







Summary codex-security scan fails deterministically at the seal step. The scan runs to completion (models are invoked, tokens billed), preflight reports zero issues, then the tool errors trying to ...
Standard full-repository scan shows only generic heartbeat for 40+ minutes — expected behavior? · Issue #70 · openai/codex-security
Summary A standard full-repository scan has been running for more than 43 minutes while the CLI prints only a generic Running scan heartbeat once per second. There are no phase changes, completed/p...

codex-security/sdk/typescript/_bundled_plugin/skills/security-scan/references/repository-wide-scan.md at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security - openai/codex-security
codex-security/README.md at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
GitHub - openai/codex-security at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security - openai/codex-security
CLI quickstart – Codex Security | ChatGPT Learn
Set up Codex Security, run a local scan, and review the report, findings, and coverage.

Introducing the Open-Source Codex Security CLI
Codex Security helps security and engineering teams find, confirm, and fix vulnerabilities. Use its command-line interface (CLI) to scan repositories you own or have permission to assess, review findings over time, and check changes before they land. Quickstart Guide for an interactive scan Cloud set-up for connected GitHub repositories Link to the public repo: Codex Security This is an early release, and we’re listening to your feedback as we continue improving it. The Codex Security CLI ...

codex-security/sdk/typescript/_bundled_plugin/skills/security-scan/SKILL.md at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
Comparing f22d4a36f26d16287bcdfd707b369116e02a08c3...150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
codex-security/sdk/typescript/src/config.ts at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
Codex Security: now in research preview
Codex Security is an AI application security agent that analyzes project context to detect, validate, and patch complex vulnerabilities with higher confidence and less noise.

envoy/api/envoy/config/bootstrap/v3/bootstrap.proto at a6848603acf28017f9194789b01d16c6c1782e3e · envoyproxy/envoy
Cloud-native high-performance edge/middle/service proxy - envoyproxy/envoy
Bastian Greshake Tzovaras (@gedankenstuecke@scholar.social)
It's great that a class of tool that by its very design is an unfixable security issue is forced into everything: «This works often enough that Måløy reported this to Microsoft as a security hole in March. He gave them a 90-day reporting window, Microsoft extended that twice to a total of 144 days, and they still didn’t have a solid fix. So Måløy posted about the hole on July 28th.» Copilot prompt injection goes viral in your documents https://pivot-to-ai.com/2026/08/03/copilot-prompt-injection-goes-viral-in-your-documents/
Settings – Codex app | OpenAI Developers
Configure Codex app behavior and preferences
