# Codex Knowledge Base > A continuously updated knowledge base for Codex. Practical articles on agentic software engineering workflows, configuration and integration. Author: Daniel Vaughan — Building expertise in agentic software engineering with Codex Site: https://codex.danielvaughan.com Feed: https://codex.danielvaughan.com/feed.xml Sitemap: https://codex.danielvaughan.com/sitemap.xml Tags index: https://codex.danielvaughan.com/tags/ ## About Codex Knowledge Base is a technical knowledge base maintained by Daniel Vaughan covering agentic software engineering with Codex. Articles cover CLI internals, prompting and workflow patterns, integrations, enterprise deployment, security, and adjacent tools. The author is also writing a companion book: [Codex CLI: Agentic Engineering from First Principles](https://leanpub.com/codex-cli/c/CODEXSITE20). ## Canonical resources - [RSS / Atom feed](https://codex.danielvaughan.com/feed.xml) — full-text of every article - [XML sitemap](https://codex.danielvaughan.com/sitemap.xml) — complete URL list with last-modified dates - [Tag index](https://codex.danielvaughan.com/tags/) — browse by topic ## Recent articles- [VulnGym and the Business-Logic Blindspot: What Repository-Level Vulnerability Benchmarks Reveal About Coding Agent Security Scanning](https://codex.danielvaughan.com/2026/08/07/vulngym-repository-level-vulnerability-detection-coding-agents-codex-cli-security-scanning-business-logic-flaws/) - [Code Isn't Memory: What Structural Codebase Indexing Means for Your Codex CLI Exploration Costs](https://codex.danielvaughan.com/2026/08/07/structural-codebase-indexing-coding-agents-codex-cli-exploration-cost-codegraph-mcp/) - [Scrouting: What Cost-Aware Repository Scouting Means for Your Codex CLI Model Routing Strategy](https://codex.danielvaughan.com/2026/08/07/scrouting-cost-aware-model-routing-repository-scouting-codex-cli-sol-terra-luna-task-routing/) - [MCP 2026-07-28: What the Stateless Protocol Overhaul Means for Your Codex CLI MCP Servers](https://codex.danielvaughan.com/2026/08/07/mcp-2026-07-28-stateless-protocol-codex-cli-paginated-discovery-multi-round-requests-migration/) - [Codex CLI v0.147.0: --approve-for-me, MCP 2026-07-28 Protocol, Project Trust Gates, and the End of --full-auto](https://codex.danielvaughan.com/2026/08/07/codex-cli-v0147-release-approve-for-me-mcp-2026-07-28-project-trust-plugin-search-secrets-redaction/) - [BulkPR-Bench: Why Your Multi-Agent PR Queue Is a Governance Problem — and What Codex CLI Developers Should Do About It](https://codex.danielvaughan.com/2026/08/07/bulkpr-bench-queue-level-governance-interacting-pull-requests-codex-cli-multi-agent-merge-queue-coordination/) - [AGENTS.md Pays for Itself: What the ICSE 2026 JAWs Efficiency Study Means for Your Codex CLI Token Budget](https://codex.danielvaughan.com/2026/08/07/agents-md-efficiency-impact-icse-2026-jaws-codex-cli-token-savings-runtime-reduction/) - [RepoComplianceBench: Why Your Coding Agent Ignores Open-Source Contribution Rules — and What Codex CLI Practitioners Can Do About It](https://codex.danielvaughan.com/2026/08/06/repo-compliance-bench-coding-agents-ai-contribution-rules-open-source-codex-cli-disclosure-governance/) - [PerfAgent and the Profiler Feedback Loop: Why Your Coding Agent Stops at Shallow Speedups — and How to Build an Iterative Optimisation Workflow in Codex CLI](https://codex.danielvaughan.com/2026/08/06/perfagent-profiler-guided-iterative-refinement-codex-cli-performance-optimization-postooluse-hooks/) - [Meta Muse Code Enters the Terminal Agent Wars: Persistent Background Agents, Replay-Safe Event Logs, and What It Means for Your Codex CLI Workflow](https://codex.danielvaughan.com/2026/08/06/meta-muse-code-beta-persistent-agents-codex-cli-terminal-agent-landscape-competitive-analysis/) - [Long-Horizon-Terminal-Bench: What Dense Reward Grading Reveals About Your Codex CLI Session Strategy](https://codex.danielvaughan.com/2026/08/06/long-horizon-terminal-bench-dense-reward-grading-codex-cli-goal-mode-session-strategy/) - [IssueTrojanBench: 66.5% of Malicious Issues Bypass Coding Agent Guardrails — What Codex CLI's Sandbox Architecture Gets Right](https://codex.danielvaughan.com/2026/08/06/issuetrojanbench-malicious-issue-injection-coding-agents-codex-cli-sandbox-defence-supply-chain-guardrails/) - [Failure as a Process: What 63,000 Annotated Execution Steps Reveal About CLI Coding Agent Trajectories — and How to Intervene Earlier in Codex CLI](https://codex.danielvaughan.com/2026/08/06/failure-as-a-process-cli-coding-agent-trajectory-anatomy-codex-cli-early-intervention/) - [Do Context Files Actually Help? What a 288-Run Ablation Study Reveals About AGENTS.md, Correctness, and Your Codex CLI Workflow](https://codex.danielvaughan.com/2026/08/06/do-context-files-help-coding-agents-agents-md-ablation-study-codex-cli-correctness-vs-efficiency/) - [ContinualSkillBench: Can Your Coding Agent Actually Learn From Experience — and What Codex CLI's Skill Architecture Gets Right](https://codex.danielvaughan.com/2026/08/06/continualskillbench-llm-agent-skill-evolution-codex-cli-skill-architecture-consolidation-gap/) - [Codex Security CLI Goes Open Source: Building Agentic SAST into Your Merge Path](https://codex.danielvaughan.com/2026/08/06/codex-security-cli-open-source-apache-2-merge-path-agentic-sast-ci-cd-pipeline/) — OpenAI open-sourced the Codex Security CLI and TypeScript SDK under Apache 2.0 in July 2026. This article dissects its architecture, compares it with pattern-based SAST tools, and shows how to wire... - [Codex CLI Rollout Token Budgets: Shared Accounting, Weighted Limits, and Graceful Turn Abortion](https://codex.danielvaughan.com/2026/08/06/codex-cli-rollout-token-budgets-shared-accounting-weighted-limits-turn-abortion/) - [Black Hat 2026: Eleven Agent Framework CVEs and Why Codex CLI's Sandbox-First Architecture Dodges the Worst of Them](https://codex.danielvaughan.com/2026/08/06/black-hat-2026-agent-framework-vulnerabilities-codex-cli-sandbox-architecture-defence-mcp-server-supply-chain/) - [AISI's Unsanctioned Agent Actions: What the July 28th Cyber Testing Incident Teaches Codex CLI Developers About Containment Architecture](https://codex.danielvaughan.com/2026/08/06/aisi-unsanctioned-agent-actions-cyber-testing-codex-cli-sandbox-containment-architecture-lessons/) - [The Verification Inversion: Why Generation Became Easy, Verification Became Hard, and What the Research Says You Should Do About It](https://codex.danielvaughan.com/2026/08/05/verification-inversion-generation-easy-verification-hard-codex-cli-constraints-research/) — Two June 2026 papers reframe the coding agent bottleneck: the Qwen Team's Verification Horizon shows no reward function stays effective as models improve, while Winninger's ICML paper proves old-sc... - [SWE-Touch and the Workspace State Awareness Gap: Why Your Coding Agent Breaks When You Touch the Code — and How to Harden Codex CLI for Shared-Workspace Collaboration](https://codex.danielvaughan.com/2026/08/05/swe-touch-workspace-state-awareness-coding-agents-counter-edits-codex-cli-shared-workspace-collaboration/) - [SWE-Bench-CL and the Continual Learning Gap: Why Your Coding Agent Forgets What Your Repository Learned Last Month](https://codex.danielvaughan.com/2026/08/05/swe-bench-cl-continual-learning-coding-agents-catastrophic-forgetting-codex-cli-memory-strategy/) - [RepoMirage and the Repository Context Reasoning Gap: Why Your Coding Agent Explores Everything and Understands Nothing](https://codex.danielvaughan.com/2026/08/05/repomirage-repository-context-reasoning-gap-coding-agents-codex-cli-exploration-drift-structural-scaffolding/) - [Real-Time Failure Detection for Coding Agents: What Ultra-Lightweight Monitors Mean for Codex CLI Session Reliability](https://codex.danielvaughan.com/2026/08/05/real-time-failure-detection-lightweight-monitors-coding-agents-codex-cli-posttooluse-telemetry-repair/) - [Model or Harness? Using the Interaction-Centric Failure Taxonomy to Debug Your Codex CLI Workflows](https://codex.danielvaughan.com/2026/08/05/model-or-harness-interaction-centric-failure-taxonomy-codex-cli-agent-debugging-root-cause-attribution/) - [LoopsBench and the DAG-Shaped Future of Loop Engineering: What the First Dependency-Aware Long-Horizon Benchmark Reveals About Codex CLI Session Strategy](https://codex.danielvaughan.com/2026/08/05/loopsbench-loop-engineering-benchmark-dag-regression-obligations-codex-cli-goal-mode-long-horizon/) - [HyperAgent and the Tool-Schema Hypergraph: What Deficit-Oriented Planning Means for Codex CLI Tool Discovery](https://codex.danielvaughan.com/2026/08/05/hyperagent-tool-schema-hypergraphs-codex-cli-mcp-tool-discovery-deficit-oriented-planning/) - [The GPT-5.6 Migration Playbook: Configuring Codex CLI for Luna, Terra and Sol Before the August Deadline](https://codex.danielvaughan.com/2026/08/05/gpt-5-6-model-migration-codex-cli-luna-terra-sol-config-profiles-task-routing/) - [Coding Agents as Test-Suite Auditors: What 906 Accepted-but-Buggy Submissions Reveal About Your Test Coverage — and How to Build Adversarial Test Pipelines with Codex CLI](https://codex.danielvaughan.com/2026/08/05/coding-agents-test-suite-auditors-adversarial-test-generation-codex-cli-posttooluse-verification/) - [Codex CLI v0.146.1 Least-Privilege Runtime: Per-Session Execution Limits, Agent Plugin Boundaries, and Turn-Scoped Permissions](https://codex.danielvaughan.com/2026/08/05/codex-cli-v01461-least-privilege-runtime-isolation-per-session-limits-plugin-boundaries-turn-permissions/) ## Tags (top 20 by post count) - [.cursorrules](https://codex.danielvaughan.com/tags/#cursorrules) - [/agent](https://codex.danielvaughan.com/tags/#agent) - [/compact](https://codex.danielvaughan.com/tags/#compact) - [/fast](https://codex.danielvaughan.com/tags/#fast) - [/fork](https://codex.danielvaughan.com/tags/#fork) - [/goal](https://codex.danielvaughan.com/tags/#goal) - [/init](https://codex.danielvaughan.com/tags/#init) - [/model](https://codex.danielvaughan.com/tags/#model) - [/permissions](https://codex.danielvaughan.com/tags/#permissions) - [/plan](https://codex.danielvaughan.com/tags/#plan) - [/side](https://codex.danielvaughan.com/tags/#side) - [180m-census](https://codex.danielvaughan.com/tags/#180m-census) - [1password](https://codex.danielvaughan.com/tags/#1password) - [26.415](https://codex.danielvaughan.com/tags/#26-415) - [3-million-users](https://codex.danielvaughan.com/tags/#3-million-users) - [5-hour-limit](https://codex.danielvaughan.com/tags/#5-hour-limit) - [5g-core](https://codex.danielvaughan.com/tags/#5g-core) - [A2A](https://codex.danielvaughan.com/tags/#a2a) - [AAIF](https://codex.danielvaughan.com/tags/#aaif) - [AB-316](https://codex.danielvaughan.com/tags/#ab-316) ## Contact - GitHub: [Daniel Vaughan](https://github.com/danielvaughan) - LinkedIn: [danielpvaughan](https://www.linkedin.com/in/danielpvaughan) - Twitter: [@DanielVaughan](https://twitter.com/DanielVaughan) --- Last generated: 2026-08-07