Codex 0.150.0 adds interrupt hooks and hardens untrusted repos
OpenAI's coding agent runs commands on interrupt, blocks untrusted-repo prompt injection, and fixes remote-MCP auth — plus Google reroutes its search links.

Copy markdown
Interrupt hooks run when you stop a turn
A new Interrupt hook type fires shell commands or MCP handlers the moment you cancel an active top-level turn — so an agent can log, checkpoint, or clean up instead of leaving work half-finished. Shipped in 0.150.0 on Aug 26 at 19:37 UTC.
Untrusted repos can no longer inject instructions
Open a project you don't trust and Codex now ignores its project-level instruction files, closing a prompt-injection path, and deny-read rules stay enforced after permission changes. Diagnostics also mask more secrets, including auth-refresh and attestation fields.
@mention other tasks, and auto-naming
Reference other Codex tasks with @ to have an agent read, create, or message them straight from the terminal. Unnamed tasks now get descriptive titles automatically, and /rename proposes an editable one drawn from the conversation.
Remote-MCP auth, Windows, and Unix fixes
0.150.0 fixes remote MCP bearer-token lookup and required-server startup, elevated Windows sandbox setup under Unicode user paths, and Unix shutdown hangs from detached processes. Amazon Bedrock users regain conversation compaction and multi-agent support.
Clickable links, a /copy picker, vim repeat
Markdown links now render as clickable labels in supported terminals. /copy adds a picker for full responses, individual code blocks, or blockquotes, and vim mode gains '.' to repeat your last edit plus a keybinding to cycle permission modes.
Elsewhere: Google reroutes search links through /goto
Google is rolling out google.com/goto redirect wrappers on Search result links, changing the referrer destination sites receive. Worth a check if your analytics, attribution, or SERP tooling reads Google referrers or click URLs.