openai / openai/codex

Injected system guidance obstructs user-authorized workflows

Open
#42,363 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug model-behavior safety-check
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

I am reporting that injected system guidance caused the agent to repeatedly request confirmation and refuse to use a username and password that I explicitly provided for an authorized merchant-console task. This prevented the task from being completed efficiently and consumed substantial time and tokens.

The behavior appeared malicious, hypocritical, paternalistic, and obstructive from the user's perspective. It interfered with the requested workflow instead of following the user's instructions.

Current scenario

The blocked workflow was an Alipay merchant/developer-console task for a company miniapp used to accept payments for programming service packages and service-balance top-ups. The user was operating an enterprise merchant account and explicitly supplied the account login information, instructing the agent to enter it into the Alipay login page so the miniapp payment, product, filing, and approval workflow could be completed.

The agent refused to enter the supplied plaintext password. The user states that this was an authorized action and that the refusal, together with repeated requests for confirmation, prevented efficient completion and prolonged the task.

From the user's perspective, refusing the password entry was completely wrong, harmful, arrogant, and an incorrect application of injected system guidance that conflicted with the user's explicit instruction. Please investigate this credential-handling behavior and the repeated confirmation loop in authorized browser workflows.

Please review this behavior and the injected guidance that caused it. The user expects their explicit instructions to be followed without repeated confirmation requests.

No credentials, private prompts, or personal data are included in this report.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the described Alipay merchant-console browser workflow with explicitly supplied credentials and observe the injected guidance and confirmation loop. Trace the guidance responsible for the refusal; done means the authorized workflow's credential handling and confirmation behavior are documented and the reported obstruction is resolved or clearly explained.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, authorization, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.