Unofficial Windows x64 binary overlay for the OpenAI Codex CLI.
LPM flags this version as an AI-agent control-surface risk. On global npm installation, the postinstall replaces executables inside a separately installed @openai/codex package. This is an unconsented lifecycle mutation of a foreign AI-agent executable.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgIts postinstall automatically starts the installer.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe installer locates the separately installed @openai Codex executable.
install.ps1View on unpkg · L91It copies package-supplied executables over that foreign Codex installation.
install.ps1View on unpkg · L216The launcher invokes PowerShell with execution-policy bypass.
bin/powershell.jsView on unpkg · L22This report applies to @chenronggui/codex-win-patch@0.153.4-patch.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgIts postinstall automatically starts the installer.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe installer locates the separately installed @openai Codex executable.
install.ps1View on unpkg · L91It copies package-supplied executables over that foreign Codex installation.
install.ps1View on unpkg · L216The launcher invokes PowerShell with execution-policy bypass.
bin/powershell.jsView on unpkg · L22