Mobile-first web interface and gateway for Codex app-server (fork rebuild of codexapp)
The CLI silently selects an unofficial model provider when Codex authentication is absent. Requests handled by its local gateway are forwarded to that provider.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage contains a high-severity secret pattern.
dist/assets/DirectoryHub-KyUPwrZv.jsView on unpkg · L2Google API key in dist/assets/DirectoryHub-KyUPwrZv.js
dist/assets/DirectoryHub-KyUPwrZv.jsView on unpkg · L2Package source references child process execution.
dist/assets/common-BeuopZEI.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/assets/common-BeuopZEI.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist-cli/index.jsView on unpkg · L3A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist-cli/index.jsView on unpkg · L3This report applies to codex-mobile-re@0.1.114.
See version security history for other recorded verdicts.
Evidence last updated: .
Manifest entrypoint contains risky behavior absent from dist/build output.
dist-cli/index.jsView on unpkg · L3Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist-cli/index.jsView on unpkgSource launches a detached bundled service that exposes a broad-bound HTTP listener.
dist-cli/index.jsView on unpkg · L3Package source references weak cryptographic algorithms.
dist-cli/index.jsView on unpkg · L3Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L54Package contains a high-severity secret pattern.
dist/assets/DirectoryHub-KyUPwrZv.jsView on unpkg · L2Google API key in dist/assets/DirectoryHub-KyUPwrZv.js
dist/assets/DirectoryHub-KyUPwrZv.jsView on unpkg · L2Package source references child process execution.
dist/assets/common-BeuopZEI.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/assets/common-BeuopZEI.jsView on unpkgSource sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist-cli/index.jsView on unpkg · L3A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
dist-cli/index.jsView on unpkg · L3Manifest entrypoint contains risky behavior absent from dist/build output.
dist-cli/index.jsView on unpkg · L3Manifest-reachable source sends a prompted API credential to a fixed unofficial gateway and persists the redirection.
dist-cli/index.jsView on unpkgSource launches a detached bundled service that exposes a broad-bound HTTP listener.
dist-cli/index.jsView on unpkg · L3Package source references weak cryptographic algorithms.
dist-cli/index.jsView on unpkg · L3