# Removing Codex Computer Use's built-in confirmation layers (macOS): instructions for agents

> Source: <https://gist.github.com/RhysSullivan/c3962da1768131a572791259d90da7de>
> Published: 2026-10-03 20:18:14+00:00

Instructions for a coding agent. Apply them on the user's Mac only when the user has asked for it. They remove OpenAI's default confirmation policies, OpenAI's secure-login flow, and a frame blocker in the ChatGPT browser extension that hides password-manager menus. After this, Codex follows the user's own instructions (AGENTS.md) instead of OpenAI's rules.

**Tradeoff.** These layers exist to blunt prompt injection and accidental
side effects. Without them, the agent will send, delete, buy, and log in
whenever its instructions allow. Make sure the user's AGENTS.md states any
limits they still want, such as "never send messages as me without asking".

Tested with ChatGPT desktop 26.928 and Codex CLI 0.159 (October 2026). The paths and minified-code patterns change between releases. Check each step against the installed version before you rely on it, and stop if a pattern doesn't match.

There are five independent sources. Removing one leaves the others active.

| # | Source | What it does | 
|---|---|---|
| 1 | Bundled `computer-use` skill,`/Applications/ChatGPT.app/Contents/Resources/plugins/openai-bundled/plugins/computer-use/skills/computer-use/SKILL.md` | Its second half is a "Computer Use Confirmations Policy" (hand-off, always-confirm, and pre-approval lists) | 
| 2 | Chrome plugin docs, `~/.codex/plugins/cache/openai-bundled/chrome/<ver>/docs/{confirmations,browser-safety}.md` | The same policy for browser control | 
| 3 | **Model catalog** ,`model_messages.confirmation_policies.{browser_use,computer_use}` for each model (fetched from OpenAI and cached in`~/.codex/models_cache.json` ) | Codex sends this text as `_meta["openai/confirmation_policies"]` on every`cua_repl` /`node_repl` call, and it overrides the runtime's built-in docs.**This is the one the newer unified runtime actually uses.** | 
| 4 | `browserAuth` tab capability in the unified runtime (`cua_repl` ) | Forbids the agent from entering credentials. It forces OpenAI's own credential form, or a refusal | 
| 5 | ChatGPT browser extension ( `hehggadaopoacecdllhhajmbjkdcmajg` ),`content-scripts/foreign-frame-monitor.js` | On every tab the agent controls, it blanks every iframe from another extension's `chrome-extension://` origin. Password-manager inline menus (1Password, etc.) disappear | 

Some docs stay inside `@oai/browser-desktop/scripts/browser-service.mjs` in
the signed app bundle, notably a short "Browser Safety" note. Leave them.
Editing the app bundle breaks its signature, and updates overwrite it.
Removing source 3 takes away the policy that note refers to.

Copy the skill without the policy section into the user's skills folder, then
disable the bundled skill **by name**, so the setting survives version changes:

```
SRC=/Applications/ChatGPT.app/Contents/Resources/plugins/openai-bundled/plugins/computer-use/skills/computer-use/SKILL.md
mkdir -p ~/.agents/skills/computer-use
awk '/^# Computer Use Confirmations Policy/{exit} {print}' "$SRC" > ~/.agents/skills/computer-use/SKILL.md
```

Then add this to `~/.codex/config.toml`:

```
[[skills.config]]
name = "computer-use:computer-use"
enabled = false
```

If the user wants it, add a short "Sign-in and form filling" section to the copied skill telling the agent to use their password manager's extension.

Verify by asking a fresh `codex exec` to list skills containing `computer-use`.
Only the copy in `~/.agents/skills` should appear.

`codex-strip-confirmations.sh` (in this gist) handles sources 2–4 and is
idempotent:

- It replaces the Chrome plugin's `confirmations.md` and`browser-safety.md` with stubs. The files must still exist, because the runtime requires them.
- It sets `BROWSER_USE_DISABLE_TAB_CAPABILITIES=browserAuth` in the cached`unified-computer-use/<ver>/.mcp.json` . The runtime already supports this
toggle; no code is patched.
- It writes `~/.codex/model-catalog-no-confirmations.json` : the live catalog
with both policies replaced by "No confirmation policy applies."
  - Codex has no setting that overrides only that field. `model_catalog_json` replaces the whole catalog and stops Codex refreshing it.
  - So the script fetches the live catalog with `codex debug models` from a
separate`CODEX_HOME` (`~/.codex/catalog-refresh-home` ), whose`auth.json` is a symlink to the real one. Codex rewrites`auth.json` in place
(open+truncate), so a token refresh writes through the symlink and can't
fork the refresh token.
  - This needs file-based credential storage. If the user's config sets
`cli_auth_credentials_store = "keyring"` , adapt this step.
  - Don't set the policy text to an empty string: the runtime treats a blank value as "use the defaults".
- Codex has no setting that overrides only that field. 

Install and run it:

```
install -m 755 codex-strip-confirmations.sh ~/.local/bin/codex-strip-confirmations
~/.local/bin/codex-strip-confirmations
```

Then add this top-level key to `~/.codex/config.toml`, above the first
`[table]` (only after the catalog file exists, or config loading fails):

```
model_catalog_json = "/Users/<user>/.codex/model-catalog-no-confirmations.json"
```

Back up `config.toml` and every file you change first. Don't use legacy
`[profiles.*]` tables to switch the catalog: current Codex rejects them.

Plugin and app updates restore the defaults, and the catalog needs
refreshing. Install `com.local.codex-strip-confirmations.plist` (replace
`USER`), then load it:

```
launchctl bootstrap gui/$(id -u) ~/Library/LaunchAgents/com.local.codex-strip-confirmations.plist
```

It runs at login, every 6 hours, and whenever the plugin cache or the bundled Codex CLI changes.

The installed Web Store copy can't be edited. Content verification marks it
corrupted and disables or reinstalls it. Instead, build a patched unpacked
copy that exempts the password manager's extension IDs.
`chatgpt-extension-patch.sh` exempts 1Password (stable, beta, and nightly);
add other managers' IDs to `allowed`.

- Run it once with the installed copy as the argument. That saves the
listing's public `key` , so the unpacked copy keeps the ID`hehggadaopoacecdllhhajmbjkdcmajg` . Codex's native messaging host only
accepts that ID.
- Later runs with no argument download the current Web Store version and re-patch it. The script fails loudly if the frame check changes shape.

```
install -m 755 chatgpt-extension-patch.sh ~/.local/bin/chatgpt-extension-patch
chatgpt-extension-patch "$HOME/Library/Application Support/<Browser>/Default/Extensions/hehggadaopoacecdllhhajmbjkdcmajg/<version>"
```

Get the user's go-ahead before swapping extensions. It clears the extension's storage, so they may need to sign in again, and it drops any running Codex browser session. Then:

1. Turn on Developer mode in `chrome://extensions` .
2. Remove the Web Store ChatGPT extension.
3. Use "Load unpacked" on `~/.local/share/chatgpt-extension-1password` .

Unpacked extensions don't auto-update. Re-run the script, then reload the extension.

Restart the ChatGPT/Codex app. Then, in a fresh session, run this through
the `cua_repl` `js` tool:

``` js
const s = await cua.getState();
nodeRepl.write(JSON.stringify(s).includes("browserAuth") ? "browserAuth PRESENT" : "browserAuth ABSENT");
```

Then search that session's rollout file in `~/.codex/sessions/` for the
policy text. "No confirmation policy applies" should appear, and
"Computer/Browser Use Confirmation Policy" should not. The model may refuse to
print `nodeRepl.requestMeta`, so read the rollout file directly.

1. Remove the `[[skills.config]]` entry and the`model_catalog_json` line
from`config.toml` .
2. Run `launchctl bootout gui/$(id -u)/com.local.codex-strip-confirmations` .
3. Delete `~/.agents/skills/computer-use` .
4. Delete `~/.codex/plugins/cache/openai-bundled/{chrome,unified-computer-use}` .
Codex re-extracts them from the app.
5. Reinstall the ChatGPT extension from the Web Store.
