Embeddable React chat widget for a Codex harness — plus a zero-dependency standalone server and CLI.
The explicitly started local server accepts cross-origin unauthenticated chat requests by default. Those requests can cause Codex to execute attacker-selected prompts with unrestricted sandbox access in its configured workspace.
Manifest entrypoint contains risky behavior absent from dist/build output.
server/bin.jsView on unpkg · L16Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
server/lib/gemini-models.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
server/lib/gemini-models.jsView on unpkg · L6A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/styles.cssView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
daemon.test.mjsView on unpkgThis report applies to @pmcai/codex-chat-widget@0.3.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest entrypoint contains risky behavior absent from dist/build output.
server/bin.jsView on unpkg · L16A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/styles.cssView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
daemon.test.mjsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
server/lib/gemini-models.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
server/lib/gemini-models.jsView on unpkg · L6