







Set up Codex Security, run a local scan, and review the report, findings, and coverage.
codex-security/README.md at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
Introducing the Open-Source Codex Security CLI
Codex Security helps security and engineering teams find, confirm, and fix vulnerabilities. Use its command-line interface (CLI) to scan repositories you own or have permission to assess, review findings over time, and check changes before they land. Quickstart Guide for an interactive scan Cloud set-up for connected GitHub repositories Link to the public repo: Codex Security This is an early release, and we’re listening to your feedback as we continue improving it. The Codex Security CLI ...

Comparing f22d4a36f26d16287bcdfd707b369116e02a08c3...150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
codex-security/sdk/typescript/_bundled_plugin/skills/security-scan/SKILL.md at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
codex-security/sdk/typescript/src/config.ts at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
SDKs and CLI for Codex Security. Contribute to openai/codex-security development by creating an account on GitHub.
GitHub - openai/codex-security at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security - openai/codex-security
Codex Security: now in research preview
Codex Security is an AI application security agent that analyzes project context to detect, validate, and patch complex vulnerabilities with higher confidence and less noise.

oss-security - Re: CVE request: io_uring zcrx freelist OOB write
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Comment and Control: Prompt Injection to Credential Theft in Claude Code, Gemini CLI, and GitHub Copilot Agent
Anthropic Claude Code Security Review, Google Gemini CLI Action, and GitHub Copilot Agent are vulnerable to prompt injection via GitHub comments — turning PR titles, issue bodies, and issue comments into attack vectors for API key and token theft.

kbwo/ccmanager
Coding Agent Session Manager for Claude Code / Gemini CLI / Codex CLI / Cursor Agent / Copilot CLI / Cline CLI / OpenCode / Kimi CLI
codex-security/sdk/typescript/_bundled_plugin/skills/security-scan/references/repository-wide-scan.md at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security - openai/codex-security
Daybreak: Tools for securing every organization in the world
OpenAI introduces new Daybreak tools, including Codex Security and GPT-5.5-Cyber, to help organizations find, validate, and patch vulnerabilities at scale.

codex-security/sdk/typescript/src/api.ts at 150d6f6bba5a00d9e3fcccf053fc25b68cee5a57 · openai/codex-security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security - openai/codex-security
Code scanning shows AI security detections on pull requests - GitHub Changelog
GitHub code scanning now surfaces AI-powered security detections directly on pull requests, expanding vulnerability coverage to languages and frameworks not currently supported by CodeQL. These detections help teams identify and…

Investigation into Message Layer Security (MLS)
This article investigates Message Layer Security (MLS), the IETF standard protocol (RFC 9420) for Signal-style end-to-end encryption. Through a practical analysis of OpenMLS (the Rust reference implementation) and a demonstration CLI chat application (mls-chat), the post reveals the substantial gap between protocol specification and production deployment. Introduction MLS (Message Layer …

argv*mory
it was a not really sunny day in tpa, fl, when i got the message from cpp swift's president. it was an invite to help with their info sec conference, the Tech Symposium. they were looking for community members who would be willing to help with different aspects, tabling, ctf challenges, organization. my brain started to turn and i knew i wanted to do something really funny. last year in october, i had tabled at the CSUF's OSScon, ran by their security club, OSS. the tabling was fun and i got to present some malware that i was working on for a research project with mitre , which is avalible here. it was cool to get people to mess around with malware when they've never seen it before, but for the tech Symposium, i had a more substantial idea of what i wanted to do.