Skip to content

Security: sandbaseai/sandbase-codex-plugin

Security

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not disclose vulnerabilities, credentials, tokens, or private account data in a public issue.

Use GitHub's private vulnerability reporting for the implementation repository:

https://github.com/sandbaseai/cli/security/advisories/new

Include the affected version, reproduction steps, expected and observed behavior, and the minimum proof needed to demonstrate impact. Remove credentials and personal data from logs and screenshots.

Scope

This repository packages the official SandBase Codex plugin. The CLI and MCP implementation are maintained in sandbaseai/cli, so implementation vulnerabilities should be reported there.

There aren't any published security advisories