Skip to content
GloamereEvidence-led Codex tools
EvalWorkflowsSupport
4.0 Beta / Codex only
GitHub

Policy / Security

Verify the release. Report vulnerabilities privately.

Before the beta tag exists, reports target the release candidate; afterward, fixes target the latest published Gloamere 4.x tag.

Supported versions

Historical 3.x artifacts are retained for traceability, but they are not an active compatibility or security-support surface.

Report a vulnerability

Use GitHub private vulnerability reporting. Do not open a public issue for a suspected vulnerability.

Include the affected plugin and version, Codex, Python, and operating system versions, impact, reproduction steps, and a minimal proof of concept. Remove API keys, tokens, private prompts, personal paths, and customer data.

Gloamere will acknowledge the report through GitHub and coordinate disclosure after a fix is available. The beta does not promise a fixed response-time SLA.

Security boundary

  • The prepared plugins contain no Gloamere backend, telemetry, hooks, MCP servers, or background services.
  • Plugins still operate within the permissions and tools granted to Codex; users should review requested actions and protect local inputs.
  • Install immutable tagged releases and compare archives against their published SHA-256 sidecars.
  • Missing, malformed, truncated, or unknown Eval evidence is non-verified. A model statement is not proof that a Skill was loaded.
Gloamere

Evidence-led tools for Codex.

SupportPrivacyTermsSecuritySource

MIT licensed. Beta candidate. No Gloamere backend or telemetry.