Files
msd-core/.changeset/1115-review-codex-flag-capability-probe.md
Tom Boucher fc37ae0c4f fix(#1115): capability-probe codex hook-trust bypass flag in /gsd:review; fail loud on empty output (#1122)
On codex-cli < 0.137.0 the review.md `codex exec` invocation passed
--dangerously-bypass-hook-trust (added in 0.137) unconditionally and discarded
stderr, so codex exited "unexpected argument" before reading the prompt and the
empty output file was treated as a completed review — a silent degraded review.

- Capability-probe the flag (`codex exec --help | grep`) and apply it via
  $CODEX_BYPASS_FLAG only when supported (works fine without it on older CLIs).
- Capture codex stderr to a .err file instead of /dev/null, and replace an empty
  output with a diagnostic so a broken reviewer is surfaced (mirrors Cursor/OpenCode).
- Update enh-773 enforcement test to require the capability gate + fail-loud guard
  instead of the unconditional flag.

Closes #1115

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-12 15:55:17 -04:00

704 B

type, pr
type pr
Fixed 1122

/gsd:review no longer produces a silent empty Codex review on codex-cli < 0.137 — the codex exec invocation passed --dangerously-bypass-hook-trust (added in codex 0.137.0) unconditionally and discarded stderr, so on older CLIs codex exited with unexpected argument before reading the prompt and the empty output was treated as a completed review. The flag is now capability-probed (codex exec --help | grep) and applied via $CODEX_BYPASS_FLAG only when supported, codex stderr is captured to a .err file instead of /dev/null, and an empty Codex output is replaced with a diagnostic so a broken reviewer is surfaced rather than silently skipped. (#1115)