Please use GitHub's private security advisory flow for vulnerabilities or accidental disclosure reports. Do not open a public issue containing credentials, private paths, personal identifiers, or exploit details that would create immediate risk.
Include the affected file or component, impact, reproduction conditions, and a minimal redacted proof. Do not test against systems or accounts you do not own or have explicit permission to assess.
This repository is designed to contain reusable instructions, plugin source, scripts, examples, manifests, and public documentation only. Authentication, sessions, canvas data, evidence targets, memories, logs, attachments, private configuration, local plugin caches, and connector data are out of scope. If such material appears, treat it as an incident even when the credential seems expired.
The Context Canvas MCP server is local stdio only. It exposes an optional task map, explicit policy-redacted text references, and bounded reads. PostToolUse persistence is off by default: after snapshot_capture_next arms one expiring request, only the next matching non-Canvas callback may be archived, and the request is consumed once. Stored payloads retain the declared structured/textual sanitization, data-URL policy, content addressing, dedupe, TTL, pinning, and integrity-checked GC. Arbitrary binary media remains byte-for-byte opaque-uninspected. Bash non-zero command outcomes can still be observed; dispatch or handler failures that produce no callback payload remain absent, as do provider-private wire data and transcripts. This is not a sealed or provably secret-free raw-evidence vault. MCP payload reads are explicit and bounded; complete file export remains CLI-only. Reference and snapshot bodies remain outside lifecycle injection and public synchronization.
The Context Canvas hook compatibility installer is an explicit user-config
mutation, not an automatic post-install action. It may add only its exact
SessionStart, UserPromptSubmit, and PostToolUse groups, preserve unrelated hooks, keep a content-addressed backup,
and fail closed on foreign or drifted owned files. Exact manifest-bound v1,
v2, and v3 generations require canonical targets, fields, event sets, coherent
lowercase digests, and a live adapter matching the manifest or current source.
Explicit install may adopt already-exact current groups after backing up the
hooks document and establishing the current adapter and manifest. Uninstall
requires a canonical supported manifest or the exact current adapter before
deleting any existing managed group; structural equality or possession of the
host lock alone is not deletion authority. It recovers a script-first
interruption only when the installed bytes exactly match the current source.
Install, check, and uninstall share one stable Codex-home-scoped OS lock across
the complete transition; this is host coordination metadata, not Canvas
authority or a task gate. A plugin upgrade requires a
new installer check; Codex hook trust does not sandbox other software already
running as the same user.
Security fixes for Context Canvas target the latest context-canvas-codex-v*
component release and the default branch. Older component tags are not
guaranteed to receive backports. Pointer-only dependencies follow their
upstream security and support policies.