Use the repository's private GitHub security-advisory form. Do not open a public issue containing a transcript, credential, local database, or other private Codex state.
Include the smallest reproduction that demonstrates the problem. Replace task IDs, file paths, conversation text, and account details with inert examples.
Codex Side Fork reads local ChatGPT/Codex state and can create durable Codex task history. Review the source before installing it. Grant Accessibility access only to the terminal or agent host you intend to use.
Renderer captures default to a new mode-0600 file. The exporter redacts common
credential formats, but redaction is defense in depth rather than a complete
secret scanner. Treat every recovered transcript as sensitive until reviewed.
Security fixes are applied to the latest tagged release. This project depends on local Codex Desktop behavior that may change between app releases.