Fetching from the wire…
Public story · 2026-08-07 · high
Scripting Codex without it meant piping yes into a prompt built for a human, skipping the approval check entirely.
Why now: As of August 7, running Codex unattended without --approve-for-me still meant piping yes and not admitting it.
Codex 0.147.0 replaces piping yes at a prompt with --approve-for-me, an auto-reviewed approval flag for unattended runs, per the changelog.
Anyone scripting Codex in CI or cron no longer has to fake consent by piping yes into a prompt built for humans. That workaround skipped every check the approval step exists for.
The new flag keeps some form of review in the loop instead of turning it off outright.
The same release tightened plugin isolation and network access enforcement, making both harder to break out of or slip past. It also raised the trust bar for local projects Codex hasn't seen before. None of those are optional the way approval gating is, and they apply whether or not you touch --approve-for-me.
--approve-for-me isn't the old model of a human clicking approve on every step, and it isn't approvals switched off. It's a middle setting. The changelog doesn't say what "automatically reviewed" actually checks, or what makes a review pass versus fail.
OpenAI didn't build this flag speculatively. Piping yes into Codex was already how people ran it in production, unsupported and never admitted. --approve-for-me is OpenAI catching up to what its own users were already doing.
Watch whether OpenAI documents what "automatically reviewed" evaluates. That detail decides whether this is a real safety boundary or a compliance-shaped wrapper around the same yes-pipe everyone was already running.
Each link below shares sources, entities, or timing with this story.
Shipped August 13 to Pro, Business and Enterprise: ChatGPT and Codex can draw on activity memories from apps and websites on macOS, with per-app opt-in and review or delete controls. OpenAI This is Cursor's Google Workspace connector move, but reaching down to OS-level activit...
Three things happened this month that only make sense together. Agent Plugins 1.0 shipped co-signed by six competitors: AWS, Anysphere, Microsoft, OpenAI, Vercel and Google (GitHub Changelog). It makes skills-plus-MCP bundles portable across clients. OpenAI's August 11 Codex c...
mpai (MIT, #12 with 93 upvotes) lets teammates join an in-progress Claude Code or Codex session over Tailscale with full prior-turn context and name-attributed prompts, with a deliberately narrow security model: the host Mac keeps execution authority, no arbitrary shell access...
Launched August 4, running in Ghostty, iTerm2, VS Code, Windows Terminal or Mac Terminal. The architecture is the differentiator: a tmux-like indirection layer between agent and shell that keeps sessions persistent across directory changes, drives full-screen apps like vim and...
Microsoft's July 23 release targets a genuine gap: harness-based agents like Claude Code and Codex drive multi-turn reasoning, tool use, and external system access but were hard to train end-to-end with standard open RL infrastructure. The trick is decoupling training from inf...
Three frontier models shipped in a single week this month, and teams with a standing eval harness had a routing decision in hours. Anthropic's own agent-eval guidance says 20-50 tasks drawn from your real usage and real failures is enough to detect issues (DeepEval). DeepEval...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.