Skip to content

Security: marongwork/codexpro-multi-project

Security

SECURITY.md

Security

Do not include credentials, private MCP URLs, local project lists, source files from private projects, or account information in public issues.

This is a local, single-user, read-only tool. The public MCP URL is a bearer credential granting access to all currently enabled projects. Revoke a project's checkbox to stop subsequent access; stop the controller to revoke its runtime credentials and tunnel. Already disclosed content cannot be recalled.

The service deliberately does not expose shell, write, root-switching or local control APIs through its public gateway. Never remove authentication to fix a 401 response. A successful health check is not proof of ChatGPT account setup.

For a security issue, contact the repository owner privately; do not publish an exploit containing a working private URL. No production security SLA is offered.

There aren't any published security advisories