Please do not publish credentials, private Codex transcripts, or sensitive configuration in a public issue.
For a suspected security/privacy bug, open a GitHub security advisory for this repository when available, or contact the maintainer privately through their GitHub profile.
High-priority issues include: persisting raw prompts/responses, destructive writes to ~/.codex, executing untrusted hook payload content, leaking credentials into speech/notifications, or unsafe privilege escalation.