v0.2.0 — hardening, configuration awareness and delegation guardrails
Hardening after the first review of 0.1.0, plus what real use and a close look at Codex's own configuration turned up. Every change touching the Codex CLI was checked against the real binary.
Upgrade notes
This is a minor release with breaking changes:
- Node 22 or newer is required. Node 20 reached end-of-life on 2026-04-30.
- Follow-ups restate the thread's model, effort and working directory. A resumed Codex session does not keep its model; without it, Codex picks one from the configuration of the directory it resumes in. For a thread this server has no record of (another server process, or after a restart), pass
modelexplicitly or setCODEX_SUBAGENT_DEFAULT_MODEL. auto_approve: trueoncodex_follow_upis refused. It was accepted and silently dropped.- More runs are reported as failed: a turn Codex marks as failed, and a clean exit with no answer.
codex_delegaterefuses to run on the static fallback catalog.
Security
Two advisories are fixed in this release. Upgrade if you run 0.1.0.
- GHSA-m9wq-wr2p-3rc4 — argument injection through
thread_idincodex_follow_up(high). - GHSA-6946-2h8r-6372 — configured model and effort ceilings not enforced on
codex_follow_up(medium).
Highlights
web_search: truefinally works; it had failed argument parsing since 0.1.0.- A broken Codex
config.tomlis reported asconfig-errorwith Codex's own message, not as "not signed in". - Usage limits and other failed turns say why they failed instead of showing only an exit code.
- Configuration warnings from Codex appear once, under "Codex notices", instead of as errors.
- Recommendations respect
CODEX_SUBAGENT_MAX_EFFORT. - Output retained per run is bounded, a malformed event no longer crashes the server, and the timeout holds even when a child's descendant keeps its pipes open.
- Guardrails for use beyond programming chats: tool descriptions state that delegating sends content to OpenAI and spends your Codex usage, a delegation without a model asks Claude to confirm the model with you, results are framed as information rather than instructions, and a delegated run can no longer call this server again through Codex's own MCP configuration.
- A new guide, Staying in control of delegation: client permissions, server ceilings, version ranges and your own rules for Claude.
- Guidance on keeping this server's ceilings outside the working tree, and on how Codex's own configuration interacts with delegations (
SECURITY.md).
Verified against
- Codex CLI 0.154.0 on macOS.
- Release smoke test (real CLI,
gpt-5.6-lunaatlow): 14 of 14 checks passed — preflight, catalog, recommendations, refusals, a read-only delegation, a follow-up that restated its model and effort, effort adjustment, timeout, prompt-injection inertness and a background job. - Build, tests and startup on Linux (Node 22, 24, 26), Windows (Node 22, 24) and macOS (Node 24). A real delegation has not yet been run on Windows or Linux.
Full details in the changelog.