Skip to content

Security: gudszent/TrafficMonitor-CodexQuota

Security

SECURITY.md

Security

Privacy model

CodexQuota does not accept, read, copy, or log browser cookies, passwords, session tokens, API keys, or Codex credential files. The appserver provider starts the official local Codex app-server and requests only derived rate-limit information through account/rateLimits/read. Authentication remains owned by Codex.

Runtime quota state and local JSON input are intentionally ignored by Git because even derived percentages and reset times can be private. Never attach credentials or authentication files to a bug report.

Reporting a vulnerability

Until a repository security contact is configured, do not publish an unpatched credential exposure or code-execution issue in a public issue. Use the repository host's private vulnerability-reporting feature. Ordinary bugs that contain no private data may be reported publicly.

There aren't any published security advisories