Only the latest commit on the default branch is treated as supported.
Please use GitHub's private vulnerability reporting or a private security advisory for this repository instead of opening a public issue:
https://github.com/lagrangee/coros-codex-mcp-bridge/security/advisories/new
Do not include passwords, OAuth codes, access tokens, refresh tokens, or private sport data in a report. If private reporting is unavailable, contact the repository owner through their GitHub profile and share only the minimum reproducible details.
The bridge is designed to read the official COROS CLI token cache locally. Keep that cache outside the repository, restrict it to the owning user, and rotate/re-authorize it if it may have been exposed.