Please report a suspected profile-crossing bug privately rather than opening a public issue containing account, workspace, project, or authentication data.
Never attach auth.json, browser data, Codex databases, prompts, thread exports, or an unredacted --include-paths report. A safe report should contain the codex-lanes version, macOS version, official ChatGPT app version, the failing check code, and a minimal synthetic reproduction.
The following are documented non-goals, not vulnerabilities by themselves:
- access by device management, endpoint security, or another same-user process;
- shared system Keychain, SSH agent, Git credential helper, or network monitoring;
- deliberate bypass by launching the official App or CLI outside codex-lanes;
- a folder manually opened from the official App before the next audit.