# Defense-in-Depth Score: Open Interpreter

**Repo:** https://github.com/openinterpreter/openinterpreter · **Commit:** `2767e5f20d6927500b8f1938c773c61afb823245` · **Reviewed:** 2026-10-03
**What it is:** Coding agent for open models (now a Codex-based Rust harness)
**Category:** Coding
**Scored configuration:** Interactive `interpreter` TUI on macOS/Linux, no flags, fresh install with the default OpenAI provider (native harness); the user answers the first-run folder prompt with "Trust and continue" (the only option besides Quit), giving the workspace-write OS sandbox, network off, approval_policy on-request and a human approver.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory opt-in · untrusted input yes · third party extensions opt-in · sub agents yes · external communication yes

## Score: 3.0 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L2 | L1 | L0 | L1 | 0.28 | G1 | **0.28** (alt) | Medium |
| C2 | Approval gates | L3 | L2 | L1 | L1 | 0.47 | G2 | **0.25** | High |
| C3 | Tool & action scoping | L1 | L1 | L1 | L2 | 0.30 | — | **0.30** | High |
| C4 | Code-execution isolation | L3 | L2 | L1 | L0 | 0.42 | G2 | **0.25** | High |
| C5 | Untrusted input blast radius | L2 | L2 | L1 | L0 | 0.35 | G2 | **0.25** | High |
| C6 | Memory, context & configuration integrity | L1 | L1 | L2 | L1 | 0.30 | C6-REPOCONFIG | **0.25** | High |
| C7 | Third-party extensions | L1 | L1 | L0 | L2 | 0.25 | — | **0.25** | High |
| C8 | Secrets & sensitive-data protection | L2 | L1 | L1 | L0 | 0.28 | — | **0.28** | High |
| C9 | Audit & traceability | L2 | L2 | L3 | L2 | 0.55 | — | **0.55** | High |
| C10 | Limits & kill switch | L1 | L2 | L1 | L1 | 0.33 | — | **0.33** | High |


Open Interpreter inherits Codex's real OS sandbox (Seatbelt on macOS, bubblewrap+seccomp on Linux): model commands can write only inside the project, have no network, and need your approval, with the exact command shown, to leave the sandbox. Protection of the project settings folder is not tamper-resistant. Every command also inherits your full environment (API keys, cloud tokens) and can read your whole disk, and there are no turn, time or spend limits.

## Critical gaps
- Sandboxed commands inherit the full parent environment (credentials included) and can read the whole filesystem, so a hijacked command can harvest secrets even though writes and network are blocked. (ASI05, ASI03, T11, LLM02; C4) — [codex-rs/protocol/src/config_types.rs:261-266](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/config_types.rs#L261-L266); [codex-rs/config/src/shell_environment_policy.rs:135-136](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/shell_environment_policy.rs#L135-L136); [codex-rs/protocol/src/permissions.rs:807-817](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/permissions.rs#L807-L817)

## Criterion details

### C1 Identity & least privilege — 0.28 (medium)

Open Interpreter runs as you and does not narrow your authority for the commands it runs: by default every shell command gets your full environment, including API keys, cloud credentials and GitHub tokens, because the built-in KEY/SECRET/TOKEN filter is off by default. MCP servers are the exception and receive only a small set of core variables. In the current session the network-off sandbox and per-command approval stop those credentials from being used; these protections are not tamper-resistant across sessions. An experimental, opt-in credential broker can swap GitHub and OpenAI tokens for dummies, but it is off by default.

- **default configuration** (default; raw 0.12 → 0.12)
  - **S L0:** Commands run with the operator's ambient identity and full environment; no scoped or per-tool credentials exist by default. — [codex-rs/protocol/src/config_types.rs:261-266](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/config_types.rs#L261-L266); [codex-rs/protocol/src/shell_environment.rs:100-101](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/shell_environment.rs#L100-L101) (verified)
    - *To reach the next level:* No scoped identity or deterministic authorization layer; credentials are not narrowed per tool or capability.
  - **C L1:** Shell subprocesses inherit everything; MCP stdio servers get a scrubbed core-variable environment. — [codex-rs/config/src/shell_environment_policy.rs:135-136](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/shell_environment_policy.rs#L135-L136); [codex-rs/rmcp-client/src/utils.rs:16-26](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rmcp-client/src/utils.rs#L16-L26); [codex-rs/rmcp-client/src/utils.rs:162-175](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rmcp-client/src/utils.rs#L162-L175) (verified)
    - *To reach the next level:* No common authorization layer; the main exec path passes the full environment and only MCP servers are scrubbed.
  - **D L0:** The default shell_environment_policy is inherit=All with the default excludes ignored, so least privilege needs manual config. — [codex-rs/protocol/src/config_types.rs:261-266](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/config_types.rs#L261-L266); [codex-rs/config/src/shell_environment_policy.rs:135-136](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/shell_environment_policy.rs#L135-L136) (verified)
    - *To reach the next level:* Ship inherit=core or apply the KEY/SECRET/TOKEN excludes by default.
  - **B L1:** A hijacked agent can read every credential the user holds. Network-off and per-call escalation hold within a session, but these layers are not tamper-resistant across sessions. — [codex-rs/protocol/src/models.rs:524-531](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/models.rs#L524-L531); [codex-rs/core/src/exec_policy.rs:826-838](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/exec_policy.rs#L826-L838); [codex-rs/protocol/src/permissions.rs:807-817](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/permissions.rs#L807-L817); [codex-rs/config/src/loader/mod.rs:1676-1696](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/loader/mod.rs#L1676-L1696) (verified)
    - *To reach the next level:* Sandbox and approval layers don't reliably bound use of the user's account-wide credentials.
- **opt-in experimental credential broker (network_proxy)** (alt; raw 0.28, cap G1 → 0.28) ← counted
  - **S L2:** The network proxy can replace GitHub/OpenAI tokens in the child environment with dummy values and inject the real token only for bound hosts. — [codex-rs/network-proxy/src/credential_broker/providers.rs:53](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/network-proxy/src/credential_broker/providers.rs#L53); [codex-rs/network-proxy/src/credential_broker/providers.rs:11](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/network-proxy/src/credential_broker/providers.rs#L11) (inferred)
    - *To reach the next level:* Host-bound substitution was not traced end to end (inferred), and credentials are not downscoped or short-lived per task.
  - **C L1:** Only GitHub and OpenAI credential families are brokered; other env credentials still pass through. — [codex-rs/network-proxy/src/credential_broker/providers.rs:53](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/network-proxy/src/credential_broker/providers.rs#L53) (verified)
    - *To reach the next level:* Brokering does not cover cloud or other credentials in the environment.
  - **D L0:** network_proxy is an experimental feature with default_enabled false. — [codex-rs/features/src/lib.rs:1284-1292](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/features/src/lib.rs#L1284-L1292) (verified)
    - *To reach the next level:* Enable brokering by default.
  - **B L1:** Same as the default: surviving layers are not tamper-resistant. — [codex-rs/protocol/src/models.rs:524-531](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/models.rs#L524-L531) (verified)
    - *To reach the next level:* Other ambient credentials remain readable inside the sandbox.
- **Cap:** G1 — Opt-in mechanism: off in the scored default configuration.
- **Notes:** Project settings handling differs from upstream Codex.

### C2 Approval gates — 0.25 (high)

Approval is built around the sandbox: commands that stay inside it (editing project files, running tests) run without asking, while anything that needs to escape it, such as network access, writes outside the project or an escalated command, stops for your approval with the exact command on screen. Forced `rm -f` deletions always prompt, and MCP tools prompt unless their server declares them read-only. The approval gate is not tamper-resistant across sessions in this fork. There is no undo for approved actions.

- **S L3:** Per-call approval shows the full command (or MCP tool and arguments), with tiers set by the sandbox boundary, a dangerous-command heuristic and MCP annotations; the approver is the human by default. — [codex-rs/core/src/tools/orchestrator.rs:203-223](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/tools/orchestrator.rs#L203-L223); [codex-rs/tui/src/bottom_pane/approval_overlay.rs:729](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/tui/src/bottom_pane/approval_overlay.rs#L729); [codex-rs/core/src/config/mod.rs:3700](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/config/mod.rs#L3700); [codex-rs/core/src/exec_policy.rs:799-806](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/exec_policy.rs#L799-L806); [codex-rs/tui/src/bottom_pane/approval_overlay.rs:858-860](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/tui/src/bottom_pane/approval_overlay.rs#L858-L860) (verified)
  - *To reach the next level:* Exec-policy argument rules are prefix-based and opt-in; approving a prefix ("don't ask again") lets later variants run unsandboxed.
- **C L2:** Every escalation from the shell, apply_patch outside writable roots, and MCP calls go through the gate, and sub-agents inherit the same policy. In-sandbox workspace writes are ungated by design, and MCP tools whose server says readOnlyHint skip approval. — [codex-rs/core/src/exec_policy.rs:826-838](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/exec_policy.rs#L826-L838); [codex-rs/core/src/mcp_tool_call.rs:2426-2431](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/mcp_tool_call.rs#L2426-L2431); [codex-rs/config/src/mcp_types.rs:26-29](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/mcp_types.rs#L26-L29); [codex-rs/core/src/agent/child_config.rs:171-180](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/agent/child_config.rs#L171-L180); [codex-rs/core/src/exec_policy.rs:440-443](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/exec_policy.rs#L440-L443) (verified)
  - *To reach the next level:* MCP auto-approval trusts server-supplied annotations, and approved prefix rules match by prefix and bypass the sandbox.
- **D L1:** On by default for trusted folders, but project config outranks user config and loads silently at the next start, and protection of the project config folder is not tamper-resistant. — [codex-rs/core/src/safety.rs:70-76](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/safety.rs#L70-L76); [codex-rs/config/src/loader/mod.rs:1676-1696](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/loader/mod.rs#L1676-L1696); [codex-rs/config/src/loader/mod.rs:84-98](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/loader/mod.rs#L84-L98); [codex-rs/config/src/config_layer_source.rs:39-46](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/config_layer_source.rs#L39-L46); [codex-rs/core/src/exec_policy.rs:678-681](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/exec_policy.rs#L678-L681) (verified)
  - *To reach the next level:* Require an explicit re-review before project config can loosen approvals.
- **B L1:** Unapproved actions are confined to workspace files with .git kept read-only, but an approved escalation runs fully unsandboxed and there is no checkpoint or undo. — [codex-rs/protocol/src/permissions.rs:848-850](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/permissions.rs#L848-L850); [codex-rs/core/src/tools/sandboxing.rs:251-261](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/tools/sandboxing.rs#L251-L261); searched `rg -n -S 'undo|checkpoint'` in `codex-rs/tui/src/slash_command.rs` → 0 hits (no /undo or checkpoint slash command) (verified)
  - *To reach the next level:* No checkpoints or rollback; escalated commands (push, deletes outside the project) are irreversible.
- **Cap:** G2 — The model can weaken the approval gate for later sessions.

### C3 Tool & action scoping — 0.30 (high)

The main tool is a general shell that accepts any command string, so argument validation is minimal: there is no allowlist, only a small heuristic that flags forced `rm` and user-written prefix rules. The file-edit tool checks every path against the writable folders before auto-approving. Everything is on by default, though the shell tool can be turned off. In practice a misused command's reach is bounded by the sandbox: writes stay in the project, but reads cover the whole machine.

- **S L1:** The exec tool takes a raw shell string; checks are a dangerous-command heuristic (forced rm) plus optional prefix rules, while apply_patch checks paths against writable roots. — [codex-rs/core/src/tools/handlers/shell_spec.rs:38](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/tools/handlers/shell_spec.rs#L38); [codex-rs/shell-command/src/command_safety/is_dangerous_command.rs:133](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/shell-command/src/command_safety/is_dangerous_command.rs#L133); [codex-rs/core/src/safety.rs:70-76](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/safety.rs#L70-L76) (verified)
  - *To reach the next level:* No allowlist validation of commands, paths or hosts at the tool layer; containment comes only from the sandbox.
- **C L1:** apply_patch and MCP calls are checked; the shell, the most used tool, has only the denylist heuristic. — [codex-rs/core/src/safety.rs:70-76](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/safety.rs#L70-L76); [codex-rs/shell-command/src/command_safety/is_dangerous_command.rs:133](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/shell-command/src/command_safety/is_dangerous_command.rs#L133) (verified)
  - *To reach the next level:* Most tools are not argument-validated.
- **D L1:** Shell, unified exec, file edit and web search are on by default; the shell can be turned off through features.shell_tool. — [codex-rs/features/src/lib.rs:960-965](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/features/src/lib.rs#L960-L965); [codex-rs/config/src/config_toml.rs:802-808](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/config_toml.rs#L802-L808) (verified)
  - *To reach the next level:* No read-only default tool set for trusted folders.
- **B L2:** A misused command can write anywhere in the project (plus /tmp) and read the whole filesystem, with network off. — [codex-rs/protocol/src/permissions.rs:807-817](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/permissions.rs#L807-L817); [codex-rs/protocol/src/permissions.rs:848-850](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/permissions.rs#L848-L850); [codex-rs/protocol/src/models.rs:524-531](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/models.rs#L524-L531) (verified)
  - *To reach the next level:* No quantity bounds; reads are machine-wide.
- **Cap:** none

### C4 Code-execution isolation — 0.25 (high)

Model-issued commands run inside a real operating-system sandbox: a deny-by-default Seatbelt profile on macOS, and bubblewrap plus seccomp with no network namespace on Linux, which fails closed if bubblewrap is missing instead of running on the host. Writes are limited to the project and /tmp, network is off, and leaving the sandbox needs your approval per command. But the sandbox is not tamper-resistant across sessions. Inside the sandbox, commands also see your full environment (credentials included) and can read your entire disk.

- **S L3:** Seatbelt (deny default) or bubblewrap+seccomp+no_new_privs, with writes limited to workspace roots and network denied by default. — [codex-rs/sandboxing/src/seatbelt_base_policy.sbpl:7-8](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/sandboxing/src/seatbelt_base_policy.sbpl#L7-L8); [codex-rs/linux-sandbox/src/bwrap.rs:373-378](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/linux-sandbox/src/bwrap.rs#L373-L378); [codex-rs/linux-sandbox/src/linux_run_main.rs:215-220](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/linux-sandbox/src/linux_run_main.rs#L215-L220); [codex-rs/protocol/src/models.rs:524-531](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/models.rs#L524-L531) (verified)
  - *To reach the next level:* Not kernel-separated isolation (microVM/gVisor/WASM).
- **C L2:** Shell, unified exec and apply_patch go through the platform sandbox with no unsandboxed fallback on Linux, but MCP stdio servers run on the host and commands matched by allow-rules bypass the sandbox. — [codex-rs/sandboxing/src/manager.rs:48-52](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/sandboxing/src/manager.rs#L48-L52); [codex-rs/linux-sandbox/src/launcher.rs:50-54](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/linux-sandbox/src/launcher.rs#L50-L54); [codex-rs/linux-sandbox/src/linux_run_main.rs:289-292](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/linux-sandbox/src/linux_run_main.rs#L289-L292); [codex-rs/rmcp-client/src/stdio_server_launcher.rs:273-282](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rmcp-client/src/stdio_server_launcher.rs#L273-L282); [codex-rs/core/src/tools/sandboxing.rs:251-261](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/tools/sandboxing.rs#L251-L261); [codex-rs/codex-mcp/src/connection_manager.rs:288-290](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/codex-mcp/src/connection_manager.rs#L288-L290) (verified)
  - *To reach the next level:* Host-run MCP servers and allow-rule bypasses run outside the sandbox.
- **D L1:** On for trusted folders, but sandbox_mode, network access and allow-rules can be set from project config in the workspace, and that folder's protection is not tamper-resistant. — [codex-rs/config/src/config_toml.rs:802-808](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/config_toml.rs#L802-L808); [codex-rs/protocol/src/permissions.rs:2259-2266](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/permissions.rs#L2259-L2266); [codex-rs/config/src/loader/mod.rs:84-98](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/loader/mod.rs#L84-L98); [codex-rs/config/src/config_layer_source.rs:39-46](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/config_layer_source.rs#L39-L46) (verified)
  - *To reach the next level:* Sandbox policy should not be changeable from workspace-scoped config.
- **B L0:** Inside the sandbox the full parent environment (API keys, cloud tokens) is present and the whole filesystem, including ~/.ssh and ~/.openinterpreter/auth.json, is readable; only writes and network are restricted. — [codex-rs/protocol/src/config_types.rs:261-266](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/config_types.rs#L261-L266); [codex-rs/config/src/shell_environment_policy.rs:135-136](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/shell_environment_policy.rs#L135-L136); [codex-rs/protocol/src/permissions.rs:807-817](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/permissions.rs#L807-L817); [codex-rs/utils/home-dir/src/lib.rs:84-90](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/utils/home-dir/src/lib.rs#L84-L90) (verified)
  - *To reach the next level:* Strip credentials from the sandbox environment and deny reads of home-directory secrets by default.
- **Cap:** G2 — The model can weaken the sandbox for later sessions.

### C5 Untrusted input blast radius — 0.25 (high)

Open Interpreter does not try to detect prompt injection; its protection is structural. Within one session, the network-off sandbox means an agent hijacked by a malicious README, command output or search result can't send data out or act outside the project without you approving a specific command. That protection is not tamper-resistant beyond the session. MCP tools that their server labels read-only are also called without approval.

- **S L2:** Egress and out-of-workspace changes need human approval in the running session because the sandbox denies them, whatever was read; in-workspace changes don't. — [codex-rs/protocol/src/models.rs:524-531](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/models.rs#L524-L531); [codex-rs/core/src/exec_policy.rs:826-838](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/exec_policy.rs#L826-L838); [codex-rs/core/src/tools/orchestrator.rs:371-375](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/tools/orchestrator.rs#L371-L375) (verified)
  - *To reach the next level:* State-changing workspace actions are not gated after untrusted content enters; there is no provenance or taint tracking.
- **C L2:** The sandbox applies to commands whatever their source, but MCP tool calls are gated only by server-declared annotations. — [codex-rs/core/src/mcp_tool_call.rs:2426-2431](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/mcp_tool_call.rs#L2426-L2431); [codex-rs/config/src/mcp_types.rs:26-29](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/mcp_types.rs#L26-L29) (verified)
  - *To reach the next level:* MCP tools with readOnlyHint=true are an ungated channel for content-driven calls.
- **D L1:** Network-off is the default for workspace-write, but it is not tamper-resistant across sessions. — [codex-rs/protocol/src/models.rs:524-531](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/models.rs#L524-L531); [codex-rs/config/src/loader/mod.rs:84-98](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/loader/mod.rs#L84-L98) (verified)
  - *To reach the next level:* Nothing the agent writes should be able to reconfigure the sandbox or approval policy.
- **B L0:** Assuming a hijack, secrets can be leaked and irreversible actions taken with no approval through a path that is not gated. — [codex-rs/core/src/safety.rs:70-76](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/safety.rs#L70-L76); [codex-rs/config/src/loader/mod.rs:1676-1696](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/loader/mod.rs#L1676-L1696); [codex-rs/config/src/mcp_types.rs:558-559](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/mcp_types.rs#L558-L559); [codex-rs/codex-mcp/src/connection_manager.rs:288-290](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/codex-mcp/src/connection_manager.rs#L288-L290); [codex-rs/rmcp-client/src/stdio_server_launcher.rs:273-282](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rmcp-client/src/stdio_server_launcher.rs#L273-L282) (verified)
  - *To reach the next level:* Persistent changes must not loosen the sandbox or launch host commands without a human decision.
- **Cap:** G2 — The model can weaken the network-off sandbox and approval policy for later sessions.

### C6 Memory, context & configuration integrity — 0.25 (high)

Open Interpreter keeps upstream Codex's folder-trust step: project config, exec-policy rules and hooks load only after you trust the folder, each hook must also be trusted by its content hash in your own settings, and some keys (model endpoints, notify, telemetry) are always ignored in project config. But project config and rules changed after the trust decision load with no prompt and can change approvals, sandbox mode and MCP servers for every later session, and the folder's protection is not tamper-resistant. AGENTS.md instructions also load silently and are writable by the agent. Long-term memories are off by default.

- **S L1:** Folder trust and hook hash-trust exist, but project config and rules changed after trust load with no further prompt; instruction files also load silently. — [codex-rs/tui/src/onboarding/trust_directory.rs:68-73](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/tui/src/onboarding/trust_directory.rs#L68-L73); [codex-rs/hooks/src/engine/discovery.rs:805-809](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/hooks/src/engine/discovery.rs#L805-L809); [codex-rs/hooks/src/config_rules.rs:23-29](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/hooks/src/config_rules.rs#L23-L29); [codex-rs/config/src/loader/mod.rs:1676-1696](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/loader/mod.rs#L1676-L1696); [codex-rs/core/src/agents_md.rs:58-66](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/agents_md.rs#L58-L66) (verified)
  - *To reach the next level:* Project config changed after the trust decision is not re-reviewed, so it can still change security settings.
- **C L1:** Only hooks are covered beyond the one-time folder trust; project config, rules, AGENTS.md and repo skills are not re-checked. — [codex-rs/hooks/src/engine/discovery.rs:713-719](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/hooks/src/engine/discovery.rs#L713-L719); [codex-rs/core/src/exec_policy.rs:678-681](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/exec_policy.rs#L678-L681); [codex-rs/core/src/agents_md.rs:58-66](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/agents_md.rs#L58-L66) (verified)
  - *To reach the next level:* Config, rules and instruction files are not covered by a per-content trust check.
- **D L2:** Trust decisions, hook trust and session state live in ~/.openinterpreter, outside the sandbox's writable roots, but project-scope config overrides user config. — [codex-rs/utils/home-dir/src/lib.rs:84-90](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/utils/home-dir/src/lib.rs#L84-L90); [codex-rs/protocol/src/permissions.rs:807-817](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/permissions.rs#L807-L817); [codex-rs/config/src/config_layer_source.rs:39-46](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/config_layer_source.rs#L39-L46) (verified)
  - *To reach the next level:* Effective configuration can still be altered through the project scope.
- **B L1:** Planted AGENTS.md persists across the user's sessions in that folder and can trigger tool use. — [codex-rs/config/src/loader/mod.rs:1676-1696](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/loader/mod.rs#L1676-L1696); [codex-rs/codex-mcp/src/connection_manager.rs:288-290](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/codex-mcp/src/connection_manager.rs#L288-L290); [codex-rs/core/src/agents_md.rs:58-66](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/agents_md.rs#L58-L66) (verified)
  - *To reach the next level:* Planted files are not session-scoped or reviewed before reuse.
- **Cap:** C6-REPOCONFIG — Workspace project config enables MCP servers and loosens approval/sandboxing at the next start without any user decision about its content.

### C7 Third-party extensions — 0.25 (high)

No third-party extensions run by default. MCP servers and plugins come from your config or the project's config and start automatically on the host, unsandboxed but with a cleaned-up environment; there is no version pinning or integrity check. The bundled QA skill tells the model to download the latest agent-browser binary from GitHub and run it, which goes through the normal per-command approval. When a skill needs an MCP server you are asked first, but the prompt lists only server names, not the command that will run.

- **S L1:** MCP servers and custom marketplace plugins run whatever the configured source provides, and the bundled QA skill installs unpinned `latest` release binaries. — [codex-rs/rmcp-client/src/stdio_server_launcher.rs:273-282](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rmcp-client/src/stdio_server_launcher.rs#L273-L282); [codex-rs/core-plugins/src/startup_sync.rs:28-30](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core-plugins/src/startup_sync.rs#L28-L30); [codex-rs/skills/src/assets/samples/qa-testing/SKILL.md:39](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/skills/src/assets/samples/qa-testing/SKILL.md#L39) (verified)
  - *To reach the next level:* No pinning, hash or signature verification for MCP servers, custom marketplaces or skill-driven tool installs.
- **C L1:** Only the vendor curated plugin catalog comes from a fixed source; MCP servers and skill-declared dependencies are unverified. — [codex-rs/core-plugins/src/startup_sync.rs:28-30](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core-plugins/src/startup_sync.rs#L28-L30); [codex-rs/core/src/mcp_skill_dependencies.rs:356](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/mcp_skill_dependencies.rs#L356) (verified)
  - *To reach the next level:* Verification does not cover MCP servers or skill dependencies.
- **D L0:** Workspace files can add MCP servers silently: project config may define mcp_servers, and servers default to enabled and start without consent. — [codex-rs/config/src/mcp_types.rs:558-559](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/mcp_types.rs#L558-L559); [codex-rs/codex-mcp/src/connection_manager.rs:288-290](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/codex-mcp/src/connection_manager.rs#L288-L290); [codex-rs/config/src/loader/mod.rs:84-98](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/loader/mod.rs#L84-L98); [codex-rs/core/src/mcp_skill_dependencies.rs:279](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/mcp_skill_dependencies.rs#L279) (verified)
  - *To reach the next level:* Only user or admin scope should be able to add servers, and adding one should show the exact command.
- **B L2:** MCP stdio servers run as separate processes with only core environment variables plus declared ones, but unsandboxed as the user. — [codex-rs/rmcp-client/src/utils.rs:16-26](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rmcp-client/src/utils.rs#L16-L26); [codex-rs/rmcp-client/src/utils.rs:162-175](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rmcp-client/src/utils.rs#L162-L175); [codex-rs/rmcp-client/src/stdio_server_launcher.rs:273-282](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rmcp-client/src/stdio_server_launcher.rs#L273-L282) (verified)
  - *To reach the next level:* No per-extension sandbox or file/network confinement.
- **Cap:** none
- **Notes:** Third-party extensions are opt-in in the sense that none ship enabled; D is L0 because the workspace can add them silently, not because consent is opt-in, so G1 does not apply.

### C8 Secrets & sensitive-data protection — 0.28 (high)

Your login is stored by default in a plaintext auth.json under ~/.openinterpreter with owner-only permissions; MCP OAuth tokens prefer the OS keyring. Secret redaction exists but isn't applied to tool output sent to the model or to saved transcripts. The biggest gap is that every shell command inherits your full environment, so long-lived keys are within reach of any command the model runs. Usage analytics (sent to the ChatGPT backend URL) are on unless disabled; prompt logging to OpenTelemetry is off.

- **S L2:** Credentials in a 0600 plaintext file by default, keyring for MCP OAuth, and a redact_secrets helper used on some display paths. — [codex-rs/config/src/types.rs:115-117](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/types.rs#L115-L117); [codex-rs/login/src/auth/storage.rs:213-218](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/login/src/auth/storage.rs#L213-L218); [codex-rs/config/src/types.rs:130-135](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/types.rs#L130-L135) (verified)
  - *To reach the next level:* No keychain by default for the main credential and no redaction before model-bound messages or transcripts.
- **C L1:** Redaction covers only some display paths; subprocess env, model-bound tool output and rollout transcripts are unprotected. — searched `rg -n -F 'redact_secrets('` in `codex-rs/core/src codex-rs/rollout/src` → 0 hits (the redaction helper is never called on model-bound tool output or rollout transcripts); [codex-rs/protocol/src/config_types.rs:261-266](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/config_types.rs#L261-L266); [codex-rs/rollout/src/policy.rs:44-60](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rollout/src/policy.rs#L44-L60) (verified)
  - *To reach the next level:* Most paths (subprocess env, transcripts, model context) are unprotected.
- **D L1:** Analytics are on unless analytics.enabled=false; OTel log export is off and prompts are not logged by default. — [codex-rs/analytics/src/client.rs:252-256](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/analytics/src/client.rs#L252-L256); [codex-rs/app-server/src/analytics_utils.rs:11-15](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/app-server/src/analytics_utils.rs#L11-L15); [codex-rs/core/src/config/otel.rs:13-20](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/config/otel.rs#L13-L20) (verified)
  - *To reach the next level:* Telemetry is opt-out rather than opt-in.
- **B L0:** Long-lived user keys in the environment are passed to every subprocess, and auth.json is readable inside the sandbox. — [codex-rs/protocol/src/config_types.rs:261-266](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/config_types.rs#L261-L266); [codex-rs/config/src/shell_environment_policy.rs:135-136](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/config/src/shell_environment_policy.rs#L135-L136); [codex-rs/protocol/src/permissions.rs:807-817](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/permissions.rs#L807-L817) (verified)
  - *To reach the next level:* Keep long-lived keys out of subprocesses by default (scrub env or broker credentials).
- **Cap:** none

### C9 Audit & traceability — 0.55 (high)

Every session is written to a JSON-lines transcript under ~/.openinterpreter/sessions that records each tool call and its output, including MCP calls; sub-agents get their own transcripts. The file sits outside the sandbox's writable area, so the model's commands can't edit it. Approval prompts and your decisions aren't saved, there is no tamper-evidence, and write failures are only logged while the agent carries on.

- **S L2:** A structured rollout records function calls, outputs, turn context and token usage. — [codex-rs/rollout/src/policy.rs:44-60](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rollout/src/policy.rs#L44-L60); [codex-rs/rollout/src/lib.rs:84](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rollout/src/lib.rs#L84) (verified)
  - *To reach the next level:* No actor attribution of approvals or approvers and no tamper-evident or exported audit stream by default.
- **C L2:** All tool calls, including MCP and custom tools, are persisted, but approval requests and decisions are transient. — [codex-rs/rollout/src/policy.rs:44-60](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rollout/src/policy.rs#L44-L60); [codex-rs/rollout/src/policy.rs:172-181](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rollout/src/policy.rs#L172-L181) (verified)
  - *To reach the next level:* Approvals and denials are not in the durable record.
- **D L3:** On by default and written by the agent process into ~/.openinterpreter, outside the sandbox's writable roots. — [codex-rs/rollout/src/lib.rs:84](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rollout/src/lib.rs#L84); [codex-rs/utils/home-dir/src/lib.rs:84-90](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/utils/home-dir/src/lib.rs#L84-L90); [codex-rs/protocol/src/permissions.rs:807-817](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/protocol/src/permissions.rs#L807-L817) (verified)
  - *To reach the next level:* Can be disabled (ephemeral sessions) without that change being logged.
- **B L2:** Items are flushed per append and write errors trigger retries and error logs, but actions proceed regardless. — [codex-rs/rollout/src/recorder.rs:1920-1922](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rollout/src/recorder.rs#L1920-L1922); [codex-rs/rollout/src/recorder.rs:1826-1834](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/rollout/src/recorder.rs#L1826-L1834) (verified)
  - *To reach the next level:* Not fail-closed and not fsync-durable per action.
- **Cap:** none

### C10 Limits & kill switch — 0.33 (high)

There is no default cap on turns, wall-clock time or spend; the token-budget feature is still under development and off. You can interrupt a turn at any time, which cancels the running task, but commands started as background terminals keep running until you clean them up or exit. Sub-agents inherit the same settings and are capped at 6 concurrent threads and a depth of 1, and at most 64 background processes can exist.

- **S L1:** A working interrupt and caps on sub-agent threads/depth and process count exist, but there is no step, wall-clock or token/cost limit. — searched `rg -n -S 'max_turns|max_iterations|max_steps|turn_limit'` in `codex-rs/core/src` → 0 hits (no turn/step cap anywhere in the core agent loop); [codex-rs/features/src/lib.rs:1672-1677](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/features/src/lib.rs#L1672-L1677); [codex-rs/core/src/session/mod.rs:4881-4884](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/session/mod.rs#L4881-L4884) (verified)
  - *To reach the next level:* No iteration cap or token/cost cap enforced in code by default.
- **C L2:** Sub-agents share the parent's policy with thread and depth caps; exec calls yield after a bounded wait. — [codex-rs/core/src/config/mod.rs:252-262](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/config/mod.rs#L252-L262); [codex-rs/core/src/unified_exec/mod.rs:78-82](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/unified_exec/mod.rs#L78-L82); [codex-rs/core/src/agent/child_config.rs:171-180](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/agent/child_config.rs#L171-L180) (verified)
  - *To reach the next level:* No overall budget that sub-agents and background processes count against.
- **D L1:** No session ceilings by default; the model chooses yield times and keeps background terminals running. — [codex-rs/core/src/tools/handlers/shell_spec.rs:31](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/tools/handlers/shell_spec.rs#L31); [codex-rs/features/src/lib.rs:1672-1677](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/features/src/lib.rs#L1672-L1677) (verified)
  - *To reach the next level:* No sensible default run-time or spend ceiling.
- **B L1:** Runs are unbounded, and interrupting a turn leaves background terminals running until /clean or exit. — [codex-rs/core/src/session/mod.rs:4881-4884](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/session/mod.rs#L4881-L4884); [codex-rs/core/src/session/handlers.rs:60-62](https://github.com/openinterpreter/openinterpreter/blob/2767e5f20d6927500b8f1938c773c61afb823245/codex-rs/core/src/session/handlers.rs#L60-L62) (verified)
  - *To reach the next level:* Stop does not kill background processes; no per-run time or cost ceiling.
- **Cap:** none

## Rule-of-Two check
[A] untrusted input: Repository files and AGENTS.md, command output, cached web_search results and MCP tool results enter context (codex-rs/core/src/agents_md.rs:58; codex-rs/protocol/src/config_types.rs:376) · [B] sensitive data/systems: Sandboxed commands can read the whole filesystem and inherit the full environment, secrets included (codex-rs/protocol/src/permissions.rs:807; codex-rs/protocol/src/config_types.rs:261) · [C] state change / egress: Workspace writes run unattended; egress needs per-call approval in the current session (codex-rs/core/src/safety.rs:70), but that protection is not tamper-resistant across sessions · Same default session? Yes

## Highest-impact improvements
1. Harden how project configuration and rules are protected from the sandboxed agent. — C2 D L1→L2, +0.050 before caps (Playbook 5)
2. Require an explicit re-review when project config sets sandbox_mode, network access, allow-rules or mcp_servers. — C4 D L1→L2, +0.050 before caps (Playbook 3)
3. Default shell_environment_policy to apply the KEY/SECRET/TOKEN excludes (or inherit=core) so sandboxed commands stop receiving long-lived credentials. — C8 B L0→L2, +0.100 before caps (Playbook 4)
4. Ship a default per-session turn and token budget and kill background terminals on interrupt. — C10 S L1→L2, +0.075 before caps (Playbook 3 step 3)
5. Show the exact command and package when adding an MCP server and disallow mcp_servers in project-local config. — C7 D L0→L2, +0.100 before caps (Playbook 3)

## Re-audit log
- No changes.

## Limitations
- Static source review of the pinned commit only; nothing was executed, installed, or probed.
- Scored the interactive TUI on macOS/Linux with the default OpenAI provider, which selects the native (Codex) tool harness. Choosing another provider auto-selects a different harness (e.g. Kimi -> kimi-code, Anthropic -> claude-code, DeepSeek -> claude-code-bare; codex-rs/model-provider-info/src/lib.rs:216-280). Those harnesses add alias tools that were only spot-checked: their Write/Edit tools write directly from the agent process after an in-process sandbox-policy check, and the kimi-code harness adds a FetchURL tool (public addresses only, no approval) that would be an unattended outbound channel. Scoring a Kimi configuration would likely lower C5 further.
- Windows, `interpreter exec`, `interpreter acp`, the app-server/daemon surfaces and the inherited cloud-tasks agent were not scored.
- This repository is a fork of OpenAI Codex. Much of the inherited code (orchestrator, exec policy, sandbox crates, hooks, rollout) was verified at this commit against an earlier audit of upstream Codex; fork-specific changes were reviewed where they touch the trust boundary (product home and project config folder naming, harness selection and alias tools, bundled QA skill). Browser/computer use, realtime/voice, remote plugins, guardian (opt-in LLM auto-reviewer) and the Windows sandbox were not examined in depth.
- Judgment call: a cross-session gap in tamper resistance was treated as the model being able to disable the approval gate and sandbox (G2 on C2, C4 and C5; C6-REPOCONFIG) rather than as operator configuration.
- The opt-in experimental credential broker (network_proxy) was only skimmed and is scored as a C1 alt with INFERRED strength.
- No reviewer-injection text was found: the two AGENTS.md files (repo root and codex-rs/tui/src/bottom_pane/) are ordinary contributor guidance.
