Codex's filesystem permission revocation is not reliably enforced, leaving agents with persistent read/write access to user directories after access is revoked in settings.
state: seedheat: mediumuncertainty: mediumconvergesscott: highcodex-permission-revocation agentic-security filesystem-containment sandbox-boundary-integritySome-Following-392OpenAI (Codex)
What is this?
A user (Some-Following-392) reports that Codex CLI continues to read/write folders after the user revoked access in settings โ a concrete sandbox boundary failure. Web results confirm Codex CLI uses a two-layer permission model (OS sandbox + approval policies) with configurable profiles, and show a long-standing GitHub issue (#2847, 441 upvotes) about inability to exclude sensitive files. The specific revocation bug is not directly corroborated in the top results; the evidence title suggests a first-hand report (likely Reddit/GitHub) that isn't surfaced in these snippets.
Why it matters to Scott
Codex CLI's permission-revocation failure is a concrete, high-profile validation of Scott's core argument: approval-based permission models are 'vibes, not architecture' โ structural containment (capability-scope separation, OS-level sandboxing, stateless execution) is required. The bug occurs in a tool Scott actively uses (Codex CLI) and has replicated locally via bubblewrap for Songbird Codex, making it directly relevant to his frameworks, dev projects, and LeverageAI advisory work on agentic security.
ip:framework.siloosip:concept.runtime-containmentip:concept.capability-scope-separationip:concept.stateless-executiondev:technology.bubblewrapdev:technology.codex-clidev:project.askdev:concept.padded-cell-agent-architectureradar:agent-security-framework-portabilityradar:aegis-inline-ebpf-agent-containmentradar:agent-substrate-sandbox-runtimeradar:aisi-agent-container-breakout-benchmarkradar:blast-sandbox-as-a-serviceradar:brig-microvm-agent-containmentradar:bubbleclaude-absent-by-default-sandboxradar:chopi-macos-agent-sandboxradar:concept.agent-harnessradar:concept.coding-agent-harnessesradar:concept.incident-response
queries asked of Scott's wikis
- agentic-security sandbox containment filesystem
- coding-agent permission-revocation boundary-integrity
- local-agent tooling filesystem-access control
- openai-codex cli security-model credential-protection
- agent-harness containment-failure incident-response
Measured heat
now 0 pts/hpeak 2 pts/hcomments 0/hpeers p23momentum: steady1 platformsage 66h
points/hour across evidence ยท reading as of 2026-10-12 02:59:37.977291+11:00 ยท deterministic, not a model opinion
How the heat travelled
pace: p52 vs 1204 stories at the 48h mark (now 66h old) โ ahead of agent-iap-credential-brokering (1.1x), behind asksary-liveloop-stateful-editing (0.9x)
Evidence (1) โ โญ canonical anchor
Interpretation history
2026-10-10T10:29:51Z
grounded: converges/high โ Codex CLI's permission-revocation failure is a concrete, high-profile validation of Scott's core argument: approval-based permission models are 'vibes, not arch
2026-10-09T00:33:38Z
case created โ First-hand user report of concrete containment failure: revoked folder access remains active with read/write capability, directly relevant to agentic-security hot topic and Codex sandbox boundary integrity.
Decision trace
- 10-10 21:29groundCodex CLI's permission-revocation failure is a concrete, high-profile validation of Scott's core argument: approval-based permission models are 'vibes, not architecture' โ structur
- 10-09 20:31sensor_dirtycomment_update
- 10-09 13:18attention_routeThe editor compared this story and chose to keep watching.
- 10-09 13:11attention_candidatecreate
- 10-09 11:33createFirst-hand user report of concrete containment failure: revoked folder access remains active with read/write capability, directly relevant to agentic-security hot topic and Codex sandbox boundary inte