huh, but what if the AI trashes my git repo? maybe it just deletes the .git folder entirely. a deterministic undo wouldn’t be the silliest feature, for the current definition of “AI”.

The default sandboxing for Codex does not allow the agent to access .git

I think this is what you meant, but just to clarify: it doesn't allow it to write to .git. Read access is allowed.