
Codex CLI Gets Live Hot-Reloading and Safer Workspace Trust
This episode breaks down recent Codex CLI updates, including live plugin hot-reloading for running sessions, improved workspace trust safety, and a critical fix that prevents untrusted repos from executing PATH helper binaries. It also covers the removal of the deprecated mcp-server entry point, targeted /copy improvements for cleaner debugging, and clearer sandbox policy reporting in codex doctor.
Chapter 1
Live Plugin Hot-Reloading and Workspace Trust Safety
Ethan Park
If you leave a Codex session running in the background for a long task, you used to hit this frustrating wall. You update a plugin in another window, but your running agent has no idea. Thanks to Jellypod, we can dive straight into how Codex CLI zero point one hundred fifty four point zero fixes that disconnect once and for all.
Maya
Wait, so it was just stuck with whatever tools it had when you first launched it?
Ethan Park
Exactly. If you upgraded a custom team tool mid-task, the session was completely desynced. To get the new functionality, you had to kill the process, drop your active context, and start over from scratch.
Maya
That sounds like a fast way to lose half an hour of context.
Ethan Park
Right, but now active sessions listen for app installed event triggers. When an external update or rollback happens, Codex dynamically re-indexes your skills, re-binds command hooks, and pulls in the new tools automatically. Pull requests four two two eight four and four two five nine three make sure it happens quietly without touching your running worktree.
Maya
Okay, let me make sure I've got the practical picture right. Say I have an agent working through a multi-step refactor in one tab, and I push a fix to our internal deployment plugin in another terminal. The agent just... picks up the new command immediately? No restart, no lost chat history?
Ethan Park
That is it, zero interruption. And speaking of startup, there is also a critical security fix in zero point one hundred fifty four point zero. Pull request four two three two four stops Codex from executing workspace-controlled PATH helper binaries during startup until you explicitly trust the repository.
Maya
Wait, so before this, just opening an untrusted repo could run arbitrary binaries hidden in PATH?
Ethan Park
It was a real edge case for workspace security. Now it halts execution until you give explicit authorization, keeping untrusted repos completely isolated.
Chapter 2
Command Deprecations and Targeted Status Copying
Ethan Park
Now, if you maintain CI scripts or local wrapper scripts around Codex, there is a hard breaking change you need to look out for. Pull request four two nine nine three completely removes the deprecated codex mcp-server entry point.
Maya
It's just gone? What happens if an automated pipeline still calls it?
Ethan Park
It fails immediately. Automated workflows need to switch over to standard daemon invocation or use the app installed events right away.
Maya
Okay, good to know. But on the developer experience side, there are some really neat terminal updates, right?
Ethan Park
Yeah, the slash copy command got a great upgrade in pull request four three zero five five. Instead of dumping the entire transcript into your clipboard just to pull one value, you can target specific diagnostic metadata using slash copy status or individual output fields.
Maya
Oh, I love that. When you're filing a bug with your platform team, you do not want to wade through thousands of lines of code output just to get a session ID or status code.
Ethan Park
Totally. And to pair with that, pull request four two eight two one adds explicit reporting for managed filesystem sandbox policies right inside codex doctor, so you can see your boundary enforcement rules at a glance.
Maya
So between targeted copying and clearer doctor reports, tracking down session issues should be way less painful.
Ethan Park
Definitely. Just make sure to audit those unpinned CI scripts before upgrading, and you are good to go.