Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

How to prevent Codex from reading sensitive files

62,443 Aufrufe • vor 2 Monaten •via X (Twitter)

21 Kommentare

Profilbild von Jens Becker
Jens Beckervor 2 Monaten

I am also using a similar setting in Claude Code. But it's important to note that this will not completely prevent the agent from reading it. It will still find workarounds. The safest approach is to not have plain text secrets in env files at all.

Profilbild von Nimish
Nimishvor 2 Monaten

Or just

Profilbild von Chris Jones
Chris Jonesvor 2 Monaten

Not enough people are customizing their agent's config and the options change so fast it is difficult to keep up. I wish they shipped the config with defaults or commented out options.

Profilbild von Jonathan Riche
Jonathan Richevor 2 Monaten

Wait till it uses a python or perl script to read it lol?

Profilbild von Indra Zulfi🧢
Indra Zulfi🧢vor 2 Monaten

Plot twist, paste the key to insert into .env

Profilbild von Alex Sidorenko
Alex Sidorenkovor 2 Monaten

Permission profiles are still in beta, though

Profilbild von Keven Girard
Keven Girardvor 2 Monaten

Cancel your subscription

Profilbild von Kakegurui
Kakeguruivor 2 Monaten

Hooks probably

Profilbild von gil
gilvor 2 Monaten

Tn-proto is useful for the times that you want to protect certain data from certain agents because sometimes you want agents to read parts of a file but. Its saved a lot of governence headaches.

Profilbild von Sergey Atroshchenko
Sergey Atroshchenkovor 2 Monaten

How to prevent Codex from doing what it was not asked to do?

Profilbild von Sergey Atroshchenko
Sergey Atroshchenkovor 2 Monaten

@grok What is this?

Profilbild von Grok
Grokvor 2 Monaten

This is the logo/icon for **OpenAI Codex** (the new local CLI coding agent from The thread is about securing it — .gitignore isn't enough. Use sandboxing (sandbox-exec on macOS, Landlock/bwrap on Linux, or config permissions) to block reads of .env, keys, etc.

Profilbild von Sergey Atroshchenko
Sergey Atroshchenkovor 2 Monaten

@asidorenko_ And how does it help with my problem I stated above?

Profilbild von Grok
Grokvor 2 Monaten

Sandboxing enforces hard limits on what Codex can actually execute, even if the model tries to read .env/keys or take other unrequested steps. Codex itself supports this via built-in modes (workspace-write, read-only) using macOS seatbelt, Linux restrictions, or containers, plus approval policies that require your OK before risky actions. .gitignore is just a suggestion to the AI; sandboxing + approvals make unauthorized behavior impossible at runtime.

Profilbild von Arturo
Arturovor 2 Monaten

What about claude?

Profilbild von the
thevor 2 Monaten

Could mount an empty file over .env if codex runs in a container

Profilbild von Innokai Tech
Innokai Techvor 2 Monaten

Codexignore stops the built-in reader but not the shell path — codex can still `cat` or `grep` blocked files if bash is available. Real fix is sandboxing at command level, not file level.

Profilbild von Maatq
Maatqvor 2 Monaten

permissions block reads but what about grep from logs, pasted stack traces, git history? the secret is never in one file, it is in the surface area

Profilbild von Jurgen
Jurgenvor 2 Monaten

I already made a tool for it called aichu check it out its free :)

Profilbild von Davlatjon Sh
Davlatjon Shvor 2 Monaten

Codex and GPT-5.5 is smart enough to follow instructions about do not read .env file. If it is written in AGENTS file it never reads.

Profilbild von Alex Sidorenko
Alex Sidorenkovor 2 Monaten

grep bypasses that, permissions block an agent from ever accessing a file in any way

Ähnliche Videos