Before submitting
Area
apps/server — Codex developer instructions / browser tool selection
Summary
T3 Code's injected browser instructions can override a repository-defined debugging workflow, even when the user explicitly asks the agent to follow that workflow. Preview being available is treated as sufficient reason to use it, although it may not support the authentication/session setup required by the repository.
This was observed in a Codex thread. The example below is deliberately generic and contains no project details.
Steps to reproduce
- Use a repository whose AGENTS.md tells the agent to follow its documented browser-debugging workflow. A referenced skill specifies Playwright MCP, a repository-owned authentication helper, and an isolated browser session initialized with the resulting storage state.
- Start a Codex thread in T3 Code with
preview_* tools exposed.
- Ask the agent to investigate a browser test and explicitly invoke that repository skill.
- The agent reads the skill but selects T3 Preview because the injected developer instructions prioritize it and restrict switching to other browser systems.
- Preview opens the target successfully but reaches a login page. Its exposed tools do not provide the storage-state loading mechanism required by the documented workflow.
- The agent asks the user to log in manually or explicitly authorize another browser instead of first resolving the repository's prescribed setup and reporting any actual missing prerequisite.
Expected behavior
The Preview preference should be a default, not a restriction that displaces an explicitly selected repository workflow. Invoking a skill that specifies a browser/toolchain should count as selecting that workflow, without requiring the user to separately name a browser exception.
If the required MCP connection is missing, the agent should report that specific prerequisite. It should not silently substitute Preview and then ask the user to redo authentication manually.
Actual behavior
The agent followed the Preview-first instruction despite reading the repository workflow, hit the separate browser's login page, and requested user intervention before completing the prescribed setup checks.
The injected rule permits alternatives when Preview tools are absent, the user explicitly requests another browser, or preview_open reports unsupported/unavailable. It does not clearly cover an explicitly invoked repository skill or a browser that opens successfully but lacks the session setup required for the task.
An additional observed failure: the agent subsequently proposed running the repository authentication helper without explaining that its output would not authenticate Preview. This illustrates how mixing the two workflows leads to misleading recovery steps.
Impact
Major degradation of repository-guided browser debugging: unnecessary login requests, interrupted automation, and confusion between browser availability and suitability for the required test identity/session.
Version or commit
Exact T3 Code build not recorded. Observed on October 5, 2026.
Environment
macOS; T3 Code with Codex; installed Codex CLI 0.159.3; model gpt-6-astra.
Workaround
Explicitly tell the agent to use the repository's Playwright MCP workflow instead of T3 Preview. This is a prompt-level workaround; a completed end-to-end run with it was not verified in this session.
Suggested correction
Make the injected browser guidance defer to explicit user-selected repository skills and documented browser workflows. Preserve Preview as the default where no such workflow has been selected. Treat missing task-critical capabilities separately from failure to open a tab.
Related: #11579 addresses agents bypassing a healthy Preview. This report concerns the opposite failure: overcorrecting browser selection prevents following a repository's required debugging setup.
Before submitting
Area
apps/server — Codex developer instructions / browser tool selection
Summary
T3 Code's injected browser instructions can override a repository-defined debugging workflow, even when the user explicitly asks the agent to follow that workflow. Preview being available is treated as sufficient reason to use it, although it may not support the authentication/session setup required by the repository.
This was observed in a Codex thread. The example below is deliberately generic and contains no project details.
Steps to reproduce
preview_*tools exposed.Expected behavior
The Preview preference should be a default, not a restriction that displaces an explicitly selected repository workflow. Invoking a skill that specifies a browser/toolchain should count as selecting that workflow, without requiring the user to separately name a browser exception.
If the required MCP connection is missing, the agent should report that specific prerequisite. It should not silently substitute Preview and then ask the user to redo authentication manually.
Actual behavior
The agent followed the Preview-first instruction despite reading the repository workflow, hit the separate browser's login page, and requested user intervention before completing the prescribed setup checks.
The injected rule permits alternatives when Preview tools are absent, the user explicitly requests another browser, or
preview_openreports unsupported/unavailable. It does not clearly cover an explicitly invoked repository skill or a browser that opens successfully but lacks the session setup required for the task.An additional observed failure: the agent subsequently proposed running the repository authentication helper without explaining that its output would not authenticate Preview. This illustrates how mixing the two workflows leads to misleading recovery steps.
Impact
Major degradation of repository-guided browser debugging: unnecessary login requests, interrupted automation, and confusion between browser availability and suitability for the required test identity/session.
Version or commit
Exact T3 Code build not recorded. Observed on October 5, 2026.
Environment
macOS; T3 Code with Codex; installed Codex CLI 0.159.3; model gpt-6-astra.
Workaround
Explicitly tell the agent to use the repository's Playwright MCP workflow instead of T3 Preview. This is a prompt-level workaround; a completed end-to-end run with it was not verified in this session.
Suggested correction
Make the injected browser guidance defer to explicit user-selected repository skills and documented browser workflows. Preserve Preview as the default where no such workflow has been selected. Treat missing task-critical capabilities separately from failure to open a tab.
Related: #11579 addresses agents bypassing a healthy Preview. This report concerns the opposite failure: overcorrecting browser selection prevents following a repository's required debugging setup.