T08 · Insecure Dependencies
- Location
SETUP.md:15- Finding
Unpinned Executable Installed from a Third-Party Homebrew Tap
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent monitoring purpose, but it installs an unpinned third-party binary that reads sensitive Codex session history.
Review the CodexMonitor source and Homebrew formula before installing, and treat Codex session logs as confidential. Use the narrowest session directory possible, avoid pointing CODEX_SESSIONS_DIR or CODEX_HOME at shared or synced locations, and do not leave watch running longer than needed.
SETUP.md:15Unpinned Executable Installed from a Third-Party Homebrew Tap
SKILL.md:34Third-Party Binary Receives Access to Sensitive Codex Session History
The setup explicitly directs the tool to read Codex session logs from ~/.codex/sessions or override paths, but it does not warn that these files may contain sensitive prompts, outputs, file paths, tokens, or other conversation artifacts. Because this skill is specifically designed to inspect and watch local session data, the lack of privacy and data-handling guidance increases the chance of unintentional exposure or misuse of sensitive information.
No suspicious patterns detected.