Local Codex session receipts
Starts a new instrumented Codex CLI session and leaves a local, hash-only receipt of command events and checked repository states. Later, AgentProof validates the receipt and compares its recorded final file commitments with the current repository. The child runs non-interactively with Codex approvals disabled and retains the selected read-only or workspace-write sandbox. It does not capture the current Codex conversation or establish completeness, truth, authorship, work quality, compliance, payment authorization or settlement, and it uses no HREVN service or credential.