This is a community desktop integration. Use the latest tagged version and keep Node/dependencies current. No security support SLA is offered.
Do not post credentials, authentication files, database contents, session captures or exploitable private details in public issues. For a sensitive finding, use GitHub's private vulnerability reporting option when available; otherwise ask for a private contact channel without disclosing the vulnerability.
The bridge requires local task-file read access and optional macOS UI-control permission. Keyboard actions affect the active Codex control. It never needs root, Full Disk Access, a new API key or disabling macOS protections for its recommended direct mode.