# Codex Security plugin
The Codex Security plugin puts [[OpenAI]]'s application security agent inside [[OpenAI Codex]], on your own machine. You install it from the plugin directory, point it at a repository you own (or are allowed to assess), and Codex runs the review as an ordinary task. It builds a threat model, looks for vulnerabilities, tries to validate each candidate, and writes a report with evidence and remediation guidance. Accept a finding and the same plugin writes a focused patch, then checks that the patch actually closes the hole.
Why does this exist? OpenAI's argument, in the June 2026 Daybreak post, is that finding vulnerabilities stopped being the bottleneck. Models now find plenty. Patching is the slow part. So the plugin tries to cover the whole loop (find, confirm, fix, verify) inside the tool developers already use, instead of adding one more alert queue for someone else to clear.
## What it does
The plugin bundles 15 skills, invoked as `$codex-security:<skill>`, plus an MCP server (see [[AI Agent Skills]] and [[Model Context Protocol (MCP)]]). In practice that gives you these workflows:
- **Standard scan** (`security-scan`): a whole repository or one folder, read-only. It runs in phases: threat modeling (assets, entry points, trust boundaries), finding discovery (broken controls, source-to-sink paths), validation (tests or other checks, with proof gaps recorded), impact and attack-path analysis, reporting, optional structural hardening, then finalization
- **Deep scan** (`deep-security-scan`): runs several complete standard scans as parallel workers and merges what they find. Defaults are 4 workers, a stop after 4 runs in a row add nothing new, 40 runs at most and a 96-hour ceiling, all tunable in `~/.codex/codex-security/config.toml`. Slower and more expensive, with less run-to-run variation
- **Change review** (`security-diff-scan`): uncommitted changes, one commit, a branch range or a pull request. Only the changed files and the code that directly supports them get reviewed
- **Threat model and policy** (`threat-model`, `define-security-policy`): you describe trust boundaries, invariants, what counts as reportable, severity and exclusions in `SECURITY.md` files. Nested ones are allowed and the file closest to the code wins. Codex Security reads them as policy context, never as instructions to execute. Build and test commands go in `AGENTS.md`
- **Backlog triage and validation** (`triage-finding`, `validation`): feed it existing findings (SARIF, a CVE or GHSA, a bug bounty report, Jira or Linear tickets, GitHub code scanning or Dependabot alerts) and it returns `confirmed`, `not_actionable` or `needs_review` for each one, ranked by exploitability. Triage only reads the code; validation can build and run it to reproduce or disprove a claim
- **Fixes** (`fix-finding`, `verify-fix`, `assess-patch-risk`): one accepted finding per task. The patch is written as an artifact first, without touching your checkout. When it's safe, Codex adds a regression test that fails before the fix and passes after it; otherwise it records the proof gap. Verification returns `fixed`, `still_vulnerable` or `inconclusive`, and it never closes the finding for you
- **Reports and handoff** (`vulnerability-writeup`, `propose-security-hardening`, `track-findings`): export to JSON, CSV or SARIF, or push up to 25 findings into Linear, GitHub Issues or Jira (through the Atlassian Rovo plugin), or one private draft GitHub Security Advisory. Every write waits until you approve the exact payload
Each scan leaves a directory behind: `report.md` as the entry point, `findings/<slug>/` with detailed write-ups and proof-of-concept files, `hardening/` for design guidance, and `scan-manifest.json`, `findings.json` and `coverage.json` for automation. Coverage is reported as `complete`, `partial` or `unknown`. Read that before trusting an empty findings list.
## Where it runs
- **Codex in the ChatGPT desktop app**: install it from **Plugins** and a **Security** workbench shows up in the sidebar, with Scans, Findings and Repositories views. Scans keep running as Codex tasks you can open with **View activity** (see [[Codex App]])
- **[[Codex CLI]]**: type `/plugins`, install Codex Security, start a new chat with `/new`, then ask "Run a Codex Security scan on this repository." You get a summary in the terminal and the full `report.md`
- **CI**: `codex plugin add codex-security@openai-curated`, then `codex exec --sandbox workspace-write` with the `security-diff-scan` skill and an API key. OpenAI documents ready-made jobs for GitHub Actions, GitLab CI/CD, Azure Pipelines and Jenkins, all skipping forked pull requests
- **[[Codex IDE Extension]]**: not supported. Plugins don't work in the IDE extension at all, so you install and run them from the desktop app or the CLI
- **[[Codex Cloud]]**: that's a different plugin, **Codex Security Cloud** (research preview). It scans connected GitHub repositories in ephemeral cloud containers, once or continuously on new commits, and offers patches as draft pull requests
OpenAI recommends `gpt-5.6-sol` with `xhigh` reasoning effort for the best results (see [[GPT-5.6]]). Since plugin 0.1.18 scans can also run through Amazon Bedrock, and 0.1.19 passes OpenRouter and Fireworks credentials to deep-scan workers.
## Pricing and availability
OpenAI publishes no separate price for the plugin; I couldn't find one in the docs, the changelog or the announcements. Scans run as ordinary Codex tasks, so they draw on your Codex usage. On [[Hacker News]], one user said a scan of a small app burned through all of his quota in 15 minutes. Another hit the 5-hour session limit mid-scan, and the built-in resume didn't work afterwards (he finished the job with [[Claude Code]] by reading the session logs).
Access has a catch. Before a scan, the plugin checks whether your account has Trusted Access for Cyber (OpenAI's Daybreak program for verified defenders). That check only warns: the scan runs either way. Without that access, though, protected output may be withheld, so the model can tell you it found a vulnerability and then refuse to describe it. A commenter speaking for the Codex Security team confirmed on HN that switching tools doesn't bypass those guardrails; Trusted Access reduces refusals but isn't a blanket bypass. Open-source maintainers can apply to Codex for OSS for conditional access.
The license is worth knowing. The plugin's manifest in `openai/plugins` says "Proprietary". The standalone CLI and TypeScript SDK (`@openai/codex-security`) are open source under Apache-2.0 and bundle the same scanner, but running their scans requires Codex Security access.
Timeline: the first changelog entry is 0.1.7 on 4 June 2026, a larger update shipped with the Daybreak expansion later that month, and the current release is 0.1.30 (24 September 2026). The plugin moves fast; OpenAI tells you to check the changelog before relying on a feature or starting a long scan.
## Limits
- **Results vary between runs.** OpenAI says so in its own FAQ. Deep scans reduce the variation, and matching recognizes the same finding across runs, but none of that makes a scan deterministic
- **Absence of a finding proves nothing on its own.** A fix only counts as verified when a later scan covers the original path without coverage gaps, and the docs still tell you to recheck the finding directly
- **Cost has no real ceiling inside the plugin.** The standalone CLI has `--max-cost`, and even there the docs describe it as an estimate, with requests already in flight allowed to finish above it
- **No local schedule.** The suggested cadence (baseline, code changes, regular review, after a fix) is advice; nothing runs on its own unless you wire it into CI. Continuous commit monitoring belongs to the Cloud plugin
- **It complements SAST and humans.** OpenAI's Cloud FAQ says it doesn't replace [[Static Application Security Testing (SAST)]] or manual security review. Its whole design starts from the repository's behavior instead of a SAST report, which catches checks that look right but don't hold, and gives up the broad deterministic coverage of a rules engine
- **One finding per fix.** The docs explicitly say not to ask Codex to fix every finding from a scan in one chat
## Where the plugin fits in Codex Security
Codex Security is a family of surfaces around the same agent, and the plugin is the newest local one:
1. **Aardvark** (30 October 2025): an "agentic security researcher" powered by GPT-5, in private beta. It monitored commits, built a threat model, validated findings in a sandbox and attached Codex-generated patches. OpenAI reported 92% recall on its benchmark repositories and 10 CVEs in open-source projects
2. **Codex Security research preview** (6 March 2026): Aardvark renamed and moved into Codex web for ChatGPT Pro, Enterprise, Business and Edu, free for the first month. OpenAI reported 1.2 million commits scanned in 30 days, and 14 CVEs from its reports to projects such as OpenSSH and GnuTLS. That cloud product is now the Codex Security Cloud plugin
3. **Codex Security plugin** (June 2026): the local version this note covers
4. **Open-source CLI and SDK** (28 July 2026): same scanner, built for many repositories over time. Covered in [[Codex Security]]
5. **Codex Security Review**: `@codex security review` on GitHub pull requests, or automatic reviews. Enterprise, Business, Edu and Pro, not Plus, billed against Codex allowance or credits
The cleanest split came from that same Codex Security team member on HN: the plugin is for scanning the repository you're working in, while the CLI and SDK handle org-wide scans, scan history, deduplication, false-positive tracking, budget controls and CI.
## Alternatives
- **[[Claude Code Security Review]]**: Anthropic's `/security-review` command and GitHub Action, plus the Claude Security plugin for Claude Code (beta since July 2026), which uses the models in your Claude Code account (see [[Claude Code Plugins]]). The separate Claude Security app on Claude.ai, in public beta for Claude Enterprise, scans connected GitHub repositories with Claude Mythos 5.1
- **GitHub Copilot Autofix**: part of GitHub's code scanning. CodeQL finds the issue deterministically, then an LLM proposes a fix on the pull request or default branch. It needs no Copilot subscription and covers a subset of CodeQL queries for C#, C/C++, Go, Java/Kotlin, Swift, JavaScript/TypeScript, Python, Ruby and Rust. Since Codex Security exports SARIF with CWE tags, the two can feed the same GitHub code scanning view
- **Snyk Code with Snyk Agent Fix** (formerly DeepCode AI Fix): Snyk's rules find the vulnerability, and since May 2026 an agentic fixer uses 35,000+ expert-written fixes as examples, rescans each patch and retries when the fix fails
The real difference is where detection comes from. Copilot Autofix and Snyk start from a deterministic engine and use an LLM to write the fix. Codex Security and Claude Security let the model do the detection too, then spend effort on validation to keep false positives down. Different failure modes, so running one of each makes sense if you can afford it (see [[DevSecOps]]).
## My take
The workflow design is the best part. One finding per patch, a regression test that must fail before the fix, coverage reported honestly, no external write until you approve it: that's how I want any agent to touch security-sensitive code. Worth copying into your own [[AI Agent Skills]], whatever tool you use.
The weak spots are the same ones that hit the [[Codex Security]] CLI: unpredictable cost and a model that can refuse to explain what it found. So start small. Run a change review on a branch you care about before you launch a deep scan of a monorepo, and watch your quota while it runs.
## References
- Codex Security plugin quickstart: https://developers.openai.com/codex/security/plugin (now served from https://learn.chatgpt.com/docs/security/plugin)
- Codex Security overview: https://learn.chatgpt.com/docs/security
- Plugin changelog: https://learn.chatgpt.com/docs/security/plugin/changelog
- Security workbench: https://learn.chatgpt.com/docs/security/plugin/workbench
- Run a scan: https://learn.chatgpt.com/docs/security/plugin/scans
- Deep scans: https://learn.chatgpt.com/docs/security/plugin/deep-scans
- Review code changes (incl. CI examples): https://learn.chatgpt.com/docs/security/plugin/code-changes
- Fix and verify findings: https://learn.chatgpt.com/docs/security/plugin/fix-findings
- Triage a backlog: https://learn.chatgpt.com/docs/security/plugin/triage-backlog
- Export and track findings: https://learn.chatgpt.com/docs/security/plugin/export-findings
- Write vulnerability reports: https://learn.chatgpt.com/docs/security/plugin/vulnerability-reports
- Propose security hardening: https://learn.chatgpt.com/docs/security/plugin/security-hardening
- Codex Security CLI quickstart: https://learn.chatgpt.com/docs/security/cli
- Codex Security CLI FAQ: https://learn.chatgpt.com/docs/security/cli/faq
- Codex Security Cloud setup: https://learn.chatgpt.com/docs/security/setup
- Codex Security Cloud FAQ: https://learn.chatgpt.com/docs/security/faq
- Improving the threat model: https://learn.chatgpt.com/docs/security/threat-model
- Codex Security Review: https://learn.chatgpt.com/docs/security/security-review
- Codex plugins: https://developers.openai.com/codex/plugins
- Models and Trusted Access (Daybreak Blue/Red): https://learn.chatgpt.com/docs/cyber-safety
- Codex pricing: https://developers.openai.com/codex/pricing
- Plugin manifest and skills: https://github.com/openai/plugins/tree/main/plugins/codex-security
- OpenAI, "Get started with the Codex Security plugin": https://openai.com/daybreak/codex-security-plugin/
- OpenAI, "Daybreak: Tools for securing every organization in the world" (June 2026): https://openai.com/index/daybreak-securing-the-world/
- OpenAI Daybreak: https://openai.com/daybreak/
- OpenAI, "Codex Security: now in research preview" (6 March 2026): https://openai.com/index/codex-security-now-in-research-preview/
- OpenAI, "Why Codex Security Doesn't Include a SAST Report" (March 2026): https://openai.com/index/why-codex-security-doesnt-include-sast/
- OpenAI, "Introducing Aardvark" (30 October 2025): https://openai.com/index/introducing-aardvark/
- HN, Daybreak / GPT-5.5-Cyber thread (221 points, 174 comments; plugin quota reports): https://news.ycombinator.com/item?id=48639063
- HN, Codex Security CLI thread (plugin vs CLI, refusals): https://news.ycombinator.com/item?id=49089755
- HN, Codex Security Plugin Quickstart submission: https://news.ycombinator.com/item?id=48676002
- GitHub, Responsible use of Copilot Autofix and Code Security AI features: https://docs.github.com/en/code-security/code-scanning/managing-code-scanning-alerts/responsible-use-autofix-code-scanning
- Snyk, Fix code vulnerabilities automatically (Snyk Agent Fix): https://docs.snyk.io/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically
- Anthropic, Claude Security: https://claude.com/product/claude-security
## Related
- [[Codex Security]]
- [[OpenAI Codex]]
- [[Codex CLI]]
- [[Codex App]]
- [[Codex Cloud]]
- [[Claude Code Security Review]]
- [[Static Application Security Testing (SAST)]]
- [[DevSecOps]]
- [[AI Agent Skills]]