CDX-CFG-008: Invalid shell_environment_policy Value
Summary
- Rule ID:
CDX-CFG-008 - Severity:
HIGH - Category:
Codex CLI - Normative Level:
MUST - Auto-Fix:
No - Verified On:
2026-07-30
Applicability
- Tool:
codex - Version Range:
unspecified - Spec Revision:
unspecified
Evidence Sources
- https://developers.openai.com/codex/config-reference
- https://developers.openai.com/codex/config-schema.json
- https://developers.openai.com/codex/enterprise/managed-configuration
- https://github.com/openai/codex/blob/rust-v0.146.0/codex-rs/core/config.schema.json
Test Coverage Metadata
- Unit tests:
true - Fixture tests:
true - E2E tests:
false
Examples
The following examples demonstrate what triggers this rule and how to fix it.
Invalid
[shell_environment_policy]
exclude = ["AWS_*"]
[shell_environment_policy.filters]
"PATH" = "include"
Valid
[shell_environment_policy]
inherit = "core"
[shell_environment_policy.filters]
"AWS_*" = "exclude"