Keep the coding goal and provider action separate
A Codex task can include many steps. This Gated preview gives one branch-creation request a defined policy, approval and receipt path through a project skill and the scoped CLI. It does not grant broader GitHub capabilities.
Codex skills contain reusable instructions in a SKILL.md file and can be invoked explicitly. Review the official Codex skills documentation for the host’s skill behavior; your Gated invitation supplies the reviewed pilot instructions.
Plan the evaluation before requesting the branch
Make the branch request concrete
Choose a non-critical repository, one unique branch name and the full SHA of an existing commit. Keep the branch-creation operation separate from the larger coding task.
Review the project skill and route
Confirm that the reviewed skill directs this request to the scoped Gated CLI. Check the credentials and other provider tools available to the Codex session; a separate GitHub credential can bypass this path.
Name the human reviewer
Choose an authorized approver with a passkey. The reviewer should compare the repository, branch and SHA with the request before confirming it. A changed target needs a new review.
Evaluate the result with evidence
Record the policy outcome, required approval and execution receipt. For an authorized live pilot, compare the GitHub branch reference with the reviewed SHA and record the revocation result.
What has been verified
- Codex runtime rehearsal
- The actual Codex runtime completed a safe-mode request, approval, simulated execution and receipt check. The test agent was revoked. This rehearsal did not establish a live GitHub write from Codex.
- Separate live GitHub proof
- A live branch creation was verified separately through the downloaded CLI. The provider branch and commit matched the reviewed request; replay and revoked-agent behavior were also checked.
The boundary to evaluate
Only requests explicitly routed through the controlled Gated path are governed. The skill does not automatically intercept every tool, block direct GitHub credentials or attest runtime identity. Branch updates, deletion, pull-request execution, merges and force-push governance are outside the implemented preview.