Skip to content

v0.2.0 — hardening, configuration awareness and delegation guardrails

Choose a tag to compare

@parisbs parisbs released this 14 Sep 21:31
· 47 commits to main since this release
bf88742

Hardening after the first review of 0.1.0, plus what real use and a close look at Codex's own configuration turned up. Every change touching the Codex CLI was checked against the real binary.

Upgrade notes

This is a minor release with breaking changes:

  • Node 22 or newer is required. Node 20 reached end-of-life on 2026-04-30.
  • Follow-ups restate the thread's model, effort and working directory. A resumed Codex session does not keep its model; without it, Codex picks one from the configuration of the directory it resumes in. For a thread this server has no record of (another server process, or after a restart), pass model explicitly or set CODEX_SUBAGENT_DEFAULT_MODEL.
  • auto_approve: true on codex_follow_up is refused. It was accepted and silently dropped.
  • More runs are reported as failed: a turn Codex marks as failed, and a clean exit with no answer.
  • codex_delegate refuses to run on the static fallback catalog.

Security

Two advisories are fixed in this release. Upgrade if you run 0.1.0.

  • GHSA-m9wq-wr2p-3rc4 — argument injection through thread_id in codex_follow_up (high).
  • GHSA-6946-2h8r-6372 — configured model and effort ceilings not enforced on codex_follow_up (medium).

Highlights

  • web_search: true finally works; it had failed argument parsing since 0.1.0.
  • A broken Codex config.toml is reported as config-error with Codex's own message, not as "not signed in".
  • Usage limits and other failed turns say why they failed instead of showing only an exit code.
  • Configuration warnings from Codex appear once, under "Codex notices", instead of as errors.
  • Recommendations respect CODEX_SUBAGENT_MAX_EFFORT.
  • Output retained per run is bounded, a malformed event no longer crashes the server, and the timeout holds even when a child's descendant keeps its pipes open.
  • Guardrails for use beyond programming chats: tool descriptions state that delegating sends content to OpenAI and spends your Codex usage, a delegation without a model asks Claude to confirm the model with you, results are framed as information rather than instructions, and a delegated run can no longer call this server again through Codex's own MCP configuration.
  • A new guide, Staying in control of delegation: client permissions, server ceilings, version ranges and your own rules for Claude.
  • Guidance on keeping this server's ceilings outside the working tree, and on how Codex's own configuration interacts with delegations (SECURITY.md).

Verified against

  • Codex CLI 0.154.0 on macOS.
  • Release smoke test (real CLI, gpt-5.6-luna at low): 14 of 14 checks passed — preflight, catalog, recommendations, refusals, a read-only delegation, a follow-up that restated its model and effort, effort adjustment, timeout, prompt-injection inertness and a background job.
  • Build, tests and startup on Linux (Node 22, 24, 26), Windows (Node 22, 24) and macOS (Node 24). A real delegation has not yet been run on Windows or Linux.

Full details in the changelog.