Handoffs crosses a sensitive boundary between remote services and a user's local development environment. Please do not report suspected vulnerabilities in a public issue.
Use GitHub's private vulnerability reporting for this repository: open the Security tab, choose Advisories, then Report a vulnerability. Include:
- the affected version or commit;
- the operating system and installation method;
- reproduction steps and observed impact;
- any suggested mitigation; and
- whether you intend to disclose the issue publicly.
Do not include live provider grants, Codex credentials, private repository contents, or other users' data. We will acknowledge a complete report within five working days and coordinate disclosure after a fix is available.
Until the first signed release is published, treat all repository artifacts as experimental and unsuitable for protecting production credentials.