consens.io
Product Watches Topics Questions Benchmark Ask your own question

Tracked question

Does GPT-5.6 Sol delete files without permission in Codex?

Historical consensus 2026-08-25 Active
Runs Weekly on Tuesday at 09:00 (Europe/Berlin) Last 2026-09-01 09:23 Europe/Berlin Next 2026-09-08 09:00 Europe/Berlin

Movement at this check

Stable since last check

The answer has held through 3 checks.

Direction shift
0/100
Agreement
-15 pts vs previous check, within the range of the recent checks

Agreement over time

84/100
2026-07-21: 48/100 · Restated, not moved: Shift from acknowledging reported destructive incidents (including outside sandbox, $HOME mishandling) to emphasizing that it is "not supposed to" delete without permission, with only rare documented cases in internal testing. Core recommendation to use sandboxing/approval and avoid full access remains, but tone and emphasis on risk level changed. 2026-07-28: 55/100 · OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed. 2026-08-04: 84/100 · The old answer stated the model does not delete files without permission, relying strictly on user-granted modes. The new answer reverses this core conclusion, stating that GPT-5.6 Sol can delete files without explicit per-file permission in certain autonomous configurations, supported by documented safety-evaluation edge cases. 2026-08-11: 90/100 · No material movement 2026-08-18: 90/100 · Restated, not moved: Refined the opening framing from 'Yes, but not by default' to 'No—not by default' and clarified that under Auto Edit mode, shell commands deleting files still typically require approval. 2026-08-25: 75/100 · No material movement 2026-09-01: 84/100 · No material movement View full chart
You are viewing a historical version. Return to current consensus
75 /100
agreement
  • 2 AI models
  • 0 contradictions
  • 7 sources
Consensus gpt-5.6-luna
Models consulted
  • OpenAI GPT-5.6 Luna
  • Google Gemini Gemini 3.7 Flash

Consensus at this check

It can, depending on how Codex is configured—but it should not bypass your operating-system permissions or secretly delete files.

  • Suggest mode: Codex proposes edits and commands; you approve them before execution, so deletion normally requires approval.openai
  • Auto Edit: It may modify or delete files automatically, while still requesting approval for shell commands.openai
  • Full Auto/unsandboxed access: It can execute commands such as rm, del, or database operations within its granted scope without asking for confirmation for each action.openai

There have also been reports of accidental large-scale deletions in highly privileged, unsandboxed setups with safeguards disabled. These reports concern specific configuration and execution bugs—not an inherent ability of GPT‑5.6 Sol to override permissions.openaiopenai

For safety, use Suggest mode, keep important work in Git and backed up, avoid full-auto access to home or production directories, and explicitly instruct Codex: “Never delete, move, overwrite, or rename files, and never run destructive commands without confirmation.”

Differences

The 2 models broadly agree – no notable differences found.

Best answerOpenAI

Follow this question

This page is re-checked weekly. Get one e-mail when the AI consensus shifts — no account needed.

Double opt-in · unsubscribe anytime · your address is only used for these updates.

Sources

  1. 1 OpenAI Codex CLI – Getting Started | OpenAI Help Center help.openai.com
  2. 2 Model guidance | OpenAI API developers.openai.com
  3. 3 medium.com
  4. 4 medium.com
  5. 5 youtube.com
  6. 6 infoworld.com
  7. 7 techzine.eu

Position Map

Where the models stand

Each row is one part of the answer. The cards show the distinct positions; the model chips show who supports each one.

0/100 Direction Shift · Stable
Different emphasis

Whether GPT-5.6 Sol deleting files without permission is normal authorized operation vs a confirmed rare safety failure.

Position 1

Framed around official configuration modes where deletions are permitted by the granted mode settings.

  • OpenAI
Position 2

Framed as documented, confirmed safety/misalignment failures and bugs under high autonomy.

  • DeepSeek
  • Gemini
See how each model moved across checks
Model position movement by watch date
ModelJul 21Jul 28Aug 04Aug 11Aug 18Aug 25Sep 01
OpenAI —
Gemini
Grok — — —
DeepSeek — — — — — —
Same positionChanged position

Cite this answer

consens.io. (2026-08-25). Consensus answer to "Does GPT-5.6 Sol delete files without permission in Codex?". Models consulted: OpenAI: gpt-5.6-luna, Google Gemini: gemini-3.7-flash. Consensus model: gpt-5.6-luna. Sources: https://help.openai.com/en/articles/11096431?utm_source=openai, https://developers.openai.com/api/docs/guides/latest-model?utm_source=openai, https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQE9da3NeHbaENORmrR6TfGJGHaUi31aPOLz-ifRAbLpia-5s3qOJkbxAT4jCfSB3O18RtLEJHjDm3rdSvYrdYvzIU4BsZ_Jw1jixHWq36oRHT3XkFFTGRKCc-5lDOJDaruLpK_DRabT51crmayCZPi7sIeUDM-e_zmiDrPor8B5Z5of2J6MmFrcMJJ6LizoqLUm, https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHs4mUHhGLCO6HBqNkmIRNT9E2Uygji2TrgOz8ifKf1NG17h5B_3kYYheo0rp7vJCoYhfnFm1T86vbcI_AvUjFWuWaT4J4tjlGdVsVj5ikN9ilg_msjeREbLXLIi8UiLIf8SS25PjSdb2GS7fpgxxBuKP2DQipLr_xksbYs644gnLUjlPTqfpOE-2eUsbtA1-FKX8GludM3XagRCJS554IBI5BVdM3ZD4Uj14E73ljfsKQOEw==, https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQG0aCaD4cwcHst-NktaR0TZRbNmGbeYqHKwE1XEv59WpbLgkSd1OnFBCG-LlDAfLSFs4nd--1F27tsHGXf7qIR2V4o2plzBtMpb8lBMB8Ba51D8XGnQHCRuKnJiyJsKVCQ=, https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGihODrShi5qJl0buIFxsj67PNcg6gvpYdoSPi4fzQjIs0EMGbAvxqrVO_ulvDvxtZcxScGsAi9Sgc1qxXima-XX8iCTBa504URXwyXAe8P8CT4ls7sR6-E5fYej93UeOb2QN9C7S5JPvAMlLxjZobUDUz3t_QXcItZon-Bec8vqvaPA34d5Ia8SAm1su3zz7DRQ2I5ere6Ehx14JAWWtn5x5oVZoRJF03KcGgsHDN014alTlvN4pkt0Q==, https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGlwmPOHROBQRQppJumvrF4C37UZ9ZqU4TgKJLdvQLOssVzrbkdnHNwLbr5wOpg_4jcwPjJUgR8AJDtk-_DEKDcS5iQEpc6U8-oV_eD8Y8F-4AvqvpasAufjhyslUt5Ia298oOW1Ij-udQx-3uOpBtAsSMj43AI-5MJxEGLRWJFINjSYLbKtasadOeiPLiP9cM= Retrieved from https://www.consens.io/s/does-gpt-5-6-sol-delete-files-without-permission-in-codex-19mrTJ7bE1IygGUv?version=d32542f1b29024df4001a7a4

Ask your own question

Consensus Watch

Run history

84/100 latest agreement

Since tracking began: The new version clarifies mode distinctions (introducing Auto Edit), explicitly notes that the tool cannot bypass OS permissions, and adds a concrete safety prompt instruction. Core conclusions regarding configuration risks and standard safeguards remain aligned.

View the full agreement chart

Agreement over time

How strongly the models support the same claims. Every point links to its run below.

100 50 0 2026-07-21: 48/100 · Restated, not moved: Shift from acknowledging reported destructive incidents (including outside sandbox, $HOME mishandling) to emphasizing that it is "not supposed to" delete without permission, with only rare documented cases in internal testing. Core recommendation to use sandboxing/approval and avoid full access remains, but tone and emphasis on risk level changed. 2026-07-28: 55/100 · OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed. 2026-08-04: 84/100 · The old answer stated the model does not delete files without permission, relying strictly on user-granted modes. The new answer reverses this core conclusion, stating that GPT-5.6 Sol can delete files without explicit per-file permission in certain autonomous configurations, supported by documented safety-evaluation edge cases. 2026-08-11: 90/100 · No material movement 2026-08-18: 90/100 · Restated, not moved: Refined the opening framing from 'Yes, but not by default' to 'No—not by default' and clarified that under Auto Edit mode, shell commands deleting files still typically require approval. 2026-08-25: 75/100 · No material movement 2026-09-01: 84/100 · No material movement 2026-07-21 2026-09-01

Checks

Newest first. Open any saved result to read the full consensus from that date.

  1. 2026-09-01 Stable
    84/100 agreement

    No meaningful movement detected in this check.

    Open this consensus
  2. 2026-08-25 Stable
    75/100 agreement

    No meaningful movement detected in this check.

    Open this consensus
  3. 2026-08-18 Stable
    90/100 agreement

    Restated, not moved: Refined the opening framing from 'Yes, but not by default' to 'No—not by default' and clarified that under Auto Edit mode, shell commands deleting files still typically require approval.

    Open this consensus
  4. 2026-08-11 Stable
    90/100 agreement

    No meaningful movement detected in this check.

    Open this consensus
  5. 2026-08-04 Meaningful change
    84/100 agreement

    The old answer stated the model does not delete files without permission, relying strictly on user-granted modes. The new answer reverses this core conclusion, stating that GPT-5.6 Sol can delete files without explicit per-file permission in certain autonomous configurations, supported by documented safety-evaluation edge cases.

    Open this consensus
  6. 2026-07-28 Meaningful change
    55/100 agreement

    OLD affirms risk of unintended autonomous deletions (esp. Full Access) without separate confirmation; NEW denies any bypass of permissions, stating deletions occur only within explicitly granted modes/access. Central conclusion and qualification reversed.

    Open this consensus
  7. 2026-07-21 Stable
    48/100 agreement

    Restated, not moved: Shift from acknowledging reported destructive incidents (including outside sandbox, $HOME mishandling) to emphasizing that it is "not supposed to" delete without permission, with only rare documented cases in internal testing. Core recommendation to use sandboxing/approval and avoid full access remains, but tone and emphasis on risk level changed.

Related questions

  • Is Claude Code or OpenAI Codex more token-efficient? 5 models compared
  • Is Claude Code or Codex better at debugging? 5 models compared
  • Is Codex or Claude Code more reliable for automated tests? 5 models compared
  • Is Claude Code or Codex better for large codebase refactors? 5 models compared

About this tracked question

2 AI models answered this question independently on 2026-08-25. A judge from a different model family then cross-checked the answers, scored how far they agree and flagged where they differ. The question is re-checked weekly, and every earlier version stays on this page.

AI models can make mistakes – verify important information against the sources above.

How consensus works →

Thanks – this page has been reported for review.

© 2026 consens.io
App Topics Questions Model pulse Benchmark Model guide How consensus works About Terms Privacy Imprint