Skip to content

Security: jfrog/codex-plugin

Security

SECURITY.md

Security

Reporting a vulnerability

Please report security issues responsibly so we can address them before public disclosure.

Include steps to reproduce, affected versions or commits, and impact if known.

Scope

This repository ships an OpenAI Codex plugin (skills and an MCP server manifest).

Do not commit secrets, API keys, or credentials, or any local JFrog runtime data the skills write into a workspace (for example under .jfrog/).

There aren't any published security advisories