
OpenAI Codex Has an Open Issue: Sensitive Files Are Not Excluded From AI Context
You don’t need a catastrophic breach for an AI coding assistant to become a security problem. You just need one “helpful” context fetch that pulls in a secrets file, an internal config, or a customer-specific document that was never meant to leave a developer’s machine. That’s why a live GitHub issue on the official OpenAI Codex repository matters: developers report they cannot reliably exclude sensitive files from AI context, and the issue remains unresolved. Hacker News noticed too, with strong discussion around the risk and the false sense of control this creates.
