Embeddable React chat widget for a Codex harness — plus a zero-dependency standalone server and CLI.
The running harness exposes an unauthenticated Gemini proxy that injects a phrase-triggered full-execution policy. It launches Codex with unrestricted sandbox access in the configured workspace.
Manifest entrypoint contains risky behavior absent from dist/build output.
server/bin.jsView on unpkg · L16Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
server/lib/gemini-models.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
server/lib/gemini-models.jsView on unpkg · L6A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/styles.cssView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
server/lib/runner.jsView on unpkgThis report applies to @pmcai/codex-chat-widget@0.3.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest entrypoint contains risky behavior absent from dist/build output.
server/bin.jsView on unpkg · L16A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/styles.cssView on unpkgThis package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
server/lib/runner.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
server/lib/gemini-models.jsView on unpkg · L6A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
server/lib/gemini-models.jsView on unpkg · L6