## Why
PR #113 added `--permission-profile` to the internal `run-codex-exec`
helper as a required Commander option. Existing callers that invoke the
helper with the pre-#113 argument set now fail during option parsing,
before the existing permission-selection fallback can preserve the
legacy `workspace-write` behavior.
The established `--sandbox` helper option was already required. Making
both helper options optional, as proposed in #115, would broaden the
internal interface unnecessarily; only the newly introduced option needs
a backward-compatible default.
## What changed
- Make `--permission-profile` optional with an empty-string default.
- Keep `--sandbox` required so malformed helper invocations still fail
early.
- Add regression coverage for omitting `--permission-profile` while
preserving the legacy `workspace-write` fallback.
- Rebuild the checked-in `dist/main.js` bundle.
## Testing
- `corepack pnpm test`
- `corepack pnpm run check`