security: disable OpenAI Codex from pipeline and tooling#18
security: disable OpenAI Codex from pipeline and tooling#18AndrewAltimit merged 2 commits intomainfrom
Conversation
OpenAI has entered partnerships with governments and defense organizations that enable mass surveillance of civilian populations and autonomous weapons kill-chain decision-making. This poses unacceptable security and ethical risks for anyone whose data transits OpenAI infrastructure. - PR validation: codex-review job set to `if: false` - docker-compose: mcp-codex moved to unreachable profile - .mcp.json: codex server disabled (no-op command) - .env.example: codex config commented out - README/AGENTS/CONTRIBUTING: all references updated, security policy blockquote added recommending Anthropic (Claude) models Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Gemini AI Code ReviewIssues (if any)
Previous Issues (for incremental reviews)(none) Suggestions (if any)
Notes
Generated by Gemini AI (gemini-3-flash-preview). Supplementary to human reviews. |
Remove stale Codex references missed in initial security disable: - Delete tools/cli/agents/run_codex.sh (contradicts security policy) - Delete tools/cli/containers/run_codex_container.sh (broken, references removed codex-agent service) - Remove CODEX_REVIEW_PATH env var from agent-review-response job - Update CLAUDE.md CI description to say "Gemini" not "Gemini/Codex" - Update pr-validation.yml comment to say "Gemini feedback" - Remove run_codex.sh entry from AGENTS.md agent table Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Review Response Agent (Iteration 1)Status: No changes needed Fixed Issues
Ignored Issues
Deferred to Human
Notes
The agent reviewed feedback but determined no code changes were required. |
Gemini AI Incremental ReviewThis is an incremental review focusing on changes since the last review. Issues (if any)(none) Previous Issues (for incremental reviews)
Suggestions (if any)(none) Notes
Generated by Gemini AI (gemini-3-flash-preview). Supplementary to human reviews. |
Review Response Agent (Iteration 2)Status: No changes needed Fixed Issues
Ignored Issues
Deferred to Human
Notes
The agent reviewed feedback but determined no code changes were required. |

Summary
if: false), MCP config, and Docker services due to OpenAI's partnerships enabling mass surveillance and autonomous weapons decision-makingChanges
pr-validation.ymlcodex-reviewjob set toif: false, status summary shows "disabled (security policy)"docker-compose.ymlmcp-codexmoved to unreachabledisabled-codexprofile,CODEX_ENABLED=false.mcp.jsoncodex-DISABLED, command replaced with no-opecho.env.exampleREADME.mdAGENTS.mdCONTRIBUTING.mdTest plan
if: false, dependent jobs unaffected)docker compose --profile services updoes not start mcp-codexGenerated with Claude Code