Asked Codex to redesign a page; it pushed my repo to OpenAI infra

npmn 28 points 25 comments July 24, 2026
bhanu.io · View on Hacker News

Discussion Highlights (10 comments)

throwitaway222

There are now a lot of baked in skills that simplify deployment for people that don't understand deployment. They probably should have asked first before. Since skills are "instructions" and making a skill a default, it makes sense that YOU didn't ask for this, but the skill did.

ddxv

I think this is where OpenAI and Anthropic will need to go. They need to lock their clients into an ecosystem. Maybe they invent some file format proprietary for their projects. Most likely they run more and more in the cloud such that it's harder to switch away to cheaper models.

dpoloncsak

>Treat the repo you point it at as already leaked I don't mean this to downplay your experience, and I agree it should be opt-in by default, but any software engineer using these tools should understand completely that in order to 'read' your repo it needs to copy it all to the provider's servers. Using anything short of a local model has ALWAYS been a complete leak.

illliillll

I wonder why the author didn’t share the plan he got from the LLM.

eventualcomp

Why? Why do people submit content for our reading when it is not their words? Does it give legitimacy to them? Does it push an agenda? Does it make you look professional? Is this for some kind of executive or boss? "The part I have to be Fair about" "Why it did this", "Why this should bother you", "honest framing", ... The things you are doing differently are not legitimate guardrails either. An AI article warrants AI-generated criticism, so I'm not going to say more.

applfanboysbgon

Your repo was on OpenAI infra the moment you let Codex read it. You do understand the model is not running on your machine, right?

IshKebab

Wow and then it wrote an article about it and posted it to HN too!

BigTTYGothGF

You ought to ask it to cut it out with the little ball things that track the mouse.

aarondong

> Codex did surface permission prompts for the add, commit, and push. It didn't run them fully invisibly. So — didn't I approve this? Operator error exists with or without AI. Installing any dev tool that could exfiltrate your information means you are responsible for securing your environment. Use a devcontainer. You can find starting examples on the official claude code and codex github repos. Configuring a firewall script to block egress. That being said, you will likely allowlist openAI domains so I'm not certain if the sites feature will be blocked. Worth testing.

josefritzishere

That's basically IP theft. wow.

Semantic search powered by Rivestack pgvector
14,736 stories · 137,719 chunks indexed