Security & supply chainA semicolon in a Codex branch name leaked its GitHub token. Scope decided the damage
BeyondTrust's Phantom Labs found that OpenAI Codex passed branch names into a shell without sanitizing them, so a single semicolon could exfiltrate the task's GitHub OAuth token. The bug is fixed, but agents still commonly hold over-scoped, long-lived credentials, and that is what made it dangerous.