Codex sandbox mode: what it actually contains and where it leaks
Codex CLI runs every command in a restricted shell by default. Here's what that sandbox actually blocks, how to grant network access when you need it, and what it can't protect you from.