Live data from Hacker News

Codex starts encrypting sub-agent prompts

github.com

261–270 of 272 posts

Re: Codex starts encrypting sub-agent prompts

#262
post #128

Earlier quoted context omitted.

It's sort of insane though, you not only have dozens/hundreds of stochastic agents running on your machine, but you cannot even inspect the instructions those agents are working off of? I've gone in to look at Claude subagent/workflows and sometimes been like "no this was a mistake to spin up" ... Codex users just get to token yolo the encrypted telephone operator instructions+shell from orchestrator to subagents?

You already have an agent freely doing stuff on your machine. Subagents prompts are a weird place to draw a line. It's not like you're reading everything the agent is doing in any case, let's not kid ourselves.

> You already have an agent freely doing stuff on your machine

No. Agents run in VMs. Assume anywhere you’re running an agent will be compromised, because eventually, it will be.

The only reason most people haven’t is luck, they didn’t happen to install Axios or Tanstack at a certain time.

Re: Codex starts encrypting sub-agent prompts

#263
post #257

Earlier quoted context omitted.

As in "browser"? or the literal thing?

I mean, yeah. At this point you made me think way more about this than I thought I would. I guess either works, whatever floats your boat :)

Ah ah, I love how you still not provide a clear answer. Take it easy, I just thought it's funny you used IE and then I realized (maybe wrongly so) you were making fun of me.

Re: Codex starts encrypting sub-agent prompts

#264

Earlier quoted context omitted.

Raising only because others cited concerns this might cause issues in personal harness contexts. It doesn't. Obviously , I wasn't claiming that it would WORK for cross-model subagents, but that this would be a limiting behavior requiring use of the Codex harness to operate if this was paired with model-level limitations on using specific tools to spawn sub-agents. Or maybe not so obvious to you.

> Raising only because others cited concerns this might cause issues in personal harness contexts. It doesn't. It literally cannot. > Obviously, I wasn't claiming that it would WORK for cross-model subagents I know, but you were questioning (before investigating) if maybe it did, which I'm saying should have been obvious it wouldn't, if you had understand how this was encrypted. > requiring use of the Codex harness t…

No? Again, obviously, the implicit question was whether personal harnesses would be broken due to a model layer bias or system response that pushed arbitrary subagent behavior to fail outside of the codex harness.

I think you don’t really understand how this works if you think the open source harness is all that’s manipulated to determine system behavior.

Re: Codex starts encrypting sub-agent prompts

#265

Earlier quoted context omitted.

It doesn't, at all. This seems to be for Sol and Terra, not Luna, and some other models that seem to switch between encrypted/unencrypted based on something, didn't dig deeper. If you're using local models, it doesn't matter. Even if Codex itself was trying to encrypt stuff for local models (which doesn't make sense, but lets say), you'd still be using a local model so obviously you'd be able to access the plain-text…

it's the multi agent config - multi_agent_v2 btw is still marked "Under Development" and they've said not to open issues for it. Then they deployed globally Sol and Terra under v2 - forcefully, through the model catalogue json (meaning user configs are ignored). v2 encrypts messages, v1 does not. Thankfully, you can override the catalogue with your own copy and set Sol and Terra multi agent to v1 again.

I wonder if at some point some parts of Codex will only work with multi_agent_v2, or the Responses API in general. Then we'd need a fork to keep using e.g. llama.cpp's Chat Requests API.

Re: Codex starts encrypting sub-agent prompts

#266
post #128

Earlier quoted context omitted.

It's sort of insane though, you not only have dozens/hundreds of stochastic agents running on your machine, but you cannot even inspect the instructions those agents are working off of? I've gone in to look at Claude subagent/workflows and sometimes been like "no this was a mistake to spin up" ... Codex users just get to token yolo the encrypted telephone operator instructions+shell from orchestrator to subagents?

>but you cannot even inspect the instructions those agents are working off of? It makes more sense when you realize they don't want developers to be doing any coding at all. That's what they seem to be moving towards. From product manager to product via AI.

They’ve already succeeded at that. My time spent manually writing and editing code must be down 99% post Opus 4.7.

Re: Codex starts encrypting sub-agent prompts

#267
post #263

Earlier quoted context omitted.

I mean, yeah. At this point you made me think way more about this than I thought I would. I guess either works, whatever floats your boat :)

Ah ah, I love how you still not provide a clear answer. Take it easy, I just thought it's funny you used IE and then I realized (maybe wrongly so) you were making fun of me.

> Ah ah, I love how you still not provide a clear answer.

Sorry, "whatever floats your boat" was meant to signal that either works, whichever of the two options fits you best :) I originally meant the MS browser, but general "internet explorer" fits too, players choice!

> then I realized (maybe wrongly so) you were making fun of me.

Oh, not at all! Just that my offhand "then update IE" turned into a bigger conversation than expected, didn't mean to make fun of you or anything like that!

Re: Codex starts encrypting sub-agent prompts

#268
post #210

Earlier quoted context omitted.

No. They don't have the key and can't do encryption in the first place; they're still grand autocomplete engines under the hood. This could only work if the company deliberately builds a mechanism into the backend which runs the decryption function and injects the plaintext somewhere in the context. Which, sure, we can check if they did that, but the whole point is presumably hiding that info so why would they

Their models don't consume encrypted text, it would be absurd to train them to do so. Surely they decrypt the text before feeding it into the LLM, so the contents could get leaked out by asking it.

[deleted]

Re: Codex starts encrypting sub-agent prompts

#269
post #243

Earlier quoted context omitted.

OpenAI's are all unnamed or suns, so it's kinda the same picture.

> OpenAI's are all unnamed or suns, so it's kinda the same picture. Umm, no: > GPT-1, GPT-2, GPT-3, GPT-3.5, GPT-4, GPT-4 Turbo, GPT-4o, GPT-4o mini, o1-preview, o1-mini, o1, o3-mini, o4-mini, o3, o3-pro, GPT-4.1, GPT-4.1 mini, GPT-4.1 nano, GPT-5, GPT-5.1, GPT-5.2, GPT-5.4, GPT-5.4 mini, GPT-5.4 nano, GPT-5.5, GPT-5.5 Pro, GPT-5.6 Luna, GPT-5.6 Terra, GPT-5.6 Sol Besides the constant shifting of nouns and adjectives…

Unnamed or celestial bodies then. That was a fine nit to pick.

The rest just aren't names, they're designations at best

Re: Codex starts encrypting sub-agent prompts

#270
post #243

Earlier quoted context omitted.

> OpenAI's are all unnamed or suns, so it's kinda the same picture. Umm, no: > GPT-1, GPT-2, GPT-3, GPT-3.5, GPT-4, GPT-4 Turbo, GPT-4o, GPT-4o mini, o1-preview, o1-mini, o1, o3-mini, o4-mini, o3, o3-pro, GPT-4.1, GPT-4.1 mini, GPT-4.1 nano, GPT-5, GPT-5.1, GPT-5.2, GPT-5.4, GPT-5.4 mini, GPT-5.4 nano, GPT-5.5, GPT-5.5 Pro, GPT-5.6 Luna, GPT-5.6 Terra, GPT-5.6 Sol Besides the constant shifting of nouns and adjectives…

Unnamed or celestial bodies then. That was a fine nit to pick. The rest just aren't names, they're designations at best

... so Anthropic is more consistent with their naming and we're back to square one in this conversation.
Post reply on HN