Codex CLI Sandbox and Security
Codex CLI has built-in sandboxing mechanisms and security policies to protect system and data security while helping you code. This section details these security mechanisms and how to configure them.
Sandbox Mechanism
Codex executes commands and operates on files in an isolated sandbox environment. This design ensures:
- Modifications to your project files are controllable
- Potentially dangerous commands require your confirmation
- Sensitive data will not be accidentally leaked
The sandbox is the first line of defense in Codex's security policy, ensuring that the AI's operations cannot go beyond your expected scope.
Execution strategy
Codex uses an Execution Policy to control the behavior of different types of operations:
Policy Types
| Policy | Behavior | Applicable scenarios |
|---|---|---|
ask | Ask for confirmation before each execution | Daily development (default) |
approve | Auto-approve execution | Fully trusted environment |
deny | Reject all operations that may have side effects | Read-only Mode |
Operations requiring confirmation
The following types of operations trigger confirmation requests:
- Executing Shell commands (especially
rm、killetc.) - Modify or delete files
- Create New File
- Access sensitive directories (e.g.
~/.ssh/、/etc/) - Network requests (in specific cases)
Configure execution policy
Set execution policy in configuration
default_policy = "ask"
For security reasons, it is not recommended to set the default policy to
approve, unless you fully understand the potential risks.
Confirmation Dialog
When Codex needs to perform sensitive operations, a confirmation dialog is displayed:
══════════════════════════════════════════════════════ 确认执行 ══════════════════════════════════════════════════════ Codex 计划执行以下操作: 命令: rm -rf node_modules/ 目录: /path/to/project 这将永久删除目录及其所有内容 [Y] 确认执行 [N] 取消 [A] 始终允许此类操作 ══════════════════════════════════════════════════════
Options Description
| Options | Description |
|---|---|
Y | Execute only once |
N | Cancel Operation |
A | Add rules, then auto-approve |
Be careful when choosing "Always Allow" and make sure the operation is indeed safe.
File access control
Protected directories
Some system directories are protected by default, and Codex will ask for additional confirmation when accessing them:
| Directory | Description |
|---|---|
~/.ssh/ | SSH keys and configuration |
~/.aws/ | AWS Credentials |
/etc/ | System Configuration |
~/.git-credentials | Git credential storage |
Custom protection rules
You can add custom protection rules in the configuration:
Configuration file access rules
# Allowed directories
allowed_paths = [
"~/projects/*",
"/workspace/*"
]
# Protected directories (require additional confirmation)
protected_paths = [
"~/.ssh/*",
"~/secrets/*"
]
Network access control
Codex can restrict the access scope of network requests:
Configure network access
# Allowed domains
allowed_domains = [
"github.com",
"api.openai.com"
]
# Whether to allow local network access
allow_localhost = false
# Whether to allow private network
allow_private_network = false
Restricting network access prevents Codex from accidentally connecting to untrusted services.
Working directory restrictions
You can restrict Codex to operate only in specific directories:
Restrict working directory
# Codex can only operate in these directories
working_directories = [
"~/projects/*",
"/workspace/*"
]
# Behavior when outside directory: warn (warning) or deny (denial)
out_of_bounds = "deny"
Command whitelist/blacklist
Whitelist mode (recommended)
Only allow execution of explicitly listed commands:
Command whitelist
# Whitelist mode
whitelist_enabled = true
allowed_commands = [
"git",
"npm",
"node",
"python",
"cargo"
]
Blacklist mode
Prohibit execution of specific commands:
Command blacklist
# Blacklist mode
blacklist_enabled = true
blocked_commands = [
"rm -rf /",
"dd",
"mkfs"
]
Whitelist mode is more secure and is recommended for use in production environments or when handling sensitive projects.
Sensitive data handling
Automatic blocking
Codex automatically detects and blocks sensitive information:
- API keys and passwords
- Tokens and authentication information
- Personally Identifiable Information (PII)
Environment variable protection
Some environment variables are automatically hidden:
AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY OPENAI_API_KEY DATABASE_URL
Manually specify sensitive data
You can manually mark content that needs protection in the configuration:
Custom sensitive data patterns
# Regular expression patterns to block
patterns = [
"password\\s*=\\s*[^\\s]+",
"api_key\\s*=\\s*[^\\s]+",
"secret\\s*=\\s*[^\\s]+"
]
Audit Logs
Codex can record audit logs of all operations:
Enable audit logging
enabled = true
log_file = "~/.codex/log/audit.log"
Log content
Audit logs record the following information:
- Timestamp
- Operation Type
- Files or commands involved
- Operation Result (Success/Failure)
- User confirmation status
View audit log
tail -f ~/.codex/log/audit.log
Audit logs are very important for security auditing and troubleshooting, especially in team environments.
Security best practices
Development environment
- Use the default execution policy (ask)
- Enable audit logging
- Configure command whitelist
Production Environment
- Restrict working directory
- Use whitelist mode
- Disable unnecessary network access
- Enable full audit logging
Sensitive Projects
- Use the strictest protection rules
- Carefully review every confirmation request
- Regularly check audit logs
FAQ
Q: Where is the execution policy configured?
The execution policy is mainly through~/.codex/config.tomlConfigure through the configuration file. Some settings can also be configured through environment variables.
Q: What if I accidentally clicked "Always Allow"?
Delete the relevant rules in the configuration file, or delete the entire configuration file and restart Codex, and the rules will be reset.
Q: Can Codex access my GitHub token?
Codex requests the necessary GitHub permissions to perform operations. You can revoke these permissions at any time in GitHub settings.
Q: How to completely disable file modifications?
Set the execution policy todeny, which will prohibit Codex from executing any operations that may modify the file system.