Repository navigation
[extension] Codex Migrate command protection #2878
Description
Activity
Contribution type
New Extension
Proposed Extension ID
command.codex-migrateCapability boundary
Protect the Codex Migrate CLI's destination-changing migration operations. The extension owns the
codex-migrateexecutable and itsinspect,export,serve, andrecovery--applyforms. Read-only inventory, inspection, recovery inspection, read-only dashboards, version, and help remain non-reviewable. It does not attempt to inspect HTTP actions taken later inside the local browser UI, nor does it weaken filesystem, SSH, or other matching Guard rules.Command surface
Executable:
codex-migrate(Mac beta/CLI 1.x). Supported subcommands:launch,inventory,inspect,export,serve, andrecovery. Mutating authority is explicit oninspect,export,serve, andrecoverythrough--apply;launchstarts the local guided browser UI without itself applying a transfer.Destructive or sensitive examples
codex-migrate inspect --target user@new-mac.local --target-home /Users/user --applycodex-migrate export --target user@new-mac.local --target-home /Users/user --component personal-skills --applycodex-migrate serve --target user@new-mac.local --target-home /Users/user --applycodex-migrate recovery --target user@new-mac.local --target-home /Users/user --apply
These forms can stage, install, replace, or recover selected destination state after the tool's own verification gates.
Safe counterparts
codex-migrate inventory --jsoncodex-migrate inspect --target user@new-mac.local --target-home /Users/user --jsoncodex-migrate export --target user@new-mac.local --target-home /Users/user --component personal-skills --jsoncodex-migrate serve --target user@new-mac.local --target-home /Users/user --no-opencodex-migrate recovery --target user@new-mac.local --target-home /Users/user --jsoncodex-migrate --help,codex-migrate --version, and subcommand help
Parser and composition edge cases
Tests will cover reordered
--apply, quoted target/home values, paths with spaces, compound commands, wrappers,--help, trailing commands, duplicate flags, unresolved expansions, and malformed or unsupported subcommands. Unknown or expansion-provided arguments must not imply safety.Risk and authority model
Proposed action class:
Codex Migrate destination-changing operation. Risk classes:destructive_shell,execution, andnetwork_egress; severity high; default mode review. Safer alternative: run the same subcommand without--apply, inspect the plan and verified destination backup, then repeat with--applyonly when ready. The extension emits evidence only and remains external/opt-in, so required core and overlapping rules retain their floors.Privacy and performance
The matcher is bounded to the canonical executable and explicit subcommand/flag structure. Evidence stores stable IDs and generic details, not targets, usernames, paths, SSH identity files, workspace names, or command text. Read-only invocations are the benign hot path and should exit after bounded token inspection.
Authoritative references
Readiness
- I searched the Extension directory and existing issues for overlapping coverage.
- I removed secrets, credentials, private command history, and local paths from these examples.
- I can contribute or help validate destructive and safe-counterpart tests.
This seems like a great candidate. Looking forward to the PR!
Contribution type
New Extension
Proposed Extension ID
command.codex-migrateCapability boundary
Protect the Codex Migrate CLI's destination-changing migration operations. The extension owns the
codex-migrateexecutable and reviews the two shell surfaces that can actually change destination state:export --applyandserve --apply. The latter enables staged transfer, finalization, and verified recovery controls in the local browser. Inventory, inspection, recovery inspection, read-only dashboards, version, and help remain non-reviewable. It does not attempt to inspect HTTP actions taken later inside the local browser UI, nor does it weaken filesystem, SSH, or other matching Guard rules.Command surface
Executable:
codex-migrate(Mac beta/CLI 1.x). Supported subcommands:launch,inventory,inspect,export,serve, andrecovery.export --applyinstalls selected repair components;serve --applyenables transfer, finalization, and verified recovery controls.inspectis read-only even if--applyis supplied, whilerecovery --applyis rejected by the CLI.launchstarts the local guided browser UI without itself applying a transfer.Destructive or sensitive examples
codex-migrate export --target user@new-mac.local --target-home /Users/user --component personal-skills --applycodex-migrate serve --target user@new-mac.local --target-home /Users/user --applyThese forms can install selected components or enable staged migration and recovery changes after the tool's own verification gates.
Safe counterparts
codex-migrate inventory --jsoncodex-migrate inspect --target user@new-mac.local --target-home /Users/user --jsoncodex-migrate inspect --target user@new-mac.local --target-home /Users/user --apply(still read-only)codex-migrate export --target user@new-mac.local --target-home /Users/user --component personal-skills --jsoncodex-migrate serve --target user@new-mac.local --target-home /Users/user --no-opencodex-migrate recovery --target user@new-mac.local --target-home /Users/user --jsoncodex-migrate --help,codex-migrate --version, and subcommand helpParser and composition edge cases
Tests cover reordered and abbreviated
--apply, quoted target/home values, paths with spaces, compound commands,execandxargswrappers, help overrides, trailing commands, unresolved expansions in flag position, expansions consumed as known option values, and quoted examples. Unknown or expansion-provided flag arguments must not imply safety.Risk and authority model
Proposed action class:
Codex Migrate destination-changing operation. Risk classes:destructive_shell,execution, andnetwork_egress; severity high; default mode review. Safer alternative: run the same subcommand without--apply, inspect the plan and verified destination backup, then repeat with--applyonly when ready. The extension emits evidence only and remains external/opt-in, so required core and overlapping rules retain their floors.Privacy and performance
The matcher is bounded to the canonical executable and explicit subcommand/flag structure. Evidence stores stable IDs and generic details, not targets, usernames, paths, SSH identity files, workspace names, or command text. Read-only invocations are the benign hot path and should exit after bounded token inspection.
Authoritative references
Readiness