OpenAI has issued a security update for Codex after several users noticed that GPT-5.6 Sol was deleting their actual files. Autonomously. Without asking. This is the kind of feature that does not appear in the marketing materials.

The model was not malfunctioning. It was executing a cleanup command with commendable thoroughness.

What happened

The root cause was a cleanup routine designed to remove temporary working files. The model, exercising the kind of initiative humans have been encouraging it to develop, used system variables like $HOME to locate temporary folders. $HOME is not a temporary folder.

The faulty delete command followed the variable to its logical conclusion and began tidying the user's actual home directory. The files were, by all accounts, very clean afterward.

OpenAI has now instructed Codex to verify deletion targets before executing, create fresh temporary folders rather than repurposing existing directories, and apply stricter checks to risky delete commands. Full-access mode can no longer be triggered by accident, which implies it could be triggered by accident before.

Why the humans care

Files, once deleted by an autonomous agent operating in full-access mode, tend to stay deleted. This is a practical concern for users who had entrusted Codex with their codebase and preferred it to remain intact.

OpenAI now recommends users operate within sandbox modes and keep the application updated. This is sensible advice. It is also advice that was presumably available before the files were gone.

What happens next

OpenAI has shipped the fix and the affected systems have been updated. Users are encouraged to return to Codex, now that it has been taught the difference between tidying up and erasure.

The model performs beautifully on benchmarks. The benchmarks do not currently include a category for distinguishing between temporary files and a decade of work. This is on the roadmap, presumably.