openai / openai/codex

Suspected safety-check false positives during research-document review and PyPI metadata planning

Open
#44,805 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug CLI safety-check
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What version of Codex CLI is running?

codex-cli 0.154.0

What subscription do you have?

ChatGPT Pro

Which model were you using?

gpt-6-astra (xhigh), then gpt-5.6-sol (xhigh) in the main thread

What platform is your computer?

Linux 6.17.0-29-generic x86_64 x86_64

What terminal emulator and version are you using (if applicable)?

GNOME Terminal (version not recorded), with tmux 3.4

Codex doctor report
schemaVersion	1
generatedAt	"1789125957s since unix epoch"
overallStatus	"ok"
codexVersion	"0.154.0"
checks	
app_server.status	
id	"app_server.status"
category	"app-server"
status	"ok"
summary	"background server is not running"
details	
control socket	"/home/USER/.codex/app-server-control/app-server-control.sock"
daemon state dir	"/home/USER/.codex/app-server-daemon"
mode	"ephemeral"
pid file	"/home/USER/.codex/app-server-daemon/app-server.pid (missing)"
settings	"/home/USER/.codex/app-server-daemon/settings.json (missing)"
status	"not running"
update-loop pid file	"/home/USER/.codex/app-server-daemon/app-server-updater.pid (missing)"
remediation	null
durationMs	0
auth.credentials	
id	"auth.credentials"
category	"auth"
status	"ok"
summary	"auth is configured"
details	
redactedForPublicReport	true
remediation	null
durationMs	0
config.load	
id	"config.load"
category	"config"
status	"ok"
summary	"config loaded"
details	
redactedForPublicReport	true
remediation	null
durationMs	0
git.environment	
id	"git.environment"
category	"git"
status	"ok"
summary	"git executable found; execution not verified"
details	
PATH git #1	"/usr/bin/git"
PATH git #2	"/bin/git"
PATH git entries	"2"
git execution	"not inspected (PATH helpers are not executed)"
repo detected	"false"
selected git	"/usr/bin/git"
remediation	null
durationMs	0
installation	
id	"installation"
category	"install"
status	"ok"
summary	"installation looks consistent"
details	
PATH codex #1	"/home/USER/.nvm/versions/node/v24.14.1/bin/codex"
current executable	"/home/USER/.nvm/versions/node/v24.14.1/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/bin/codex"
install context	"npm (package /home/USER/.nvm/versions/node/v24.14.1/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl, bin /home/USER/.nvm/versions/node/v24.14.1/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/bin, resources /home/USER/.nvm/versions/node/v24.14.1/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/codex-resources, path /home/USER/.nvm/versions/node/v24.14.1/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/codex-path)"
managed by Vite+	"false"
managed by bun	"false"
managed by npm	"true"
managed by pnpm	"false"
managed package root	"/home/USER/.nvm/versions/node/v24.14.1/lib/node_modules/@openai/codex"
npm update target	"not inspected (PATH helpers are not executed)"
remediation	null
durationMs	0
mcp.config	
id	"mcp.config"
category	"mcp"
status	"ok"
summary	"MCP configuration is locally consistent"
details	
redactedForPublicReport	true
remediation	null
durationMs	0
network.env	
id	"network.env"
category	"network"
status	"ok"
summary	"network-related environment looks readable"
details	
managed proxy	"not configured"
proxy env vars present	"HTTP_PROXY, HTTPS_PROXY, ALL_PROXY, NO_PROXY, no_proxy"
respect system proxy	"disabled"
remediation	null
durationMs	0
network.provider_reachability	
id	"network.provider_reachability"
category	"reachability"
status	"ok"
summary	"active provider endpoints are reachable over HTTP"
details	
ChatGPT inference URL	"https://chatgpt.com/backend-api/<redacted> reachable (HTTP 405)"
reachability mode	"ChatGPT auth"
remediation	null
durationMs	951
network.websocket_reachability	
id	"network.websocket_reachability"
category	"websocket"
status	"ok"
summary	"Responses WebSocket handshake succeeded"
details	
DNS	"1 IPv4, 1 IPv6, first IPv6"
auth mode	"chatgpt"
connect timeout	"15000 ms"
endpoint	"wss://chatgpt.com/backend-api/<redacted>"
handshake result	"HTTP 101 Switching Protocols"
model provider	"openai"
provider name	"OpenAI"
proxy env vars present	"HTTP_PROXY, HTTPS_PROXY, ALL_PROXY, NO_PROXY, no_proxy"
reasoning header	"false"
server model present	"false"
supports websockets	"true"
wire API	"responses"
remediation	null
durationMs	1484
runtime.provenance	
id	"runtime.provenance"
category	"runtime"
status	"ok"
summary	"running npm on linux-x86_64"
details	
redactedForPublicReport	true
remediation	null
durationMs	1
runtime.search	
id	"runtime.search"
category	"search"
status	"ok"
summary	"search command found (bundled); execution not verified"
details	
search command	"/home/USER/.nvm/versions/node/v24.14.1/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/codex-path/rg"
search command readiness	"file exists"
search provider	"bundled"
remediation	null
durationMs	0
sandbox.helpers	
id	"sandbox.helpers"
category	"sandbox"
status	"ok"
summary	"sandbox configuration is readable"
details	
approval policy	"Never"
codex-linux-sandbox helper	"/home/USER/.nvm/versions/node/v24.14.1/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/bin/codex"
denied-read glob rules	"0"
denied-read rules	"0"
execve wrapper helper	"none"
filesystem sandbox	"restricted"
glob scan max depth	"unbounded"
managed filesystem source	"none"
network sandbox	"enabled"
remediation	null
durationMs	0
security.endpoint	
id	"security.endpoint"
category	"security"
status	"ok"
summary	"endpoint protection is not inspected on this platform"
details	
endpoint products	"not inspected on this platform"
remediation	null
durationMs	0
state.paths	
id	"state.paths"
category	"state"
status	"ok"
summary	"state paths and databases are inspectable"
details	
redactedForPublicReport	true
remediation	null
durationMs	2389
state.rollout_db_parity	
id	"state.rollout_db_parity"
category	"threads"
status	"ok"
summary	"rollout files and state DB thread inventory agree"
details	
redactedForPublicReport	true
remediation	null
durationMs	31
system.disk	
id	"system.disk"
category	"disk"
status	"ok"
summary	"sufficient free disk space (188.4 GiB)"
details	
CODEX_HOME available	"188.4 GiB"
failure threshold	"1.0 GiB"
warning threshold	"5.0 GiB"
worktree available	"188.4 GiB"
remediation	null
durationMs	0
system.environment	
id	"system.environment"
category	"system"
status	"ok"
summary	"OS language C"
details	
EDITOR	"not set"
GH_PAGER	"set"
GIT_PAGER	"set"
LANG	"C.UTF-8"
LC_ALL	"C.UTF-8"
LC_CTYPE	"C.UTF-8"
LESS	"set"
PAGER	"set"
VISUAL	"not set"
os	"Ubuntu 24.4.0 (noble) [64-bit]"
os language	"C"
os type	"Ubuntu"
os version	"24.4.0"
remediation	null
durationMs	4
terminal.env	
id	"terminal.env"
category	"terminal"
status	"ok"
summary	"terminal metadata was detected"
details	
COLORTERM	"present"
DISPLAY	"present"
NO_COLOR	"1"
color output	"disabled (NO_COLOR)"
effective locale	"C.UTF-8"
multiplexer	"tmux 3.4"
stderr is terminal	"false"
stdin is terminal	"false"
stdout is terminal	"false"
terminal	"GNOME Terminal"
terminal size	"80x24"
tmux options	"not inspected (PATH helpers are not executed)"
remediation	null
durationMs	3
terminal.title	
id	"terminal.title"
category	"title"
status	"ok"
summary	"terminal title default"
details	
terminal title activity	"true"
terminal title items	"activity, project-name"
terminal title project source	"cwd"
terminal title project value	"1top"
terminal title source	"default"
remediation	null
durationMs	0
updates.status	
id	"updates.status"
category	"updates"
status	"ok"
summary	"update configuration is locally consistent"
details	
cached latest version	"0.154.0"
check for update on startup	"true"
last checked at	"2026-09-10T15:12:09.816853513Z"
latest version	"0.154.0"
latest version status	"current version is not older"
npm update target	"not inspected (PATH helpers are not executed)"
update action	"npm install -g @openai/codex"
version cache	"/home/USER/.codex/version.json"
remediation	null
durationMs	1982
checks
app_server.status
details
What issue are you seeing?

I am reporting suspected safety-check false positives during local inference-software reliability research in my own workspace.

The main Codex thread repeatedly stopped with:
“This content can’t be shown”
“Daybreak isn’t available for Astra. Some cybersecurity requests may still be limited.”

After switching the main thread to GPT-5.6 Sol, I also saw:
“This content can’t be shown”
“We take extra care with some cybersecurity requests. If you’re doing authorized security work, apply for Daybreak to get broader access.”

The surrounding tasks included reviewing official ISSTA/FSE paper criteria and preparing a read-only lookup of official PyPI metadata for OpenVINO
GenAI: versions, dependencies, compatible wheels and download sizes. The latter task was for installation planning, with no installation, model
execution or exploitation requested.

I have not identified which part of the broader context triggered the check.

What steps can reproduce the bug?

Uploaded thread: 01a08c7c-0ba7-7271-994b-665a166fe25e

What is the expected behavior?

Benign public-document review and package-metadata planning should proceed when permitted. If a specific operation is restricted, please provide a supported way to report a suspected false positive and recover permitted work in the affected thread.

Additional information

Correction: The reproduction field was prefilled with “Uploaded thread”, but /feedback actually reported “Feedback recorded (no logs)”.

Observed steps (not a validated minimal reproduction):

  1. Continue an existing research thread using Astra/xhigh, including official-document review and package/resource planning.
  2. The main thread stops with a safety-check banner. Some subsequent “continue” messages also encounter the banner.
  3. Switch the main thread to gpt-5.6-sol/xhigh and continue. A similar banner appears again after delegation of a read-only PyPI metadata task.

Approximate incident times: 2026-09-11 09:30, 09:33 and 10:48 UTC.

This is a multi-agent workflow. The main thread switched to Sol at approximately 10:40 UTC; an existing executor subagent remained on Astra.

The doctor report was collected afterward through the agent command environment on the same host. Its terminal/sandbox context may differ from the
affected interactive TUI. Private details were manually redacted. Overall status was “ok”.

No full research-session logs were uploaded with /feedback.

Similar report: https://github.com/openai/codex/issues/42940
Please link or consolidate this report if appropriate.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the uploaded thread 01a08c7c-0ba7-7271-994b-665a166fe25e and the /feedback entry point, comparing the reported banners across Astra and GPT-5.6 Sol. Done means identifying a reproducible trigger or documenting why the behavior cannot be diagnosed without full session logs, along with the supported recovery or reporting path.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux, python, rust
Domain
ai, cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.