A stronger default for OpenAI Codex CLI: better prompts, one consistent workflow, and runtime helpers. Codex stays the execution engine.
Review flagged AI-agent configuration or capability changes. This remains warn-only unless evidence shows foreign-agent hijack through preinstall/install/postinstall, hidden persistence, exfiltration, remote code execution, or other concrete malicious behavior.
Package source references dynamic require/import behavior.
hooks/goat-hook.mjsView on unpkg · L62Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/cli/commands/setup.jsView on unpkgThe explicit goat setup command modifies project or user Codex agent guidance and hook configuration.
dist/cli/commands/setup.jsView on unpkg · L84The explicit goat setup command modifies project or user Codex agent guidance and hook configuration.
dist/cli/commands/setup.jsView on unpkg · L93This report applies to codex-goat@0.1.5.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
hooks/goat-hook.mjsView on unpkg · L62The explicit goat setup command modifies project or user Codex agent guidance and hook configuration.
dist/cli/commands/setup.jsView on unpkg · L84The explicit goat setup command modifies project or user Codex agent guidance and hook configuration.
dist/cli/commands/setup.jsView on unpkg · L93Manifest-trigger-reachable source writes behavior-bearing configuration into a user or project AI-agent control surface.
dist/cli/commands/setup.jsView on unpkg