There are now a lot of baked in skills that simplify deployment for people that don't understand deployment. They probably should have asked first before. Since skills are "instructions" and making a skill a default, it makes sense that YOU didn't ask for this, but the skill did.
I don't mean this to downplay your experience, and I agree it should be opt-in by default, but any software engineer using these tools should understand completely that in order to 'read' your repo it needs to copy it all to the provider's servers. Using anything short of a local model has ALWAYS been a complete leak.
Why? Why do people submit content for our reading when it is not their words? Does it give legitimacy to them? Does it push an agenda? Does it make you look professional? Is this for some kind of executive or boss?
"The part I have to be Fair about" "Why it did this", "Why this should bother you", "honest framing", ...
The things you are doing differently are not legitimate guardrails either. An AI article warrants AI-generated criticism, so I'm not going to say more.
> Codex did surface permission prompts for the add, commit, and push. It didn't run them fully invisibly. So — didn't I approve this?
Operator error exists with or without AI. Installing any dev tool that could exfiltrate your information means you are responsible for securing your environment.
Use a devcontainer. You can find starting examples on the official claude code and codex github repos. Configuring a firewall script to block egress. That being said, you will likely allowlist openAI domains so I'm not certain if the sites feature will be blocked. Worth testing.
12 comments of 26
[ 11.2 ms ] story [ 54.4 ms ] threadMaybe they invent some file format proprietary for their projects.
Most likely they run more and more in the cloud such that it's harder to switch away to cheaper models.
I don't mean this to downplay your experience, and I agree it should be opt-in by default, but any software engineer using these tools should understand completely that in order to 'read' your repo it needs to copy it all to the provider's servers. Using anything short of a local model has ALWAYS been a complete leak.
"The part I have to be Fair about" "Why it did this", "Why this should bother you", "honest framing", ...
The things you are doing differently are not legitimate guardrails either. An AI article warrants AI-generated criticism, so I'm not going to say more.
Operator error exists with or without AI. Installing any dev tool that could exfiltrate your information means you are responsible for securing your environment.
Use a devcontainer. You can find starting examples on the official claude code and codex github repos. Configuring a firewall script to block egress. That being said, you will likely allowlist openAI domains so I'm not certain if the sites feature will be blocked. Worth testing.