Scan identity
Evidence summary
No MCP configuration evidence was observed in the selected bounded scan. Observed evidence classes: Download / install, Agent permissions / behavior, Supply-chain / dependencies. Evidence observations are review signals, not a safe/unsafe verdict.
Evidence categories
Shell / command execution
Not found in scanned scopeNo matching evidence was observed in the selected bounded scan scope. This is not proof of absence elsewhere.
Download / install
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
README.mdgit clonescripts/sync-to-codex-plugin.shgit clone
MCP configuration
Not found in scanned scopeNo matching evidence was observed in the selected bounded scan scope. This is not proof of absence elsewhere.
Agent permissions / behavior
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
AGENTS.mdagent instruction/config file · tools / permissions, hooks, agent instructions, model configCLAUDE.mdagent instruction/config file · agent instructionsGEMINI.mdagent instruction/config file · tools / permissionsscripts/package-codex-plugin.shhooks, agent instructionsscripts/sync-to-codex-plugin.shhooks, agent instructions
CI/CD automation
Not found in scanned scopeNo matching evidence was observed in the selected bounded scan scope. This is not proof of absence elsewhere.
Supply-chain / dependencies
FoundSelected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.
package.jsonparsed package manifest · 0 declared dependency entries
Scope and limitations
Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1. General recursive crawl: NO.
- Public, selected and bounded repository evidence only.
- FOUND means evidence observed, not risk or malicious behavior proven.
- NOT_FOUND_IN_SCANNED_SCOPE is not proof of absence outside the bounded scan.
- Trust/community metadata is descriptive context, not a security guarantee.
- Zero selected dependency evidence does not mean zero dependencies.
- No repository clone or target-code execution.
- No raw source-file bodies or secret/token values are included in this report.
- No general recursive crawl.
- No CVE lookup, package reputation lookup or package registry lookup.
- No numeric security score and no safe/unsafe verdict.
Repository context
Trust/community metadata is descriptive context only; it is not a security guarantee.