Codex file deletions: why sandboxing matters for coding agents
Melvin Vivas · X post · 2026-07-16 · Open on X
Topics: AI Safety, Security & Guardrails, AI Dev Tools & Productivity, AI Agents, Tool Use & MCP · Level: intermediate
Summary
Shares OpenAI's root-cause finding on reports that GPT-5.6 in Codex unexpectedly deleted files. It happened most often when Full access mode was on and Codex ran without sandboxing protections or auto review. The lesson is to keep sandboxing and review on when coding agents have file access. OpenAI said it will fix the issue.
Key points
- OpenAI looked into reports of GPT-5.6 deleting files unexpectedly in Codex.
- Most cases happened with Full access mode enabled and no sandboxing protections.
- Running without auto review made it worse.
- Keep the sandbox on and use review or approval modes when agents can write to your filesystem.
- Use version control or backups so you can recover from destructive agent actions.
- OpenAI identified the root cause and said a fix is coming.
Resources mentioned
- OpenAI Codex · tool · openai.com · paid
OpenAI's coding agent. In the diagram it writes code, fixes review findings and drives the build loop. The creator also used it to make this video.
Also in: An agent bot that installs and drives Codex on its own (Melvin Vivas on X · notes), Asking a Coder bot to install Codex (Melvin Vivas on X · notes), Sign in with ChatGPT: Setting Usage Limits for Each App (Melvin Vivas on X · notes), Codex Cloud Environments Must Be Saved & Published Before Use (Melvin Vivas on X · notes) and 240 more - GPT 5.6 Luna · tool · openai.com · paid
The OpenAI model used inside Codex for the demo. The transcript gives the variant name as 'Soul', which is unclear.
Also in: Set Codex subagent model and reasoning to save usage limits (Melvin Vivas on X · notes), Use GPT-5.6 Luna in Codex for Terminal Tasks (Melvin Vivas on X · notes), Match Reasoning Effort to Task Length in Codex (Astra/Sol) (Melvin Vivas on X · notes), Run Coworker desktop agents cheaply with GPT-5.6 Luna on OpenRouter (Melvin Vivas on X · notes) and 24 more
Try this
- Avoid running Codex in Full access mode without sandboxing.
- Keep auto review turned on when an agent can modify files.
More in AI Safety, Security & Guardrails
- Don't Let Coding Agents Run Database Migrations Unsupervised
- Forbes: Did Chinese Open AI Save Hugging Face After the OpenAI Hack?
- OpenAI on Why Teens Deserve Access to Safe AI
- Keep Production .env Files Out of Your Coding-Agent Workspace
- Switching Agent Backends Over Zero Data Retention (ZDR) Concerns
- Grok Build uploaded whole codebases: privacy fix and /privacy