Code Atlas is a local, single-user application. It reads local repositories and can send selected source context to OpenAI through a signed-in Codex CLI. Do not expose its local HTTP server to the internet or open source you are not permitted to share with that account.
If you find a security issue, please avoid posting exploit details or private project data in a public issue. Contact the maintainers through the repository's private vulnerability reporting feature, if available. Otherwise, open an issue asking for a private contact channel without including the sensitive details. There is no guaranteed response time or supported version window yet.
For a suspected compromise, stop the app, clear any affected local data, and follow your organization's incident process. The app's source filter is not a secret scanner.