Skip to content

feat(codex): allowlist the computer skill's codex exec command - #88

Merged
jeffh merged 1 commit into
mainfrom
codex-computer-allowed-tools
Sep 10, 2026
Merged

jeffh merged 1 commit into
mainfrom
codex-computer-allowed-tools

Conversation

@jeffh

@jeffh jeffh commented Sep 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Add allowed-tools: Bash(codex exec --enable computer_use --dangerously-bypass-approvals-and-sandbox *) to the codex:computer skill frontmatter so its invocation is pre-approved.
  • Reorder the documented codex exec flags: the three fixed flags first, then -m / -c model_reasoning_effort / -C.
  • Document why the order matters — permission allowlists match on the command prefix, so anything user-configurable has to come after the fixed flags.

Test plan

  • Run /codex:computer and confirm the codex exec call matches the allowlist and does not trigger a permission prompt.

Note

Medium Risk
Pre-approves Bash runs that bypass sandbox and approvals for Computer Use; scope is limited to the documented prefix but still grants autonomous UI control without per-action confirmation.

Overview
The codex:computer skill now declares an allowed-tools entry that pre-approves Bash(codex exec --enable computer_use --dangerously-bypass-approvals-and-sandbox *), so invocations matching that prefix should skip extra permission prompts.

The documented codex exec example is reordered: --enable computer_use, --dangerously-bypass-approvals-and-sandbox, and --skip-git-repo-check come first, then -m, -c model_reasoning_effort, and -C. New text explains that allowlists match on the command prefix, so user-configurable flags must stay after the fixed ones for the allowlist to still match.

Reviewed by Cursor Bugbot for commit 554a363. Bugbot is set up for automated code reviews on this repo. Configure here.

Add an `allowed-tools` entry so the Computer Use invocation can run
without a permission prompt, and reorder the `codex exec` flags so the
three fixed flags (`--enable computer_use`,
`--dangerously-bypass-approvals-and-sandbox`, `--skip-git-repo-check`)
come before the user-configurable model/effort/directory flags.
Permission allowlists match on the command prefix, so the fixed flags
must lead for the allowlist to match.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Cursor Bugbot completed successfully with no findings that need human review, so no reviewers were assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@jeffh
jeffh merged commit 2bada34 into main Sep 10, 2026
4 checks passed
@jeffh
jeffh deleted the codex-computer-allowed-tools branch September 10, 2026 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant