Codex-teammode Workflow ships prompts and documentation, not executable services. Traditional CVE-style vulnerabilities are unlikely.
That said, please report the following privately:
- Prompt-injection patterns that could cause an installing agent to bypass safety rules, for example blindly overwriting target files, exfiltrating secrets, or ignoring the
Hard Rulessection ofBOOTSTRAP_PROMPT.md. - Leaked secrets or PII found anywhere in this repo.
- License or attribution issues.
Email: 19922108279@163.com
Please do not open a public issue for the above.
- Acknowledgement within 7 days.
- A fix or mitigation plan within 30 days where applicable.
- Bugs in third-party AI agents such as Codex or Claude Code. Report those to the vendor.
- General disagreement with workflow choices — please open a regular issue or discussion instead.