Skip to content

Security: llmpolska/codex-clamshell

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not publish security vulnerabilities in a public issue. Contact LLM Polska through llmpolska.pl with reproduction steps and the affected version.

Privileged operation

codex-clamshell runs as a root-owned LaunchDaemon because changing pmset disablesleep requires administrator privileges. The service performs no network requests and executes only fixed system binaries with fixed paths.

Review install.sh, uninstall.sh, and src/codex-clamshell before installation. Installed files are owned by root:wheel and are not writable by regular users.

There aren't any published security advisories