Please open a private security advisory if the repository is hosted on GitHub, or contact the maintainer through the repository owner's preferred channel.
Do not include exploit details in a public issue before the maintainer has had time to review the report.
Codex Maintainer Kit reads local repository metadata and writes optional Markdown/template files. Security-sensitive changes should pay special attention to path handling, file writes, and future integrations that might read remote content.