This repository is a public template. It is designed to avoid secrets and active external integrations by default.
Open a GitHub security advisory or private issue with:
- affected file or workflow
- expected risk
- reproduction steps that do not include real secrets
- suggested mitigation, if known
Do not paste real API keys, auth files, cookies, tokens, or private customer data into issues.
- No global Codex mutation.
- No required API keys.
- No active MCP, hooks, rules, or plugins by default.
- No network access for sandboxed commands by default.
- Secret scanner reports marker type and path, not values.