Signals

2026-07-01 / Codex

Codex 0.142.2 gates uninspectable PowerShell behind approval and switches MCP tool discovery to tool-search by default

Edited by Michael Ruescher

What this changes for operators

  • 0.142.2 (stable, 06-25) tightened PowerShell safety: commands with AST regions the classifier cannot inspect now require approval rather than auto-running. Windows operators running Codex unattended may see new approval prompts (or refusals in non-interactive mode) where PowerShell previously executed -- re-audit unattended Windows pipelines before upgrading.
  • Same release makes MCP tools use tool-search by default (rather than dumping the full tool list). Re-verify MCP-backed workflows still resolve the tools you expect against your model/provider.

Signal metadata

Source findings

Featured in

Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0

Schema: bitter.frontier_signals.v0 / ID: 2026-07-01-codex-powershell-approval-and-mcp-tool-search

Research evidence and publication history are open in the repository.