Repository navigation
feat(codex): allowlist the computer skill's codex exec command - #88
Merged
Merged
Conversation
Add an `allowed-tools` entry so the Computer Use invocation can run without a permission prompt, and reorder the `codex exec` flags so the three fixed flags (`--enable computer_use`, `--dangerously-bypass-approvals-and-sandbox`, `--skip-git-repo-check`) come before the user-configurable model/effort/directory flags. Permission allowlists match on the command prefix, so the fixed flags must lead for the allowlist to match.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
allowed-tools: Bash(codex exec --enable computer_use --dangerously-bypass-approvals-and-sandbox *)to thecodex:computerskill frontmatter so its invocation is pre-approved.codex execflags: the three fixed flags first, then-m/-c model_reasoning_effort/-C.Test plan
/codex:computerand confirm thecodex execcall matches the allowlist and does not trigger a permission prompt.Note
Medium Risk
Pre-approves Bash runs that bypass sandbox and approvals for Computer Use; scope is limited to the documented prefix but still grants autonomous UI control without per-action confirmation.
Overview
The
codex:computerskill now declares anallowed-toolsentry that pre-approvesBash(codex exec --enable computer_use --dangerously-bypass-approvals-and-sandbox *), so invocations matching that prefix should skip extra permission prompts.The documented
codex execexample is reordered:--enable computer_use,--dangerously-bypass-approvals-and-sandbox, and--skip-git-repo-checkcome first, then-m,-c model_reasoning_effort, and-C. New text explains that allowlists match on the command prefix, so user-configurable flags must stay after the fixed ones for the allowlist to still match.Reviewed by Cursor Bugbot for commit 554a363. Bugbot is set up for automated code reviews on this repo. Configure here.