OpenAI ships a security scanner you point at any model
Codex Security is a CLI and SDK that finds, validates and fixes vulnerabilities, and can run the scan through OpenRouter, Bedrock or Fireworks instead.
- Stars
- 9.9K
- Language
- TypeScript
- License
- Apache-2.0
- Age
- 3 months old
- Last push
- August 15, 2026
- Latest release
- npm-v0.1.12 · August 15, 2026
Figures as of . Project site: developers.openai.com.
@openai/codex-security is OpenAI's vulnerability scanner as a CLI and a TypeScript SDK, Apache-2.0 licensed, one month old and shipping releases the day this was written. The middle of the README shows it is not locked to OpenAI models.
What it is
Point it at a directory and it looks for security defects, validates them, and can propose fixes. Three commands get you from nothing to a scan:
npm install @openai/codex-security
npx @openai/codex-security login
npx @openai/codex-security scan .
There is a shallow default and a deep mode with knobs that read like a batch job rather than a linter: --workers, --subagents, --max-discovery-runs, --stop-after-no-new, --max-time-hours. Deep discovery runs up to 96 hours by default. That describes an agent that searches a codebase until it stops finding new things.
Why it showed up now
Releases are landing continuously (npm-v0.1.12 on the day of the snapshot), and the repository has grown to five figures of stars in a month. The 0.1.x version line says the interface is still moving.
How it actually works
The scan is model-driven, and the model is a flag: --model gpt-5.6-terra --effort high picks the effort level, and --provider redirects the whole thing elsewhere. The README documents OpenRouter with an Anthropic model, Fireworks with Qwen, and Amazon Bedrock, including the standard AWS credential chain, profiles and web identity. Vendors rarely ship first-class support for running their security product on a competitor's model.
Credential handling is documented in detail, which matters for CI: environment API keys are passed to the current scan and never written to Codex's credential home or the system keyring; local sign-in honours the configured credential backend, including a managed device's keyring; and when both a ChatGPT sign-in and an API key exist, interactive scans ask which to use while non-interactive scans keep API-key precedence.
Try it
npx @openai/codex-security scan . --mode deep --max-time-hours 1.5
Node 22.13+, 24.x or 26.x, plus Python 3.10 or later. In CI, set OPENAI_API_KEY or CODEX_API_KEY and skip the login.
Where it is weak
Access is gated. The README states that some cybersecurity requests and protected findings require approval through Trusted Access for Cyber, applied for separately. A scanner you cannot fully run until an application clears is a different proposition from one you install.
Deep mode is expensive: workers, subagents and discovery runs multiply tokens, and a scan allowed to run for hours keeps spending for hours. The README publishes no benchmark, no precision or recall figures against a labelled corpus, so the only way to know how it compares to the scanners you already run is to run it on a repository whose bugs you already know.
There are 125 open issues on a one-month-old repository, and the version line is 0.1.x. Treat findings as leads to verify, not as a gate to hand a release process.
Sources
- openai/codex-security · GitHub · July 13, 2026
- Codex Security documentation · OpenAI · August 15, 2026
- security
- vulnerability scanning
- CLI
- OpenAI