Key Guardian history to the effective REPL policy
Use
when:
Codex
Auto-review
may
approve
node_repl
or
cua_repl
actions,
especially
with
a
custom
model_catalog_json,
JavaScript
can
nest
browser,
computer-use,
and
MCP
effects,
so
generic
tool-call
review
is
insufficient.
0.152.1
or
later.
For
every
custom
Guardian
reviewer
model,
set
a
non-empty
model_messages.auto_review.node_repl_policy
containing
the
complete
nested-effect
review
policy.
Omit
the
field
only
to
accept
Codex’s
bundled
fallback;
an
explicit
empty
string
disables
injection.
Bind
the
resolved
policy
text
into
the
review-session
reuse
key.
Acceptance check: create catalog variants A and B with unique policy sentinels. Trigger two approval-required REPL calls under A: the first Guardian developer input contains A exactly once, and the second may reuse that reviewer thread. Switch to B; the next review must use a new thread, contain B, and omit A.
0.152.1
contains
only
this
behavioral
repair.
Merged
PR
#41919
adds
the
catalog
field,
bundled
fallback,
explicit-empty
semantics,
policy-aware
reuse,
and
tests
for
Node/CUA,
cache
invalidation,
and
unsafe
fallback
rejection.
Caveat: this is a review-prompt identity fix, not a security proof. Auto-review remains probabilistic; keep the OS sandbox, network policy, MCP approval modes, and effect-level canaries independent.