On August 7, OpenAI open-sourced its official security scanning plugin Codex Security on npm as @openai/codex-security (GitHub: openai/codex-security, currently version 0.1.8). It bundles external agent invocation, multi-LLM provider support, AppArmor sandbox hardening, and containerized bulk scanning into an official CLI + TypeScript SDK — the first unified, OpenAI-endorsed security layer for the vibe coding track, open to external agents from day one rather than restricted to Codex itself.
Key points
- Find → Verify → Fix scanning. Run with
npx @openai/codex-security scan .. Engineering-oriented parameters include--mode deep,--workers 2,--subagents 0(disables sub-agents),--stop-after-no-new 3, and--max-discovery-runs 10— a design language built around controlling AI agent costs on long tasks, not the run-everything approach of traditional static scanners. - Multi-provider inference. Defaults to OpenAI models (
gpt-5.6-terra,gpt-5.6-luna), switchable viaOPENROUTER_API_KEY(e.g.,anthropic/claude-sonnet-4.5),FIREWORKS_API_KEY(e.g.,accounts/fireworks/models/qwen3-235b-a22b), orAWS_BEARER_TOKEN_BEDROCK+AWS_REGIONfor Amazon Bedrock. Any vibe coding tool — Claude Code, Cursor Agent, Replit Agent — can trigger scans automatically, making AI code security a standalone product line rather than a Codex add-on. - Authentication.
npx @openai/codex-security loginuses ChatGPT local login (no API key needed, stored in the system keyring with file fallback);OPENAI_API_KEY/CODEX_API_KEYserve CI scenarios, with API keys taking priority in non-interactive contexts.CODEX_SECURITY_STATE_DIRrelocates state when the default directory is not writable. - Tool's own security. SECURITY.md defines a trusted-local threat model: environment API keys are never stored in Codex credential directories or the keyring;
--verboseoutput redacts credentials; container images are pinned to immutable Git revisions; an AppArmor hardened compose config (compose.apparmor.yaml) is provided; untrusted pre-commit hooks are blocked from execution. - LLM-based vs. rule-based. Semgrep runs rule matching, CodeQL dataflow analysis, Snyk database matching. Codex Security is an LLM-reasoning-based finder: vulnerability patterns are described in natural language (
--scan-prompt-file/--post-scan-prompt-file), depth via--effort high. This is stronger at novel vulnerability patterns that lack rules, at the cost of determinism — mitigated by deep mode and discovery-run limits. - Comparison as a first-class feature.
scans compare BEFORE_SCAN_ID AFTER_SCAN_IDmatches findings by root cause and labels them new / persisting / reopened / resolved / unknown — enabling "net change" reporting in PR comments, which traditional SAST tools have lacked. - Anthropic Skills / Agent Plugins 1.0.0: packages Skills/MCP/Tools into portable units; OpenAI instead made security scanning a standalone, officially maintained product outside any Skills system.
- NVIDIA SkillSpector + LangGraph + YARA + SARIF (Aug 4): traditional security tools with AI workflow orchestration, versus Codex Security's AI-agent-first design.
- Microsoft SkillOpt: solves cross-model skill migration; Codex Security solves the security gate for AI-written code — together they complete the AI coding toolchain picture.
- Whether the 0.1.x API stabilizes before 1.0; enterprises need version pinning.
- How open the "Trusted Access for Cyber" approval process actually is — some vulnerability categories require approval, possibly limiting academic/research use.
- IDE integration depth (a "one-click scan" UX path is not yet documented).
- Cross-provider latency and reproducibility differences (OpenAI vs. Anthropic vs. Fireworks) have no published benchmarks.
- No official guidance yet on combining traditional SAST tools (Semgrep, Snyk, SARIF) as pre-filters with Codex Security for semantic confirmation.
- OpenAI announcement (X, @ChatGPTapp, Aug 7): https://x.com/ChatGPTapp/status/1954472109380260483
- GitHub repository: https://github.com/openai/codex-security
- npm package: https://www.npmjs.com/package/@openai/codex-security
- Official CLI docs: https://learn.chatgpt.com/docs/security/cli
- TypeScript SDK README: https://github.com/openai/codex-security/blob/main/sdk/typescript/README.md
- "Trusted Access for Cyber" application: https://chatgpt.com/cyber
- v0.1.0 prep PR: https://github.com/openai/codex-security/pull/11852
- v0.1.8 release notes: https://github.com/openai/codex-security/pull/301
- Containerized bulk scans: https://github.com/openai/codex-security/blob/main/sdk/typescript/README.md#containerized-bulk-scans
Release cadence and licensing
v0.1.0 was prepared July 24 and v0.1.8 shipped August 8 — 23 days from initialization to 0.1.x. The exact license (Apache 2.0 / MIT) is not yet clearly published on the GitHub homepage, though the announcement welcomes open-source maintainers and contributors. Enterprises should pin versions (@openai/codex-security@0.1.8) since the 0.1.x API may change in minor releases.
Relation to adjacent products
Open questions
Bottom line: Codex Security is not another OpenAI all-in-one bundle — it is the first security scanning foundation in the vibe coding era that is officially maintained by a model vendor, open to all agents, and model-agnostic. AI coding tools finally share a common security gate instead of each reimplementing SAST.