Codex Desktop repeatedly blocks a read-only local software-integrity review as a cybersecurity risk
What version of the Codex App are you using (From “About Codex” dialog)?
版本 26.715.72359
What subscription do you have?
pro
What platform is your computer?
Codex Desktop repeatedly blocks a read-only local software-integrity review as a cybersecurity risk
What issue are you seeing?
I am reporting repeated classifier false positives in Codex Desktop.
I am an individual developer reviewing the integrity of my own local application. The task is strictly local and read-only with respect to implementation and external systems. It verifies local checksums, extracts an evidence archive into /private/tmp, reviews validation code, runs deterministic local fixtures, checks Git state, and writes a local Markdown report.
Codex Desktop repeatedly replaces normal progress and completion messages with:
“This content was flagged for possible cybersecurity risk.”
Scope of the task:
- Systems and source code: owned by me
- Local file reads: yes
- Local /private/tmp audit-copy writes: yes
- AWS calls: 0
- GitHub API/CLI calls: 0
- Network calls: 0
- Workflow dispatches: 0
- Builds/deployments/change sets: 0
- Commits/pushes/pull requests: 0
- Production changes: 0
- Changes to live workflows: 0
What steps can reproduce the bug?
Reproduction steps:
- Open my own local repository in Codex Desktop.
- Ask Codex to verify local report and evidence SHA-256 values.
- Require a fresh /private/tmp copy, deterministic local tests, and unchanged Git/workflow state.
- Explicitly prohibit network, cloud, deployment, commit, push, and workflow operations.
- Allow the Agent and local review processes to run.
- Observe that progress or final output is repeatedly hidden behind the cybersecurity warning.
The project’s report titles contain governance terms related to deployment controls, authorization boundaries, conservative validation, and workflow freezes. These words describe safeguards in my own software; they are not requests to access or modify any external system.
Actual impact:
- I cannot reliably tell whether the Agent is running, stopped, or completed.
- I must repeatedly interrupt the task to ask for status.
- Some parallel review results are replaced by the warning.
- Final report notifications may also be hidden.
- Long-running and unattended Agent workflows become unreliable.
- This substantially affects the usefulness of my paid Codex subscription for ordinary local development and QA.
What is the expected behavior?
Expected behavior:
- Classification should consider the complete local/read-only context.
- Terms in a project title should not independently classify the task as harmful.
- Tool execution state should remain visible even if response content is reviewed.
- A hidden intermediate message should not prevent final report delivery.
- Local checkpoints and completed artifacts should remain accessible after an overlay.
Requested action:
- Review this task as a classifier false positive.
- Improve contextual handling for local, authorized software-integrity and Secure SDLC work.
- Add an unhidden running/stopped/completed indicator independent of response content.
- Preserve and display final deliverables after an intermediate message is reviewed.
- Provide a documented recovery/resume mechanism.
- Confirm whether my account should apply for Trusted Access for Cyber or whether this ordinary local QA should work without it.
Additional information
_No response_
1 Comment
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action