2026-10-11 16:37 UTC

Codex's filesystem permission revocation is not reliably enforced, leaving agents with persistent read/write access to user directories after access is revoked in settings.

state: seedheat: mediumuncertainty: mediumconvergesscott: highcodex-permission-revocation agentic-security filesystem-containment sandbox-boundary-integritySome-Following-392OpenAI (Codex)

What is this?

A user (Some-Following-392) reports that Codex CLI continues to read/write folders after the user revoked access in settings โ€” a concrete sandbox boundary failure. Web results confirm Codex CLI uses a two-layer permission model (OS sandbox + approval policies) with configurable profiles, and show a long-standing GitHub issue (#2847, 441 upvotes) about inability to exclude sensitive files. The specific revocation bug is not directly corroborated in the top results; the evidence title suggests a first-hand report (likely Reddit/GitHub) that isn't surfaced in these snippets.

Why it matters to Scott

Codex CLI's permission-revocation failure is a concrete, high-profile validation of Scott's core argument: approval-based permission models are 'vibes, not architecture' โ€” structural containment (capability-scope separation, OS-level sandboxing, stateless execution) is required. The bug occurs in a tool Scott actively uses (Codex CLI) and has replicated locally via bubblewrap for Songbird Codex, making it directly relevant to his frameworks, dev projects, and LeverageAI advisory work on agentic security.
ip:framework.siloosip:concept.runtime-containmentip:concept.capability-scope-separationip:concept.stateless-executiondev:technology.bubblewrapdev:technology.codex-clidev:project.askdev:concept.padded-cell-agent-architectureradar:agent-security-framework-portabilityradar:aegis-inline-ebpf-agent-containmentradar:agent-substrate-sandbox-runtimeradar:aisi-agent-container-breakout-benchmarkradar:blast-sandbox-as-a-serviceradar:brig-microvm-agent-containmentradar:bubbleclaude-absent-by-default-sandboxradar:chopi-macos-agent-sandboxradar:concept.agent-harnessradar:concept.coding-agent-harnessesradar:concept.incident-response
queries asked of Scott's wikis
  • agentic-security sandbox containment filesystem
  • coding-agent permission-revocation boundary-integrity
  • local-agent tooling filesystem-access control
  • openai-codex cli security-model credential-protection
  • agent-harness containment-failure incident-response

Measured heat

now 0 pts/hpeak 2 pts/hcomments 0/hpeers p23momentum: steady1 platformsage 66h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion

How the heat travelled

10-08 22:01โญ origin directly observedCodex accessing folders I revoked access to days ago.
Some-Following-392 on r/OpenAI
โ€”
10-08 22:01amplified on r/OpenAI ๐Ÿ‘‘reddit.post.1x145ev
Some-Following-392
peak 2 ยท 7 comments ยท 100% of case engagement
10-08 22:31our radar first saw it ยท +0.5hdiscovery anchor: reddit.post.1x145evโ€”
pace: p52 vs 1204 stories at the 48h mark (now 66h old) โ€” ahead of agent-iap-credential-brokering (1.1x), behind asksary-liveloop-stateful-editing (0.9x)

Evidence (1) โ€” โญ canonical anchor

sourceobjectauthorscorecomments
๐ŸŸ  reddit โญCodex accessing folders I revoked access to days ago.
OpenAI
Some-Following-39227

Interpretation history

Decision trace