← Files Adaptive Codex OrchestratorARCHIVED FILE

docs/i18n/SECURITY.md

2.59 KB · Sep 30, 2026 · 23:14 UTC

↓ Download file

# Security overview

**English** · [한국어](SECURITY.ko.md) · [日本語](SECURITY.ja.md) ·
[简体中文](SECURITY.zh-CN.md) · [Русский](SECURITY.ru.md)

This is a concise public-review companion to the detailed, authoritative
[Security policy](../SECURITY.md). Adaptive Codex Orchestrator is an
independent community tool, not an official, affiliated, sponsored, or
endorsed OpenAI product.

## Security posture

The plugin is a local, offline control and policy layer. It does not change the
parent model, reasoning setting, permissions, approvals, sandbox, or global
Codex configuration, and it does not make model-generated code safe by itself.
Users must review `hooks/hooks.json` and `hooks/runtime.py` before trusting
hooks, then review generated changes and validation evidence before use.

Key controls include:

- Deterministic, non-LLM command parsing. Prompt text stays in memory for the
  current event and is never stored, logged, evaluated, or inserted into a
  command.
- Invalid JSON, unknown events, unsupported state, and unavailable storage fail
  closed for plugin functionality while normal Codex work continues.
- Schema-versioned state, atomic replacement, best-effort locking, hashed
  project identity, and writes limited to the host-provided `PLUGIN_DATA`.
- Git discovery with an argument array, `shell=False`, captured output, and a
  short timeout. Prompt text is never part of the command.
- Optional, bounded delegation; nested delegation is disabled by default. The
  parent retains security-sensitive decisions, integration, and final review.

The plugin cannot protect a compromised host, operating-system account, Python
runtime, Git executable, or plugin package. It cannot verify the Ultra setting
or guarantee the correctness, security, or availability of model output.

## Reporting a vulnerability

Do not disclose exploit details, credentials, prompts, proprietary source, or
private paths in a public issue. The designated security-reporting candidate is a
[private GitHub advisory](https://github.com/battle-doll/adaptive-codex-orchestrator/security/advisories/new),
which must be enabled and verified before use. If it is unavailable, first ask
the maintainer for a private channel without sharing sensitive details.

Include the affected version, platform and Codex surface, minimal reproduction,
impact, and whether trusted hooks are required. No response-time commitment is
currently made.

Control commands are recognized in Korean and English only. These translations
do not add Japanese, Simplified Chinese, or Russian command support.

SHA-256: c72a7b9d5dd03882932452ccebdf70348a9f335d6a62e0f8b0b74e3ae552e33d