Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The script deliberately disables ephemeral execution and then scans ~/.codex/sessions to recover generated image data from persisted rollout files. That means prompts, attached image references, and model/session artifacts are stored on disk and later parsed without any explicit user consent or prominent privacy warning, increasing the chance of unintended local disclosure to other processes, backups, or shared accounts.
