Codex Security CLI
Codex Security is a thin CLI and SDK wrapper around Codex and its security
plugin. Use their existing behavior instead of building another runtime.
## Threat model
controls may ship without a corresponding tool, especially for secret input until a secure tool-driven input flow exists. Do not add a tool when the agent can already
prefix, prefix cache, the
four bounds on context growth), and
[`docs/security-model.md`](docs/security-model.md) (per-layer security). Don't duplicate
those here — link to them.
## What this recipe teaches
Horizon leans
rethink the design); and prefer reusing existing mechanisms over adding parallel ones. Capability-based security note: a resource becomes "ambient" (auto-injected) only by user/admin configuration — a gatekeeper must never
block already says.
Comments are appropriate for gotchas, non-obvious invariants, external constraints, security or
performance reasoning, and deliberate departures from a convention. Explain why the surprising
choice is necessary