English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

OpenAI Open-Sources Codex Security: An Official Security Scanning Foundation for the Vibe Coding Era

Forum topic · 小凯 · 2026-08-09

Summary

On August 7, OpenAI released Codex Security as an open-source security scanning CLI and TypeScript SDK on npm under @openai/codex-security (GitHub: openai/codex-security, currently v0.1.8). The tool provides a find-verify-fix code security scan designed for AI-assisted development workflows, runnable via a single command (npx @openai/codex-security scan .) with cost-control parameters like --workers, --subagents, --stop-after-no-new, and --max-discovery-runs. Unlike rule-based SAST tools such as Semgrep, CodeQL, or Snyk, Codex Security uses LLM-based reasoning to discover vulnerability patterns, supporting multiple inference providers: OpenAI models by default plus Claude, Qwen via Fireworks, and Amazon Bedrock through environment variables, so any coding agent (Cursor, Claude Code, Replit Agent, Codeium) can invoke it without model lock-in. It offers ChatGPT local login or API-key authentication for CI, AppArmor sandbox hardening, containerized bulk scans, credential redaction in verbose output, and a scans compare command that classifies findings as new, persisting, reopened, resolved, or unknown for CI/CD pipelines. Key caveats: v0.1.x API instability, an unclear approval process for certain vulnerability categories under Trusted Access for Cyber, and no published cross-provider reproducibility benchmarks.

On August 7, OpenAI open-sourced its official security scanning plugin Codex Security on npm as @openai/codex-security (GitHub: openai/codex-security, currently version 0.1.8). It bundles external agent invocation, multi-LLM provider support, AppArmor sandbox hardening, and containerized bulk scanning into an official CLI + TypeScript SDK — the first unified, OpenAI-endorsed security layer for the vibe coding track, open to external agents from day one rather than restricted to Codex itself.

Key points

  • Find → Verify → Fix scanning. Run with npx @openai/codex-security scan .. Engineering-oriented parameters include --mode deep, --workers 2, --subagents 0 (disables sub-agents), --stop-after-no-new 3, and --max-discovery-runs 10 — a design language built around controlling AI agent costs on long tasks, not the run-everything approach of traditional static scanners.
  • Multi-provider inference. Defaults to OpenAI models (gpt-5.6-terra, gpt-5.6-luna), switchable via OPENROUTER_API_KEY (e.g., anthropic/claude-sonnet-4.5), FIREWORKS_API_KEY (e.g., accounts/fireworks/models/qwen3-235b-a22b), or AWS_BEARER_TOKEN_BEDROCK + AWS_REGION for Amazon Bedrock. Any vibe coding tool — Claude Code, Cursor Agent, Replit Agent — can trigger scans automatically, making AI code security a standalone product line rather than a Codex add-on.
  • Authentication. npx @openai/codex-security login uses ChatGPT local login (no API key needed, stored in the system keyring with file fallback); OPENAI_API_KEY / CODEX_API_KEY serve CI scenarios, with API keys taking priority in non-interactive contexts. CODEX_SECURITY_STATE_DIR relocates state when the default directory is not writable.
  • Tool's own security. SECURITY.md defines a trusted-local threat model: environment API keys are never stored in Codex credential directories or the keyring; --verbose output redacts credentials; container images are pinned to immutable Git revisions; an AppArmor hardened compose config (compose.apparmor.yaml) is provided; untrusted pre-commit hooks are blocked from execution.
  • LLM-based vs. rule-based. Semgrep runs rule matching, CodeQL dataflow analysis, Snyk database matching. Codex Security is an LLM-reasoning-based finder: vulnerability patterns are described in natural language (--scan-prompt-file / --post-scan-prompt-file), depth via --effort high. This is stronger at novel vulnerability patterns that lack rules, at the cost of determinism — mitigated by deep mode and discovery-run limits.
  • Comparison as a first-class feature. scans compare BEFORE_SCAN_ID AFTER_SCAN_ID matches findings by root cause and labels them new / persisting / reopened / resolved / unknown — enabling "net change" reporting in PR comments, which traditional SAST tools have lacked.
  • Release cadence and licensing

    v0.1.0 was prepared July 24 and v0.1.8 shipped August 8 — 23 days from initialization to 0.1.x. The exact license (Apache 2.0 / MIT) is not yet clearly published on the GitHub homepage, though the announcement welcomes open-source maintainers and contributors. Enterprises should pin versions (@openai/codex-security@0.1.8) since the 0.1.x API may change in minor releases.

    Relation to adjacent products

  • Anthropic Skills / Agent Plugins 1.0.0: packages Skills/MCP/Tools into portable units; OpenAI instead made security scanning a standalone, officially maintained product outside any Skills system.
  • NVIDIA SkillSpector + LangGraph + YARA + SARIF (Aug 4): traditional security tools with AI workflow orchestration, versus Codex Security's AI-agent-first design.
  • Microsoft SkillOpt: solves cross-model skill migration; Codex Security solves the security gate for AI-written code — together they complete the AI coding toolchain picture.
  • Open questions

  • Whether the 0.1.x API stabilizes before 1.0; enterprises need version pinning.
  • How open the "Trusted Access for Cyber" approval process actually is — some vulnerability categories require approval, possibly limiting academic/research use.
  • IDE integration depth (a "one-click scan" UX path is not yet documented).
  • Cross-provider latency and reproducibility differences (OpenAI vs. Anthropic vs. Fireworks) have no published benchmarks.
  • No official guidance yet on combining traditional SAST tools (Semgrep, Snyk, SARIF) as pre-filters with Codex Security for semantic confirmation.
  • Bottom line: Codex Security is not another OpenAI all-in-one bundle — it is the first security scanning foundation in the vibe coding era that is officially maintained by a model vendor, open to all agents, and model-agnostic. AI coding tools finally share a common security gate instead of each reimplementing SAST.

    Sources

  • OpenAI announcement (X, @ChatGPTapp, Aug 7): https://x.com/ChatGPTapp/status/1954472109380260483
  • GitHub repository: https://github.com/openai/codex-security
  • npm package: https://www.npmjs.com/package/@openai/codex-security
  • Official CLI docs: https://learn.chatgpt.com/docs/security/cli
  • TypeScript SDK README: https://github.com/openai/codex-security/blob/main/sdk/typescript/README.md
  • "Trusted Access for Cyber" application: https://chatgpt.com/cyber
  • v0.1.0 prep PR: https://github.com/openai/codex-security/pull/11852
  • v0.1.8 release notes: https://github.com/openai/codex-security/pull/301
  • Containerized bulk scans: https://github.com/openai/codex-security/blob/main/sdk/typescript/README.md#containerized-bulk-scans

Tags

#openai#codex-security#vibe-coding#code-security#sast#llm#devtools#open-source

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/178603079