My favorite part (codex thing) is how it runs all commands twice, every time.
Once on a sandbox, realizes nothing works in its sandbox, then again outside the sandbox.
Fucking hell.
I just run it in dangerous / yolo mode in my own sandbox. Works great and no more nagging.
I add commands that constantly fall into this rabbit hole to AGENTS.md alongside an instruction for the agent to request escalation immediately instead of failing first then retrying out of the sandbox. It’s a hack, but it works.