Not if the harness applies an OS-level sandbox to the process, as Codex does.
https://learn.chatgpt.com/docs/sandboxing?surface=cli
Unfortunately it was possible in codex too, until recently.
https://github.com/openai/codex/issues/5237
on linux, thats this: https://ubuntu.com/security/notices/USN-8288-1
No, you need to apply the sandbox to the codex process itself. Codex does not do this.
Unfortunately it was possible in codex too, until recently.
https://github.com/openai/codex/issues/5237