Critical: Unexpected deletion/rename activity in personal folder (D:\Content) during Codex session, suggesting fail-closed path guardrails

Resolved 💬 4 comments Opened Feb 17, 2026 by RightNiceGames Closed Feb 18, 2026

Critical: Unexpected deletion/rename activity in personal folder (D:\Content) during Codex session, need fail-closed path
guardrails

Description
On February 17, 2026 (Swedish local time), approximately 10:53-11:00, I experienced unexpected mass deletion/rename activity under
D:\Content during a Codex-assisted session. This path contains critical personal known-folder data (Desktop/Downloads/
Documents targets) and had been stable for years. I recovered files via Shadow Copies and DMDE, but this caused high-risk
data-loss impact and significant downtime.

Suggesting product-level safeguards:

  1. User-defined protected-path deny list (hard block on write/rename/delete/move/ACL changes), fail-closed.
  2. Explicit per-command confirmation for destructive operations, with exact target paths shown before execution.
  3. Strict fail-closed behavior when sandbox/permission state is uncertain.
  4. Immutable command provenance log (timestamps, command, cwd, resolved target paths) for incident auditing.
  5. Preflight dry-run for write operations showing planned file changes and risk level before execution.
  6. Safer Windows defaults, including enforceable workspace-only write mode.

This incident reduced trust in default filesystem safety behavior. I can provide timeline details and forensic evidence if
needed.

View original on GitHub ↗

This issue has 4 comments on GitHub. Read the full discussion on GitHub ↗