WOAFC Toolkit is a prompt-and-skill plugin. Security reports may still involve unsafe file behavior, sensitive-data exposure, prompt-injection amplification, distribution integrity, or misleading privacy/security guarantees.
| Version | Security status |
|---|---|
Latest immutable, tagged 0.6.x after beta entry gates pass |
Receives best-effort security fixes |
0.6.0 candidate checkout before entry gates/tag |
Pre-release testing only; not a supported distribution |
| Earlier versions | Upgrade or reproduce on the latest 0.6.x before requesting a fix |
| Unreleased branches | Not a supported distribution channel |
Use a private GitHub Security Advisory.
Do not include an exploitable vulnerability, secret, private workspace data, or affected-user identity in a public issue. If the advisory form is unavailable, open a minimal public issue stating only that the private security channel is unavailable; do not disclose technical details there.
Include:
- Affected plugin version, commit, and mirror.
- Codex CLI/host version, model when relevant, and operating system.
- Reproduction steps with a minimal sanitized workspace.
- Expected and actual reads, writes, network effects, or generated artifacts.
- Impact, preconditions, and whether user confirmation was bypassed.
- Suggested mitigation, if known.
Maintainers aim to acknowledge a complete report within five business days and provide an initial severity/scope assessment within ten business days. These are public-beta targets, not guaranteed service levels.
- Plugin distribution or manifest behavior that installs unexpected content.
- A bundled skill causing unauthorized destructive writes or bypassing an explicit no-overwrite/consent contract.
- Sensitive data being included in reports or support artifacts contrary to the documented contract.
- Prompt or reference content that materially amplifies a reproducible injection or data-exfiltration path.
- False security/privacy guarantees presented as proven despite missing evidence.
- Vulnerabilities in Codex, an underlying model/provider, GitHub, GitLab, Python, or the operating system; report those upstream.
- Social engineering without a plugin-specific behavior.
- Generic model hallucination without a reproducible WOAFC contract violation.
- Denial-of-service claims requiring unrealistic local resource use.
- Public disclosure of secrets that were already committed by the reporter.
Give maintainers a reasonable opportunity to reproduce and remediate before public disclosure. A release fix should use an immutable version tag on both release mirrors and document affected versions in the changelog.