Replace codex --full-auto with --sandbox workspace-write and enable --approve-for-me
Upgrade to Codex rust-v0.147.0, migrate off removed --full-auto, turn on --approve-for-me, and adopt portable Agent Plugins plus Cursor skill import for shared agent workflows.Why this loop
Codex rust-v0.147.0 removes the deprecated codex exec --full-auto flag; --sandbox workspace-write is the replacement, so scripts and aliases that still pass --full-auto will fail after upgrade. The same release adds --approve-for-me for automatically reviewed approvals, portable Agent Plugins searchable across local, personal, workspace, and remote catalogs, and import of Cursor-managed skills with duplicate-free sync of imported Claude and Cursor conversations. Linux installs must use codex-package-<target> archives because redundant Linux bundle archives are no longer published. Unfamiliar local projects now require explicit trust, managed authentication restrictions are enforced before credentials are used, plugin isolation is hardened (network access denied when policy updates fail), and secrets plus complete bearer tokens are redacted from displayed commands and replayed history.
Proposed actions
- Upgrade Codex CLI to rust-v0.147.0 from https://github.com/openai/codex/releases/tag/rust-v0.147.0. On Linux install only codex-package-<target> archives; do not use the removed redundant Linux bundle archives.
- Run: rg -n --hidden -g '!/node_modules/' -g '!/.git/' -- '--full-auto' then replace every Codex use of --full-auto, including
codex exec --full-auto, with --sandbox workspace-write and delete --full-auto. - Add --approve-for-me to Codex CLI invocations used for unattended or pre-reviewed runs (shell aliases, agent wrappers, and CI
codex/codex execsteps). - Import Cursor-managed skills into Codex and re-synchronize already-imported Claude and Cursor conversations so updates apply without creating duplicate sessions.
- Install portable Agent Plugins and search local, personal, workspace, and remote plugin catalogs instead of copying plugin files. Expect explicit trust for unfamiliar local projects, managed-auth checks before credentials are used, and network deny if plugin policy updates fail.
Agent prompt
Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI costCodex / agent CLI task
DevAgentRadar → OpenAI Codex
Task: evaluate and optionally implement follow-ups from this coding-assistant release.
Context
Assistant: OpenAI Codex CLI Proposal: Replace codex --full-auto with --sandbox workspace-write and enable --approve-for-me Summary: Upgrade to Codex rust-v0.147.0, migrate off removed --full-auto, turn on --approve-for-me, and adopt portable Agent Plugins plus Cursor skill import for shared agent workflows. Primary source: https://github.com/openai/codex/releases/tag/rust-v0.147.0
Why it matters
Codex rust-v0.147.0 removes the deprecated codex exec --full-auto flag; --sandbox workspace-write is the replacement, so scripts and aliases that still pass --full-auto will fail after upgrade. The same release adds --approve-for-me for automatically reviewed approvals, portable Agent Plugins searchable across local, personal, workspace, and remote catalogs, and import of Cursor-managed skills with duplicate-free sync of imported Claude and Cursor conversations. Linux installs must use codex-package-<target> archives because redundant Linux bundle archives are no longer published. Unfamiliar local projects now require explicit trust, managed authentication restrictions are enforced before credentials are used, plugin isolation is hardened (network access denied when policy updates fail), and secrets plus complete bearer tokens are redacted from displayed commands and replayed history.
Suggested actions
- Upgrade Codex CLI to rust-v0.147.0 from https://github.com/openai/codex/releases/tag/rust-v0.147.0. On Linux install only codex-package-<target> archives; do not use the removed redundant Linux bundle archives.
- Run: rg -n --hidden -g '!/node_modules/' -g '!/.git/' -- '--full-auto' then replace every Codex use of --full-auto, including
codex exec --full-auto, with --sandbox workspace-write and delete --full-auto. - Add --approve-for-me to Codex CLI invocations used for unattended or pre-reviewed runs (shell aliases, agent wrappers, and CI
codex/codex execsteps). - Import Cursor-managed skills into Codex and re-synchronize already-imported Claude and Cursor conversations so updates apply without creating duplicate sessions.
- Install portable Agent Plugins and search local, personal, workspace, and remote plugin catalogs instead of copying plugin files. Expect explicit trust for unfamiliar local projects, managed-auth checks before credentials are used, and network deny if plugin policy updates fail.
Config surfaces this release may change
- sandbox settings (high confidence) — check your repo before applying
- MCP servers — check your repo before applying
After you finish
Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.
Tell the human: open https://devagentradar.com/proposals/openai-codex-rust-v0-147-0-replace-codex-full-auto-with-sandbox-workspac and mark Applied, Skipped, or Failed. Proposal id: 1b479e9c-64be-47d4-8404-600b3d6a6995
Deliverables:
- Short impact assessment
- Optional patch plan (files + steps)
- Do not invent APIs not in the source notes
Your loop
This browser · no sign-in · not shared as “you”After you run the prompt
Only you can mark this. Agents cannot write your loop.
Your decision stays on this device. A public tally appears after a few votes.