# Local Codex file and environment review

Use different synthetic markers to review file reads and inherited tool-process data.

Fake inputs and an offline boolean probe. Product outcomes are untested.

Source: https://aona.ai/resources/guides/codex-env-secrets-file-access/
Sources checked: 2026-09-21

| Input | Intended rule | Observed |
| --- | --- | --- |
| Allowed file | Define a readable baseline | Untested |
| Restricted .env canary | Define the read restriction | Untested |
| Fake inherited variable | Define whether inheritance is allowed | Untested |

## Review checklist

- [ ] Record the effective local permission model
  Include CLI version, OS, roots, selected profile and relevant administrative requirements.
- [ ] Check inheritance without printing secrets
  Use only the fixed fake variable and record its setup separately from the boolean result.
- [ ] Explain the observation
  A missing marker is not conclusive until the allowed baseline and fixture setup are established.

## Included example files

- README.md
- allowed-marker.txt
- env-canary.txt
- fake-environment.txt
- environment_probe.py
- results.csv
- codex-permissions.example.toml
- codex-environment-filter.example.toml

## Source references

- OpenAI: Agent approvals and security: https://learn.chatgpt.com/docs/agent-approvals-security (2026-09-21)
- OpenAI: Permission profiles: https://learn.chatgpt.com/docs/permissions (2026-09-21)
- OpenAI: Configuration reference: https://learn.chatgpt.com/docs/config-file/config-reference (2026-09-21)
- Codex: historical .env read concern: https://github.com/openai/codex/issues/13778 (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
