Codex CLI Sandbox and Security

Codex CLI has built-in sandboxing mechanisms and security policies to protect system and data security while helping you code. This section details these security mechanisms and how to configure them.


Sandbox Mechanism

Codex executes commands and operates on files in an isolated sandbox environment. This design ensures:

  • Modifications to your project files are controllable
  • Potentially dangerous commands require your confirmation
  • Sensitive data will not be accidentally leaked

The sandbox is the first line of defense in Codex's security policy, ensuring that the AI's operations cannot go beyond your expected scope.


Execution strategy

Codex uses an Execution Policy to control the behavior of different types of operations:

Policy Types

PolicyBehaviorApplicable scenarios
askAsk for confirmation before each executionDaily development (default)
approveAuto-approve executionFully trusted environment
denyReject all operations that may have side effectsRead-only Mode

Operations requiring confirmation

The following types of operations trigger confirmation requests:

  • Executing Shell commands (especiallyrm、killetc.)
  • Modify or delete files
  • Create New File
  • Access sensitive directories (e.g.~/.ssh/、/etc/)
  • Network requests (in specific cases)

Configure execution policy

Set execution policy in configuration

[exec]
default_policy = "ask"

For security reasons, it is not recommended to set the default policy toapprove, unless you fully understand the potential risks.


Confirmation Dialog

When Codex needs to perform sensitive operations, a confirmation dialog is displayed:

══════════════════════════════════════════════════════
  确认执行
══════════════════════════════════════════════════════

  Codex 计划执行以下操作:

  命令: rm -rf node_modules/
  目录: /path/to/project

  这将永久删除目录及其所有内容

  [Y] 确认执行  [N] 取消  [A] 始终允许此类操作
══════════════════════════════════════════════════════

Options Description

OptionsDescription
YExecute only once
NCancel Operation
AAdd rules, then auto-approve

Be careful when choosing "Always Allow" and make sure the operation is indeed safe.


File access control

Protected directories

Some system directories are protected by default, and Codex will ask for additional confirmation when accessing them:

DirectoryDescription
~/.ssh/SSH keys and configuration
~/.aws/AWS Credentials
/etc/System Configuration
~/.git-credentialsGit credential storage

Custom protection rules

You can add custom protection rules in the configuration:

Configuration file access rules

[sandbox]
# Allowed directories
allowed_paths = [
    "~/projects/*",
    "/workspace/*"
]

# Protected directories (require additional confirmation)
protected_paths = [
    "~/.ssh/*",
    "~/secrets/*"
]

Network access control

Codex can restrict the access scope of network requests:

Configure network access

[network]
# Allowed domains
allowed_domains = [
    "github.com",
    "api.openai.com"
]

# Whether to allow local network access
allow_localhost = false

# Whether to allow private network
allow_private_network = false
Restricting network access prevents Codex from accidentally connecting to untrusted services.

Working directory restrictions

You can restrict Codex to operate only in specific directories:

Restrict working directory

[sandbox]
# Codex can only operate in these directories
working_directories = [
    "~/projects/*",
    "/workspace/*"
]

# Behavior when outside directory: warn (warning) or deny (denial)
out_of_bounds = "deny"

Command whitelist/blacklist

Whitelist mode (recommended)

Only allow execution of explicitly listed commands:

Command whitelist

[commands]
# Whitelist mode
whitelist_enabled = true
allowed_commands = [
    "git",
    "npm",
    "node",
    "python",
    "cargo"
]

Blacklist mode

Prohibit execution of specific commands:

Command blacklist

[commands]
# Blacklist mode
blacklist_enabled = true
blocked_commands = [
    "rm -rf /",
    "dd",
    "mkfs"
]
Whitelist mode is more secure and is recommended for use in production environments or when handling sensitive projects.

Sensitive data handling

Automatic blocking

Codex automatically detects and blocks sensitive information:

  • API keys and passwords
  • Tokens and authentication information
  • Personally Identifiable Information (PII)

Environment variable protection

Some environment variables are automatically hidden:

AWS_ACCESS_KEY_ID
AWS_SECRET_ACCESS_KEY
OPENAI_API_KEY
DATABASE_URL

Manually specify sensitive data

You can manually mark content that needs protection in the configuration:

Custom sensitive data patterns

[sensitive]
# Regular expression patterns to block
patterns = [
    "password\\s*=\\s*[^\\s]+",
    "api_key\\s*=\\s*[^\\s]+",
    "secret\\s*=\\s*[^\\s]+"
]

Audit Logs

Codex can record audit logs of all operations:

Enable audit logging

[audit]
enabled = true
log_file = "~/.codex/log/audit.log"

Log content

Audit logs record the following information:

  • Timestamp
  • Operation Type
  • Files or commands involved
  • Operation Result (Success/Failure)
  • User confirmation status

View audit log

# View recent audit logs
tail -f ~/.codex/log/audit.log
Audit logs are very important for security auditing and troubleshooting, especially in team environments.

Security best practices

Development environment

  • Use the default execution policy (ask)
  • Enable audit logging
  • Configure command whitelist

Production Environment

  • Restrict working directory
  • Use whitelist mode
  • Disable unnecessary network access
  • Enable full audit logging

Sensitive Projects

  • Use the strictest protection rules
  • Carefully review every confirmation request
  • Regularly check audit logs

FAQ

Q: Where is the execution policy configured?

The execution policy is mainly through~/.codex/config.tomlConfigure through the configuration file. Some settings can also be configured through environment variables.

Q: What if I accidentally clicked "Always Allow"?

Delete the relevant rules in the configuration file, or delete the entire configuration file and restart Codex, and the rules will be reset.

Q: Can Codex access my GitHub token?

Codex requests the necessary GitHub permissions to perform operations. You can revoke these permissions at any time in GitHub settings.

Q: How to completely disable file modifications?

Set the execution policy todeny, which will prohibit Codex from executing any operations that may modify the file system.

other extensions