Skip to content

Security: KevinBigham/codex-safe-starter

Security

SECURITY.md

Security Policy

Supported Scope

This repository is a public template. It is designed to avoid secrets and active external integrations by default.

Reporting A Vulnerability

Open a GitHub security advisory or private issue with:

  • affected file or workflow
  • expected risk
  • reproduction steps that do not include real secrets
  • suggested mitigation, if known

Do not paste real API keys, auth files, cookies, tokens, or private customer data into issues.

Default Security Posture

  • No global Codex mutation.
  • No required API keys.
  • No active MCP, hooks, rules, or plugins by default.
  • No network access for sandboxed commands by default.
  • Secret scanner reports marker type and path, not values.

There aren't any published security advisories