Codex Data Tool handles files that can contain account state, conversation history, source code, project names, absolute paths, Git settings and SSH keys.
Do not attach a generated backup directory, manifest.json, ZIP package,
configuration JSON, reconciliation report, SQLite database or JSONL session
file to a public issue or repository. These files may reveal private data even
when their names look harmless.
SSH backup is disabled by default. Enable it only when you understand that the resulting package may contain private keys.
Please open a GitHub security advisory instead of a public issue when a report needs to include exploit details or sensitive examples. Replace all real user names, host names, IP addresses, project names and local paths with placeholders.
Release notes include the SHA256 hash of the Windows executable. This project does not currently provide a code-signing certificate, so Windows SmartScreen may show an unknown-publisher warning.