The default sandboxing for Codex does not allow the agent to access .git

I think this is what you meant, but just to clarify: it doesn't allow it to write to .git. Read access is allowed.