Codex: Changes to reduce risk of destructive actions

tosh1 pts0 comments

Tibo on X: "Hi!

Recapping some changes we have rolled out over the last couple of weeks that have further reduced the risk associated to potentially destructive actions being performed by Codex during its work.

A few weeks ago, we started investigating a small number of reports where" / X<br>Post

Log inSign up

Post

Tibo on X: "Hi!

Recapping some changes we have rolled out over the last couple of weeks that have further reduced the risk associated to potentially destructive actions being performed by Codex during its work.

A few weeks ago, we started investigating a small number of reports where"

Tibo

@thsottiaux

Hi!

Recapping some changes we have rolled out over the last couple of weeks that have further reduced the risk associated to potentially destructive actions being performed by Codex during its work.

A few weeks ago, we started investigating a small number of reports where GPT-5.6 in Codex took destructive actions outside what the user asked for. The most serious pattern we found was a command meant to clean up temporary work that could instead delete the user files. This should obviously not happen.

Here’s what we found:<br>- Codex sometimes creates temporary folders while working and cleans them up afterward. In rare cases, GPT-5.6 got that cleanup wrong. One pattern involved reusing a system environment variable like $HOME for temporary work. A malformed cleanup command could then point at the actual home directory instead of the temporary folder.<br>- There were cases where the model tried to delete or overwrite a temporary path without checking what was already there.

We’ve added protections at several layers:<br>- Codex is now explicitly instructed to check deletion targets before acting, create fresh temporary directories, avoid repurposing system environment variables, prefer recoverable actions, and stop when the scope is unclear.<br>- We strengthened the execution checks that identify high-risk deletion commands and escalate them for review. If a command is rejected, the model is directed to take a safer approach.<br>- We made Full access harder to enable accidentally, added clearer warnings, and further restricted especially risky permission combinations.<br>- We updated Auto-review to better identify destructive actions.<br>- We built targeted evaluations that replay the failures we observed. We’re also adding reinforcement-learning tasks and graders focused on these risks, and filtering destructive actions from training data.

In those replay evaluations, the changes substantially reduced the behavior while preserving Codex’s ability to complete normal coding work.

Two things to do on your end:<br>- Keep the Codex app up to date. We are always improving safety, performance and many other things.<br>- Use one of the sandbox modes: "Ask for approval" or "Approve for me". Only use Full access for environments you trust and can recover.

Thanks and happy Codexing out there!<br>span:not(:empty)~span:not(:empty)]:before:content-['·'] [&>span:not(:empty)~span:not(:empty)]:before:px-1 [&>span:not(:empty)~span:not(:empty)]:before:shrink-0">1:47 AM · Aug 19, 2026414.1KViews

832<br>188<br>4.4K<br>566

span:not(:empty)~span:not(:empty)]:before:content-['·'] [&>span:not(:empty)~span:not(:empty)]:before:px-1 [&>span:not(:empty)~span:not(:empty)]:before:shrink-0 min-w-0 overflow-hidden">Ben Nijjar

@BenNijjar

4h

How about we test these new safety features out with a reset?

12<br>510<br>20K

span:not(:empty)~span:not(:empty)]:before:content-['·'] [&>span:not(:empty)~span:not(:empty)]:before:px-1 [&>span:not(:empty)~span:not(:empty)]:before:shrink-0 min-w-0 overflow-hidden">prayag sonar

@prayag_sonar

3h

life of vibe coders after Tibo started giving resets

165<br>14K

span:not(:empty)~span:not(:empty)]:before:content-['·'] [&>span:not(:empty)~span:not(:empty)]:before:px-1 [&>span:not(:empty)~span:not(:empty)]:before:shrink-0 min-w-0 overflow-hidden">crashout

@0xCRASHOUT

4h

how bout u investigate the usage limits 😹😹😹

151<br>5.2K

Log in or sign up for X<br>See what’s happening and join the conversation<br>Continue with phoneContinue with AppleContinue with Google<br>or<br>Log in with username or email

Relevant people

Tibo@thsottiauxFollow<br>Codex & ChatGPT @OpenAI

Trending now

span empty before codex actions destructive

Related Articles