Evidence record / codex

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.

2026-09-21-codex-untrusted-projects-stop-feeding-agents-md-and-startup-stops-running-workspace-helpers-befo

Untrusted projects stop feeding AGENTS.md, and startup stops running workspace helpers before trust. When the project is untrusted, project-scoped AGENTS.md discovery is skipped. User-level instructions are kept, and trust level is part of the instruction cache key, so a runtime trust change reloads instructions. Managed deny-read rules stay enforced after permission changes (#40004). From 0.154.0, startup no longer executes workspace-controlled helpers before trust is established.

Channel: tagged-release. Half: defect. Date: 2026-08-26 (0.150.0); 2026-09-09 (0.154.0).

Operator consequence: Cloning a hostile repo and opening it untrusted no longer lets it inject instructions or run helpers at startup. Upgrade to >=0.154.0 for both fixes. If your workflow depends on repo AGENTS.md, the project must now be trusted. Check this in CI and in ephemeral checkouts where trust is never granted.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-codex-untrusted-projects-stop-feeding-agents-md-and-startup-stops-running-workspace-helpers-befo

Profile citations

  • Codex / claim / untrusted-projects-no-agents-md-no-helpers

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact