{"record":{"id":"c93df39ede029a2c","repo":"affaan-m/ECC","slug":"openai-transfer-consent-is-required","errorCode":null,"errorMessage":"OpenAI transfer consent is required","messagePattern":"OpenAI transfer consent is required","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"skills/council-multi-model/scripts/review-with-codex.js","lineNumber":186,"sourceCode":"  return versionMatch[1];\n}\n\nfunction buildEnvironment(sourceEnv = process.env) {\n  const allowed = [\n    'PATH', 'HOME', 'USERPROFILE', 'CODEX_HOME',\n    'TMPDIR', 'TMP', 'TEMP', 'SystemRoot', 'ComSpec', 'PATHEXT',\n  ];\n  return Object.fromEntries(\n    allowed.filter((name) => sourceEnv[name]).map((name) => [name, sourceEnv[name]])\n  );\n}\n\nfunction runReview(prompt, options, dependencies = {}) {\n  if (!prompt.trim()) throw new Error('review packet is empty');\n  if (Buffer.byteLength(prompt, 'utf8') > MAX_PROMPT_BYTES) {\n    throw new Error(`review packet exceeds ${MAX_PROMPT_BYTES} bytes`);\n  }\n  if (!options.consent) throw new Error('OpenAI transfer consent is required');\n  if (options.timeoutMs < 10_000 || options.timeoutMs > MAX_TIMEOUT_MS) {\n    throw new Error('timeout is outside the 10-120 second safety range');\n  }\n\n  const spawn = dependencies.spawnSync || spawnSync;\n  const environment = buildEnvironment(dependencies.env || process.env);\n  const verifySupport = dependencies.verifyToollessSupport || verifyToollessSupport;\n  verifySupport({ spawnSync: spawn, env: environment });\n  const makeTemp = dependencies.mkdtempSync || fs.mkdtempSync;\n  const readFile = dependencies.readFileSync || fs.readFileSync;\n  const remove = dependencies.rmSync || fs.rmSync;\n  const tempDir = makeTemp(path.join(os.tmpdir(), 'ecc-council-review-'));\n  const outputFile = path.join(tempDir, 'last-message.txt');\n\n  try {\n    const result = spawn('codex', buildCodexArgs(tempDir, outputFile), {\n      cwd: tempDir,\n      env: environment,","sourceCodeStart":168,"sourceCodeEnd":204,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/council-multi-model/scripts/review-with-codex.js#L168-L204","documentation":"runReview() requires explicit consent before sending the packet to OpenAI's Codex CLI, because the review content leaves the local machine. If options.consent is falsy, this error is thrown. In the CLI this consent is granted via the --consent-to-openai flag; as a library call you must set consent: true in the options object.","triggerScenarios":"runReview(prompt, { consent: false, ... }) or runReview(prompt, {}) — consent flag omitted; CLI invoked without --consent-to-openai (though parseArgs normally catches that first, direct library callers bypass parseArgs).","commonSituations":"Programmatic callers constructing the options object by hand and forgetting consent: true; scripts composing runReview without the argument parser; teams intentionally requiring a user-visible opt-in before external transfer.","solutions":["Pass consent: true in the options object: runReview(prompt, { consent: true, hostProvider: 'anthropic', timeoutMs: 60000 })","For CLI use, add the --consent-to-openai flag","If consent should be dynamic, prompt the user for confirmation and set the flag based on their answer","Only grant consent when the packet content is safe to send to a third-party service"],"exampleFix":"// before\nrunReview(packet, { hostProvider: 'anthropic', timeoutMs: 60000 });\n// after\nrunReview(packet, { consent: true, hostProvider: 'anthropic', timeoutMs: 60000 });","handlingStrategy":"validation","validationCode":"function hasConsent(options) {\n  return options != null && options.consent === true;\n}\nif (!hasConsent(opts)) throw new Error('set options.consent = true before external review');","typeGuard":"function isConsentedOptions(o) {\n  return typeof o === 'object' && o !== null && o.consent === true;\n}","tryCatchPattern":"try {\n  return runReview(prompt, options);\n} catch (err) {\n  if (err.message === 'OpenAI transfer consent is required') {\n    console.error('Pass --consent-to-openai (CLI) or consent: true (library)');\n    process.exitCode = 2;\n    return null;\n  }\n  throw err;\n}","preventionTips":["Always build options through parseArgs rather than hand-rolled objects","Make consent an explicit, reviewed step in automation pipelines","Never default consent to true silently","Document that library callers must set consent: true themselves"],"tags":["consent","privacy","validation","codex"],"backgroundTag":"missing-required-flag","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}