Agents and security
Providers and security
Models and providers
phax can run a phase with Claude Code, OpenAI Codex or Mistral Vibe. A plan asks for a model and an effort; the routing layer maps them to a provider that has them, following providerPriority in ~/.phax/model-routing.json (mistral-vibe, codex-cli, then claude-code by default). Vibe and Codex are disabled until you enable them, so a fresh install runs everything with Claude Code.
docs/model-routing.md explains how a request is resolved, and the model catalog lists the models phax knows.
Security modes
Every run has a security mode, from security.profile in phax.json or --security:
Providers differ: Claude Code and Codex jail the filesystem; Vibe only partly, so a secure run skips it and falls back to Claude Code. No provider filters network by domain, and only Codex can cut a phase's network off. The mode a phase actually ran with is in its security.json. phax security status shows what each installed provider can enforce.
The agent can run your gate commands and the commands in security.agentCommands, and nothing else where the provider supports an allowlist. The phax binary has no network permission of its own: what reaches the network (an agent, git push, gh) is a program it starts. And phax never builds a shell command from your data: every command it runs gets its arguments one by one. docs/security.md has the details.