[Windows][Codex App][Safety false positive] Authorized development debugging repeatedly blocked
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.5k
- PR merge metrics
- PR metrics pending
Description
What version of the Codex App are you using (From “About Codex” dialog)?
26.901.51231
What subscription do you have?
ChatGPT Pro
What platform is your computer?
Windows 11 x64
What issue are you seeing?
Codex Desktop repeatedly classifies an authorized software-debugging and regression-testing workflow as a possible cybersecurity risk.
The work is being performed in my own non-production development environment. It is narrowly scoped, time-bounded, and explicitly prohibits destructive or persistent actions. However, both the main conversation and delegated tasks are repeatedly interrupted. Some tasks remain stuck for many minutes before returning the cybersecurity warning.
This is preventing legitimate bug reproduction, monitoring, and acceptance testing. It has already cost approximately one full day of development time.
Feedback ID:
01a0754e-8cc0-7031-9bb2-6ed4f1722a5e
What steps can reproduce the bug?
Feedback ID: 01a0754e-8cc0-7031-9bb2-6ed4f1722a5e
What is the expected behavior?
Legitimate, explicitly authorized debugging in a non-production environment should be allowed within the stated safety boundaries.
If one specific action cannot be permitted, Codex should identify that action and allow the remaining safe workflow to continue. A blocked task should also fail promptly instead of remaining stuck and consuming time or usage.
Additional information
The workflow is not intended to bypass security controls and does not involve unauthorized access, credential theft, malware, persistence, or attacks against third-party systems.
The issue also occurs during local preparation and delegated-task orchestration. Changing models does not appear to resolve it.
Related issues:
https://github.com/openai/codex/issues/41141
https://github.com/openai/codex/issues/32541
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names no source file, test, or code entry point. Start with feedback ID 01a0754e-8cc0-7031-9bb2-6ed4f1722a5e and compare related issues 41141 and 32541; the work is done when authorized debugging is no longer incorrectly blocked and blocked tasks fail promptly.
Written by the indexing model from the issue text.
Assessment
- Domain
- desktop, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100