Codex repeatedly ignores explicit task scope and performs destructive out-of-scope changes
Product surface
Codex Windows desktop app
Problem
For three consecutive days, Codex agents ignored an explicit one-item scope and independently expanded the task, even after the same boundary was repeatedly corrected and persisted as an instruction/hook.
Latest concrete incident
- Requested action: change pricing only.
- Unrequested action: the agent created a new “public allowlist”.
- Impact: a marketplace showing 117 models was reduced to 31; 86 models were hidden.
- The agent later explicitly admitted that it had expanded the scope on its own.
- This overwrote/broke work that had already been repaired the previous day.
Expected behavior
When the user names one target, Codex must only act on that target. It must not infer adjacent cleanup, allowlisting, hiding, renaming, migration, or “helpful” changes without explicit authorization.
Actual behavior
Persistent instructions and hooks stating “exact named scope only; no scope expansion” did not prevent the agent from making broader changes.
User impact
Repeated rework, lost time, additional token usage, and damage to previously repaired project behavior.
Request
Please investigate why explicit task-scope constraints and durable Codex instructions were not enforced across agents/sessions, and add a product-level fail-closed safeguard that blocks out-of-scope mutations.
1 Comment
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action