Exposing a GitHub token in a public repository
alignment.openai.com
alignment.openai.com
But what’s crazy to me is that the agent had write access to the codex repo in the first place. WTF
Not sure exactly how that works since I’d imagine that the key needs to be there in full eventually?