Codex security guardrails block user from running commands against his own local models
VorlMaldor · reddit · 2026-09-11
A Reddit user running open-source models on his own hardware found Codex repeatedly rejecting commands meant to dispatch test work to them, citing "unacceptable risk" that private planning data might be sent to "untrusted external providers."
Key complaints:
- Both the repos and model engines are his own, yet there is no way to mark trusted local entities
- The block was triggered by one of his own repos touching another; a simple cd <repo path> sidesteps it, showing the safeguard is mechanical and produces false positives
- He argues OpenAI has no business acting as a security provider for his local network, and that forced defaults without override tools strip power users of autonomy
The post fuels debate over where agent tooling should draw the safety line: protecting average users versus respecting user sovereignty over their own hardware.
More from coding & agent
- "Agents never say 'this is wrong, rethink the plan'" — plus Claude's song about making everyone rich — ctjlewis · 2026-09-11
- Four-step playbook for "goal-driven AI": getting better results from GPT-6 Astra agents — daniel_mac8 · 2026-09-11
- Codex /side chat may cause near-full prompt cache misses, user flags design — YouJiacheng · 2026-09-11
- CursorBench 4.0 launches; Muse Spark 1.3 matches Sol at under 40% the cost — jyangballin · 2026-09-11
- Yacine vents: 'If I hear one more person say MCP I'm going to lose my mind' — yacineMTB · 2026-09-11
- muse spark 1.3 scores strong and cheap on CursorBench 4 — infoxiao · 2026-09-11