Please report security issues privately through GitHub's private vulnerability reporting, not in a public issue. Include steps to reproduce and the version you tested.
You can expect an acknowledgement within a few days. Once a fix is ready, it ships in a release and the advisory is published with credit to you, unless you prefer otherwise.
This plugin lets an AI agent operate the apps and browser tabs on your computer, so these areas matter most:
- App approvals. The plugin never approves app access itself: Codex's
approval_policyand the approvals stored in ChatGPT/Codex decide, and any prompt Codex forwards to the plugin is declined. A way to make the plugin approve app access is a vulnerability. - Surfaces. The
surfacesoption narrows what a cooperative model uses; it is documented as not being a security boundary. A bypass of OpenCode'scomputer_usepermission rules would be in scope. - The Codex process. The plugin starts
codex app-serverfrom the ChatGPT or Codex app bundle, thecodexPathoption,$OPENCODE_CODEX_COMPUTER_USE_CODEX_PATHorPATH. Anything that makes it run a different binary than the one configured is in scope. - Local files. The optional debug log contains accessibility trees and page text; it is written only when
debugis set.
Issues in OpenAI's Computer Use engine or in Codex itself should go to OpenAI.
Security fixes go into the latest release.