







Codex Security helps security and engineering teams find, confirm, and fix vulnerabilities. Use its command-line interface (CLI) to scan repositories you own or have permission to assess, review findings over time, and check changes before they land. Quickstart Guide for an interactive scan Cloud set-up for connected GitHub repositories Link to the public repo: Codex Security This is an early release, and we’re listening to your feedback as we continue improving it. The Codex Security CLI ...
codex-security/README.md at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
GitHub - openai/codex-security at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security - openai/codex-security
Codex Security: now in research preview
Codex Security is an AI application security agent that analyzes project context to detect, validate, and patch complex vulnerabilities with higher confidence and less noise.

CLI quickstart – Codex Security | ChatGPT Learn
Set up Codex Security, run a local scan, and review the report, findings, and coverage.

GitHub MCP Exploited: Accessing private repositories via MCP
We showcase a critical vulnerability with the official GitHub MCP server, allowing attackers to access private repository data. The vulnerability is among the first discovered by Invariant's security analyzer for detecting toxic agent flows.

Comparing f22d4a36f26d16287bcdfd707b369116e02a08c3...150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
codex-security/sdk/typescript/_bundled_plugin/skills/security-scan/SKILL.md at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
Code scanning shows AI security detections on pull requests - GitHub Changelog
GitHub code scanning now surfaces AI-powered security detections directly on pull requests, expanding vulnerability coverage to languages and frameworks not currently supported by CodeQL. These detections help teams identify and…

codex-security/sdk/typescript/_bundled_plugin/skills/security-scan/references/repository-wide-scan.md at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security - openai/codex-security
Ditching GitHub
This is going to be some sort of a public service announcement, withside notes. This has been brewing for a long, long time (years), it’sjust that I never se...
OpenWiki: Open Source Repo Documentation for Coding Agents
OpenWiki generates and maintains codebase documentation so coding agents can find the repo context they need without loading everything into one instruction file.

codex-security/sdk/typescript/src/config.ts at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
GitHub Codespaces
GitHub Codespaces gets you up and coding faster with fully configured, secure cloud development environments native to GitHub.

A GitHub Issue Title Compromised 4,000 Developer Machines
A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.

Is GitHub Cooked?
Track GitHub service incidents and outages. Real-time stats, incident history, and downtime analytics.
