Codex Resource Audit v0.1.0
Codex Resource Audit v0.1.0
First public release of Codex Resource Audit — a Windows-first, read-only evidence tool for attributing Codex-owned processes and explaining lifecycle observations without unsafe assumptions.
Observe → Verify → Attribute → Explain → Compare
What it helps you do
A typical workflow is:
- Discover possible Codex root candidates.
- Independently verify one current root using PID + creation time + executable path.
- Capture the task across S0–S4.
- Compare what appeared, changed, or was no longer observed.
- Attribute processes only when ownership evidence is sufficient.
- Review lifecycle evidence separately.
The core principle is:
See what changed. Claim only what the evidence supports.
Highlights
- Candidate discovery with neutral grouping and Quick Index
- Explicit operator-verified root workflow
- Exact process identity using PID + creation time + executable path
- Fail-closed Codex ownership attribution
- S0–S4 foreground Session capture
- Concise Evidence Summary
- Lifecycle
UNKNOWNexplanations - Synthetic/offline examples for safe evaluation
- Windows GitHub Actions offline CI
Safety boundaries
UNKNOWN != CODEX
CANDIDATE_ONLY != VERIFIED_ROOT
ATTACHED_BROWSER != CODEX_OWNED
PROCESS_SURVIVAL != RESIDUE
PROCESS_SURVIVAL != ORPHAN
PARENT_NOT_OBSERVED != EXIT_CONFIRMED
NO_LONGER_OBSERVED != EXIT_CONFIRMED