redacted or synthetic data.

Scope and response

The current main branch is supported. This is a prompt and configuration repository: reports may concern installer behavior, unsafe permissions, prompt-injection boundaries, accidental disclosure, or third-party content provenance.

Maintainers should acknowledge a report before discussing it publicly. No fixed response-time commitment is currently offered.

There aren't any published security advisories