Code GenerationOpen_source
C

Codex Security

OpenAI's application security agent for the terminal and CI

Overview

About Codex Security

Codex Security is OpenAI's application security agent, shipped as the Apache-2.0 npm package @openai/codex-security containing both a CLI and a TypeScript SDK. It scans a repository for likely vulnerabilities, validates candidate findings before it reports them, and can produce bounded patches for findings you approve. The same scanner is available four ways: as a plugin inside the ChatGPT desktop app, from your terminal, through the SDK, and as Codex Security cloud against connected GitHub repositories.

The validation pass is the part that distinguishes it from running a model over your source. Security scanning fails on noise long before it fails on coverage, and a tool that reports fifty plausible issues of which three are real is worse than no tool, because the triage cost lands on the people least able to absorb it. Codex Security builds a repository-specific threat model, checks likely vulnerabilities against real code context rather than generic signatures, and validates high-signal issues in an isolated environment before surfacing them, with the evidence attached. Two caveats belong up front. The package is at an early version and moving fast, and there is an access gate: the README states that some cybersecurity requests and protected findings require approval through Trusted Access for Cyber, and the documentation adds that running scans requires Codex Security access, with a Trusted-Access-verified account recommended. The exact boundary of that gate is not published, so budget for the possibility that a scan you want is out of scope. Codex Security cloud, the GitHub-connected half, is described by OpenAI as a research preview.

Pricing

Free tier
  • CLI and TypeScript SDK (Apache-2.0)$0/mo

From the vendor pricing page, 2026-09-30

Details

GitHub Stars 10,937
Forks 831
Data from: GitHub • Website•Updated: Sep 30, 2026
securitycode-reviewvulnerability-scanningdebugging