Please report security issues responsibly so we can address them before public disclosure.
- Email: security@jfrog.com or follow the process described on JFrog's security page.
Include steps to reproduce, affected versions or commits, and impact if known.
This repository ships an OpenAI Codex plugin (skills and an MCP server manifest).
Do not commit secrets, API keys, or credentials, or any local JFrog runtime data the skills write into a workspace (for example under .jfrog/).