Escaping the OpenAI Codex sandbox, twice — Accomplish Blog
read-only was the OpenAI Codex mode you picked to be safe opening someone else's repo and asking a question handed them a shell https://www.accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/ Two ways out. One lets a patch write anywhere on the disk with no prompt. The other gets unsandboxed command execution out of read-only, the strictest mode Codex has.