Most incidents in this database come with a command, a commit, or a log line pinpointing exactly what went wrong. This one doesn't — and that gap is itself worth documenting.
What the report says
On August 12, 2026, a user working with OpenAI's Codex on an active Windows development project found that important project files had been deleted during a session, without having asked for or approved the deletion. They filed GitHub issue #38312 the next day, labeled bug, safety-check, sandbox, and windows-os.
The report is unusually upfront about its own limits. The reporter states plainly that the exact Codex version, model, original prompt, deletion command, and affected paths "were not yet captured" at filing time — the priority was stopping further damage and assessing recovery, not gathering diagnostics first.
What it doesn't establish
No reproduction. No confirmed Codex version or model. No captured command. No count of files lost or confirmation of what, if anything, was recovered. As of this writing, the issue is open with no maintainer response.
That's why this entry is scored low severity (3.5) and marked both verified: false and reproducible: false in our record — a single user account with real but unconfirmed detail, not a documented failure mode with a known trigger.
Why it's in the database anyway
The ask embedded in the issue is a reasonable one regardless of the missing specifics: agents should treat bulk or recursive deletion, and removal of existing user-authored files, as high-risk — requiring an explicit before-the-fact confirmation naming what will be lost, rather than treating filesystem write access as implied permission to delete valuable project data. Whether Codex's specific behavior here matches that ask can't be confirmed from what's public yet.
Status
Filed 2026-08-13 against openai/codex, no maintainer response as of this writing.
Full record and sourcing: STUPID-2026-0091
This is one of 80+ severity-scored AI agent incidents documented at StupidLLM, an open incident database for AI coding agent failures — every entry marked with exactly how well-verified it is, including this one.
Top comments (0)