Agent Config Directory Access
- Category
- Agent Snooping
- Confidence
- 90% confidence
- Finding
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
- Content
Also works in OpenAI Codex
The same local MCP server runs in OpenAI Codex — the Codex CLI and IDE extension read MCP servers from
~/.codex/config.toml. With the CLI installed globally (npm i -g @sogni-ai/sogni-creative-agent-skill), register it and start a new Codex session:bash codex mcp add sogni-creative-agent -- node "$(npm root -g)/@sogni-ai/sogni-creative-agent-skill/desktop-extension/server/index.mjs"
