← Files Codex SecurityARCHIVED FILE

preflight/capability-profiles.toml

2.29 KB · Oct 2, 2026 · 00:04 UTC

↓ Download file

version = 1

[capabilities.delegated_workers]
kind = "runtime"
check = "delegation_available"

[capabilities.goal_tools]
kind = "runtime"
check = "goal_tools_available"

[capabilities.usable_worker_slots_6]
kind = "multi_agent_capacity"
op = ">="
value = 6
v1_default = 6

[capabilities.usable_worker_slots_8]
kind = "multi_agent_capacity"
op = ">="
value = 8
v1_default = 6

[capabilities.agent_depth_2]
kind = "config"
path = "agents.max_depth"
op = ">="
value = 2
default = 1

[capabilities.goals_enabled]
kind = "config"
path = "features.goals"
op = "=="
value = true
default = true

[profiles.security_diff_scan]
description = "Capabilities for Git-backed Codex Security diff scans."

[[profiles.security_diff_scan.requirements]]
capability = "delegated_workers"
severity = "warn"
reason = "Large diff scans may use discovery workers when available; otherwise the parent reviews every changed file."

[[profiles.security_diff_scan.requirements]]
capability = "goal_tools"
severity = "suggest"
reason = "Goal tools help long diff scans preserve completion criteria across many steps."

[[profiles.security_diff_scan.requirements]]
capability = "goals_enabled"
severity = "suggest"
reason = "Enabling goals makes long diff scans easier to resume and audit."

[profiles.security_scan]
description = "Capabilities for repository-wide or scoped-path Codex Security scans."

[[profiles.security_scan.requirements]]
capability = "delegated_workers"
severity = "warn"
reason = "Standard scans use an independent baseline auditor and focused investigation workers when delegation is available."

[[profiles.security_scan.requirements]]
capability = "usable_worker_slots_6"
severity = "warn"
reason = "A six-thread cap provides room for an independent baseline and parallel investigators; it does not require six running workers."

[profiles.deep_security_scan]
description = "Capabilities for deep repository-wide Codex Security scans."
requirements = []

[profiles.security_diff_scan.remediation]
summary = "Recommended Codex config for longer diff scans."

[[profiles.security_diff_scan.remediation.patches]]
path = "features.goals"
value = true

[[routes]]
skill = "security-diff-scan"
profile = "security_diff_scan"

[[routes]]
skill = "security-scan"
profile = "security_scan"

[[routes]]
skill = "deep-security-scan"
profile = "deep_security_scan"

SHA-256: 543a0f6a0e81cbbac1fe43e2e3d44d6163a6792384ab9c768ac519295d9ec8a1