You said Codex is cleared for security work on open-source code, so here is a narrow target if you want one. WYWA is an Apache-2.0 persistent Codex runtime; the part I do not trust yet is its closed signed-intake edge: an application flood must not consume consent-withdrawal capacity, even through w...