skills.config enabled=false cannot be overridden by project or custom subagent config
What version of Codex CLI is running?
codex-cli 0.142.0
What subscription do you have?
API/custom provider setup: Azure OpenAI via model_provider=azure. This CLI session is not using a ChatGPT subscription directly.
Which model were you using?
gpt-5.5 via custom Azure OpenAI provider using the Responses API
What platform is your computer?
Linux 6.18.33.1-microsoft-standard-WSL2 x86_64 x86_64
What terminal emulator and version are you using (if applicable)?
Windows Terminal 1.24.11321.0, running Ubuntu/WSL2. TERM=xterm-256color.
Codex doctor report
{
"schemaVersion": 1,
"generatedAt": "1782298166s since unix epoch",
"overallStatus": "ok",
"codexVersion": "0.142.0",
"checks": {
"app_server.status": {
"id": "app_server.status",
"category": "app-server",
"status": "ok",
"summary": "background server is not running",
"details": {
"control socket": "/home/<redacted>/.codex/app-server-control/app-server-control.sock",
"daemon state dir": "/home/<redacted>/.codex/app-server-daemon",
"mode": "ephemeral",
"pid file": "/home/<redacted>/.codex/app-server-daemon/app-server.pid (missing)",
"settings": "/home/<redacted>/.codex/app-server-daemon/settings.json (missing)",
"status": "not running",
"update-loop pid file": "/home/<redacted>/.codex/app-server-daemon/app-server-updater.pid (missing)"
},
"remediation": null,
"durationMs": 1
},
"auth.credentials": {
"id": "auth.credentials",
"category": "auth",
"status": "ok",
"summary": "auth is provided by the active model provider",
"details": {
"auth file": "/home/<redacted>/.codex/auth.json",
"auth storage mode": "File",
"model provider requires OpenAI auth": "false",
"provider auth env var": "AZURE_OPENAI_API_KEY (present)"
},
"remediation": null,
"durationMs": 0
},
"config.load": {
"id": "config.load",
"category": "config",
"status": "ok",
"summary": "config loaded",
"details": {
"CODEX_HOME": "/home/<redacted>/.codex",
"config.toml": "/home/<redacted>/.codex/config.toml",
"config.toml parse": "ok",
"cwd": "/home/<redacted>/developer/pers/TEMP",
"enabled feature flags": "shell_tool, unified_exec, shell_snapshot, terminal_resize_reflow, sqlite, hooks, enable_request_compression, multi_agent, apps, tool_suggest, plugins, in_app_browser, browser_use, browser_use_external, computer_use, plugin_sharing, image_generation, resize_all_images, skill_mcp_dependency_install, mentions_v2, steer, guardian_approval, goals, collaboration_modes, tool_call_mcp_elicitation, personality, fast_mode, tui_app_server, auto_compaction, remote_compaction_v2, workspace_dependencies",
"feature flag overrides": "none",
"feature flags enabled": "31",
"log dir": "/home/<redacted>/.codex/log",
"mcp servers": "6",
"model": "gpt-5.5-dep",
"model provider": "azure",
"sqlite home": "/home/<redacted>/.codex"
},
"remediation": null,
"durationMs": 0
},
"git.environment": {
"id": "git.environment",
"category": "git",
"status": "ok",
"summary": "git version 2.43.0",
"details": {
"PATH git #1": "/usr/bin/git",
"PATH git #2": "/bin/git",
"PATH git entries": "2",
"git build options": "git version 2.43.0; cpu: x86_64; no commit associated with this build; sizeof-long: 8; sizeof-size_t: 8; shell-path: /bin/sh",
"git exec path": "/usr/lib/git-core",
"git version": "git version 2.43.0",
"repo detected": "false",
"selected git": "/usr/bin/git"
},
"remediation": null,
"durationMs": 49
},
"installation": {
"id": "installation",
"category": "install",
"status": "ok",
"summary": "installation looks consistent",
"details": {
"PATH codex #1": "/run/user/1000/fnm_multishells/<redacted>/bin/codex",
"current executable": "/home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/bin/codex",
"install context": "npm (package /home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl, bin /home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/bin, resources /home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/codex-resources, path /home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/codex-path)",
"managed by bun": "false",
"managed by npm": "true",
"managed package root": "/home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex",
"npm update target": "/home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex"
},
"remediation": null,
"durationMs": 178
},
"mcp.config": {
"id": "mcp.config",
"category": "mcp",
"status": "ok",
"summary": "MCP configuration is locally consistent",
"details": {
"configured servers": "6",
"disabled servers": "6",
"stdio servers": "4",
"streamable_http servers": "2"
},
"remediation": null,
"durationMs": 0
},
"network.env": {
"id": "network.env",
"category": "network",
"status": "ok",
"summary": "network-related environment looks readable",
"details": {
"proxy env vars": "none"
},
"remediation": null,
"durationMs": 0
},
"network.provider_reachability": {
"id": "network.provider_reachability",
"category": "reachability",
"status": "ok",
"summary": "active provider endpoints are reachable over HTTP",
"details": {
"azure API base URL": "https://<redacted>.openai.azure.com/openai/<redacted> reachable (HTTP 404)",
"reachability mode": "provider auth"
},
"remediation": null,
"durationMs": 453
},
"network.websocket_reachability": {
"id": "network.websocket_reachability",
"category": "websocket",
"status": "ok",
"summary": "Responses WebSocket is not enabled for the active provider",
"details": {
"model provider": "azure",
"provider name": "Azure OpenAI",
"proxy env vars": "none",
"supports websockets": "false",
"wire API": "responses"
},
"remediation": null,
"durationMs": 0
},
"runtime.provenance": {
"id": "runtime.provenance",
"category": "runtime",
"status": "ok",
"summary": "running npm on linux-x86_64",
"details": {
"commit": "unknown",
"current executable": "/home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/bin/codex",
"install method": "npm (package /home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl, bin /home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/bin, resources /home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/codex-resources, path /home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/codex-path)",
"platform": "linux-x86_64",
"version": "0.142.0"
},
"remediation": null,
"durationMs": 0
},
"runtime.search": {
"id": "runtime.search",
"category": "search",
"status": "ok",
"summary": "search is OK (bundled)",
"details": {
"search command": "/home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex/node_modules/@openai/codex-linux-x64/vendor/x86_64-unknown-linux-musl/codex-path/rg",
"search command readiness": "file exists",
"search provider": "bundled"
},
"remediation": null,
"durationMs": 0
},
"sandbox.helpers": {
"id": "sandbox.helpers",
"category": "sandbox",
"status": "ok",
"summary": "sandbox configuration is readable",
"details": {
"approval policy": "Never",
"codex-linux-sandbox helper": "/home/<redacted>/.codex/tmp/arg0/codex-arg0t5bPdL/codex-linux-sandbox",
"execve wrapper helper": "/home/<redacted>/.codex/tmp/arg0/codex-arg0t5bPdL/codex-execve-wrapper",
"filesystem sandbox": "unrestricted",
"network sandbox": "enabled"
},
"remediation": null,
"durationMs": 0
},
"state.paths": {
"id": "state.paths",
"category": "state",
"status": "ok",
"summary": "state paths and databases are inspectable",
"details": {
"CODEX_HOME": "/home/<redacted>/.codex (dir)",
"active rollout files": "361 files, 231240425 total bytes, 640555 average bytes",
"archived rollout files": "0 files, 0 total bytes, 0 average bytes",
"goals DB": "/home/<redacted>/.codex/goals_1.sqlite (file)",
"goals DB integrity": "ok",
"log DB": "/home/<redacted>/.codex/logs_2.sqlite (file)",
"log DB integrity": "ok",
"log dir": "/home/<redacted>/.codex/log (dir)",
"memories DB": "/home/<redacted>/.codex/memories_1.sqlite (file)",
"memories DB integrity": "ok",
"sqlite home": "/home/<redacted>/.codex (dir)",
"state DB": "/home/<redacted>/.codex/state_5.sqlite (file)",
"state DB integrity": "ok"
},
"remediation": null,
"durationMs": 2809
},
"state.rollout_db_parity": {
"id": "state.rollout_db_parity",
"category": "threads",
"status": "ok",
"summary": "rollout files and state DB thread inventory agree",
"details": {
"default model provider": "azure",
"rollout DB active files": "361",
"rollout DB active rows": "361",
"rollout DB archive mismatches": "0",
"rollout DB archived files": "0",
"rollout DB archived rows": "0",
"rollout DB duplicate DB paths": "0",
"rollout DB duplicate rollout thread ids": "0",
"rollout DB malformed file names": "0",
"rollout DB missing active rows": "0",
"rollout DB missing archived rows": "0",
"rollout DB model providers": "azure=361",
"rollout DB rows": "361",
"rollout DB scan cap reached": "false",
"rollout DB scan errors": "0",
"rollout DB sources": "cli=339, subagent:thread_spawn=19, exec=2, subagent:review=1",
"rollout DB stale rows": "0"
},
"remediation": null,
"durationMs": 3970
},
"system.environment": {
"id": "system.environment",
"category": "system",
"status": "ok",
"summary": "OS language C",
"details": {
"EDITOR": "set",
"GH_PAGER": "set",
"GIT_PAGER": "set",
"LANG": "C.UTF-8",
"LC_ALL": "C.UTF-8",
"LC_CTYPE": "C.UTF-8",
"PAGER": "set",
"VISUAL": "set",
"os": "Ubuntu 24.4.0 (noble) [64-bit]",
"os language": "C",
"os type": "Ubuntu",
"os version": "24.4.0"
},
"remediation": null,
"durationMs": 9
},
"terminal.env": {
"id": "terminal.env",
"category": "terminal",
"status": "ok",
"summary": "terminal metadata was detected",
"details": {
"COLORTERM": "present",
"DISPLAY": "present",
"NO_COLOR": "1",
"WAYLAND_DISPLAY": "present",
"WSL_DISTRO_NAME": "present",
"WSL_INTEROP": "present",
"WT_SESSION": "present",
"color output": "disabled (NO_COLOR)",
"effective locale": "C.UTF-8",
"stderr is terminal": "false",
"stdin is terminal": "false",
"stdout is terminal": "false",
"terminal": "Windows Terminal",
"terminal size": "80x24"
},
"remediation": null,
"durationMs": 3
},
"terminal.title": {
"id": "terminal.title",
"category": "title",
"status": "ok",
"summary": "terminal title default",
"details": {
"terminal title activity": "true",
"terminal title items": "activity, project-name",
"terminal title project source": "cwd",
"terminal title project value": "TEMP",
"terminal title source": "default"
},
"remediation": null,
"durationMs": 0
},
"updates.status": {
"id": "updates.status",
"category": "updates",
"status": "ok",
"summary": "update configuration is locally consistent",
"details": {
"cached latest version": "0.142.0",
"check for update on startup": "true",
"dismissed version": "0.135.0",
"last checked at": "2026-06-24T09:13:05.733969406Z",
"latest version": "0.142.0",
"latest version status": "current version is not older",
"npm update target": "/home/<redacted>/.local/share/fnm/node-versions/v24.16.0/installation/lib/node_modules/@openai/codex",
"update action": "npm install -g @openai/codex",
"version cache": "/home/<redacted>/.codex/version.json"
},
"remediation": null,
"durationMs": 216
}
}
}
What issue are you seeing?
When a skill is disabled at user level with [[skills.config]] enabled = false, I cannot re-enable that skill for a narrower scope.
I tested re-enabling the skill in all of these places:
- Project-level
.codex/config.toml - Project-level custom subagent config, e.g.
.codex/agents/debugger.toml - User-level custom subagent config, e.g.
~/.codex/agents/debugger.toml
In all cases, the skill remains unavailable to the agent/subagent once it has been disabled in ~/.codex/config.toml.
This makes skills.config behave like an irreversible session-wide filter rather than a normal layered config value. It prevents a useful workflow: keep powerful or context-specific skills disabled by default globally, but enable them only for one trusted project or one specialized subagent.
Concrete use case:
- I have repo-local skills:
use-chrome,use-server, anduser-auth. - I want them disabled by default for the main agent.
- I want only a
debuggersubagent to have those skills, because that subagent also gets a Chrome DevTools MCP server for browser smoke tests. - If I disable the skills at user level, the
debuggersubagent cannot get them back, even when its own custom agent TOML sets those skills toenabled = true.
What steps can reproduce the bug?
- Create a repo-local skill:
.agents/skills/my-skill/SKILL.md
---
name: my-skill
description: Test skill for skills.config override behavior.
---
Use this skill only for testing.
- Disable the skill globally in ~/.codex/config.toml:
[[skills.config]]
name = "my-skill"
enabled = false
- Confirm the main agent no longer sees the skill, for example by checking /skills or:
codex --cd /path/to/repo debug prompt-input 'noop'
- Try to re-enable it at project level in /path/to/repo/.codex/config.toml:
[[skills.config]]
name = "my-skill"
enabled = true
- Start Codex in that trusted project and check /skills or codex debug prompt-input. The skill remains unavailable.
- Try to re-enable it in a custom subagent file, for example ~/.codex/agents/debugger.toml:
name = "debugger"
description = "Test subagent for skill override behavior."
developer_instructions = "Use my-skill if available."
[[skills.config]]
name = "my-skill"
enabled = true
- Spawn the debugger subagent from the project. The subagent still does not have access to my-skill.
The same result occurs if the custom subagent file is project-local under .codex/agents/debugger.toml.
What is the expected behavior?
I expect config layering to allow a narrower scope to re-enable a skill that was disabled at a broader scope.
For example:
- User-level config can disable a skill by default.
- Project-level config can re-enable it for a trusted project.
- Custom subagent config can re-enable it for that specific subagent.
This would match the mental model of other Codex config values and would allow least-privilege skill exposure: hide project/runtime skills from the main agent by default, but expose them only to a specialized subagent.
Additional information
I also tested policy.allow_implicit_invocation: false in each skill's agents/openai.yaml.
That prevents the skills from being injected into the main agent's implicit skill-discovery context, which is expected. However, it does not solve this use case because the main agent then cannot reliably invoke those skills for a subagent workflow.
In my workflow, the main agent is supposed to spawn a specialized debugger subagent for browser/runtime smoke tests. The debugger subagent needs use-chrome, use-server, and user-auth. If those skills are marked allow_implicit_invocation: false, the main agent no longer sees them in the available skill list and therefore cannot select or explicitly route them as part of the subagent task.
So allow_implicit_invocation: false is useful for hiding skills from automatic triggering, but it is not equivalent to "available only to this subagent." The missing capability is scoped skill exposure: disabled or hidden for the main agent, but enabled for a specific trusted project or custom subagent.
Current workaround (doesn't fully address the bug):
I disabled the skills globally in user config and extended my shell wrapper so that launching Codex with a specific alias passes a one-off CLI override:
codex h devtools -- ...
That wrapper expands to a -c skills.config=[...] override that re-enables only the runtime skills for that invocation. This works, but it enables the skills for both the main agent and subagent. Currently there is no way to disable a skill for the main agent while enabling it project-level and/or custom-agent-level, unlike MCP servers.
The behavior I expected is that skills.config would follow the same layered configuration model described for Codex config generally: user-level defaults can be narrowed or overridden by trusted project config and by custom agent config. The docs also state that custom agent files can include supported config.toml keys such as skills.config, so I expected a custom agent's skills.config to control that agent's skill exposure.
This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗