{"slug": "codex-cli-0-147-test-agent-plugins-approvals-and-mcp-separately", "title": "Codex CLI 0.147: Test Agent Plugins, Approvals, and MCP Separately", "summary": "OpenAI's Codex CLI 0.147 introduces test agent plugins, approvals, and MCP support, but developers are advised to test each trust boundary independently rather than treating the upgrade as a single pass/fail event. The release removes the deprecated 'codex exec --full-auto' shortcut and adds opt-in MCP 2026-07-28 support, while the accompanying analysis emphasizes verifying plugin provenance, approval scope, and process cleanup separately.", "body_md": "Codex CLI 0.147 combines several changes that affect different trust boundaries. Treating the upgrade as one pass/fail event misses the failures that matter.\n\nTest five things independently:\n\n`--approve-for-me`\n\nboundary.A successful launch proves only that Codex started. It does not prove that plugin provenance, approval scope, protocol negotiation, imported context, or process cleanup are correct.\n\nPortable plugins can move instructions, tools, apps, and supporting files between environments. Before activation, record:\n\nThen disable the plugin and start a fresh session. The capability should disappear. Catalog visibility is not execution proof.\n\n`--approve-for-me`\n\nis not unrestricted execution\nThe flag adds automatic approval review. It does not erase the sandbox, network policy, managed restrictions, or the need to verify side effects.\n\nUse a disposable workspace and check:\n\nCodex 0.147 also removes the deprecated `codex exec --full-auto`\n\nshortcut. Unattended workflows should declare sandbox and approval behavior explicitly.\n\nOpt-in MCP 2026-07-28 support adds capabilities such as paginated discovery and multi-round requests. A connected server can still fail during tool discovery, schema validation, one invocation, or response handling.\n\nRecord the negotiated protocol version, enumerate tools, call one bounded tool, and verify the artifact outside Codex.\n\nCursor-managed skills and imported Claude or Cursor conversations increase reusable context. They also increase the chance of stale instructions, duplicate guidance, and hidden conflicts.\n\nPin the source, inspect references, run a known-answer task, and confirm which instruction won when scopes conflict.\n\nThe release includes Windows process and path fixes. Verify them by starting a harmless bounded background task, interrupting it, and checking both the process tree and expected artifact state. A quiet terminal is not proof that the child process stopped.\n\nUpgrade only when every boundary has its own evidence receipt. If one check fails, roll back or disable only that capability instead of deleting unrelated configuration.\n\nOfficial release:\n\n[https://github.com/openai/codex/releases/tag/rust-v0.147.0](https://github.com/openai/codex/releases/tag/rust-v0.147.0)\n\nComplete source-linked analysis and acceptance checklist:\n\n[https://tgwise.com/intelligence/codex-cli-0-147-agent-plugins-approve-for-me-mcp/](https://tgwise.com/intelligence/codex-cli-0-147-agent-plugins-approve-for-me-mcp/)", "url": "https://wpnews.pro/news/codex-cli-0-147-test-agent-plugins-approvals-and-mcp-separately", "canonical_source": "https://dev.to/yan_gao_3ad90a90b26925538/codex-cli-0147-test-agent-plugins-approvals-and-mcp-separately-6h4", "published_at": "2026-08-15 18:42:09+00:00", "updated_at": "2026-08-15 19:11:57.122577+00:00", "lang": "en", "topics": ["developer-tools", "ai-agents", "ai-tools", "ai-infrastructure"], "entities": ["OpenAI", "Codex CLI", "MCP"], "alternates": {"html": "https://wpnews.pro/news/codex-cli-0-147-test-agent-plugins-approvals-and-mcp-separately", "markdown": "https://wpnews.pro/news/codex-cli-0-147-test-agent-plugins-approvals-and-mcp-separately.md", "text": "https://wpnews.pro/news/codex-cli-0-147-test-agent-plugins-approvals-and-mcp-separately.txt", "jsonld": "https://wpnews.pro/news/codex-cli-0-147-test-agent-plugins-approvals-and-mcp-separately.jsonld"}}