Prompt before trusting local project directories - #36960
Merged
copyberry[bot] merged 1 commit intoAug 4, 2026
Merged
Conversation
## Why Trusting a directory enables project-local config, hooks, and exec policies, which can increase exposure to prompt injection. Require an explicit decision instead of automatically trusting projects whose trust level is unset. ## What changed - Add a directory-trust step to TUI onboarding, with options to trust and continue or quit. - Apply trust to the Git repository root when starting from a subdirectory, persist the decision, and reload config before continuing. - Keep the prompt active and show the config error when trust cannot be persisted. Skip the prompt for remote workspaces and projects with an explicit trust level. ## Testing - Cover trust-screen rendering, keyboard selection, persistence failures, and prompt visibility for explicit trust and Windows sandbox states. GitOrigin-RevId: 850e6f54aec84d584cd161348ecdb1da89aaabd4
copyberry
Bot
force-pushed
the
copyberry/codex-internal-to-codex-oss/850e6f54aec84d584cd161348ecdb1da89aaabd4
branch
from
August 4, 2026 19:48
76739c9 to
17801b4
Compare
copyberry
Bot
deleted the
copyberry/codex-internal-to-codex-oss/850e6f54aec84d584cd161348ecdb1da89aaabd4
branch
August 4, 2026 19:49
davidkneubuehler
temporarily deployed
to
issue-triage
August 4, 2026 19:51 — with
GitHub Actions
Inactive
davidkneubuehler
temporarily deployed
to
issue-triage
August 4, 2026 19:51 — with
GitHub Actions
Inactive
davidkneubuehler
temporarily deployed
to
issue-triage
August 4, 2026 19:51 — with
GitHub Actions
Inactive
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prompt before trusting local project directories
Why
Trusting a directory enables project-local config, hooks, and exec policies, which can increase exposure to prompt injection. Require an explicit decision instead of automatically trusting projects whose trust level is unset.
What changed
Testing