For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to the page URL.
Primary navigation

Codex Security

Find and remediate vulnerabilities with the Codex Security plugin, CLI, TypeScript SDK, or Codex Security Cloud.

Codex Security is an application security agent that helps security and engineering teams find, confirm, and fix vulnerabilities. Use it in Codex, from your terminal, through the TypeScript SDK, or with connected GitHub repositories.

For your first local scan, start with the Codex Security plugin quickstart.

Use Codex Security in the desktop app

In the ChatGPT desktop app, open the ChatGPT dropdown and select Codex. Install and enable the Codex Security plugin to open Security in the sidebar. The Security workbench keeps your scans, findings, and repositories in one place while Codex runs each scan in a task.

  • Use Scans to start scans, follow their progress, and review saved results.
  • Use Findings to inspect issues and evidence across completed scans.
  • Use Repositories to review repository history and open findings.

See Use the Security workbench for the complete desktop-app workflow.

Explore plugin use cases

The desktop Security workbench and Codex CLI use the Codex Security plugin. The separate Codex Security Cloud plugin scans connected GitHub repositories in Codex cloud. For Codex sandboxing, approvals, network controls, and admin settings, see Agent approvals & security.

Codex Security CLI and SDK

The CLI and TypeScript SDK are available as the public @openai/codex-security package. Run the CLI with npx:

npx @openai/codex-security --help

Running scans requires Codex Security access. For best results, use an account verified for Trusted Access for Cyber.

Use the same scanner as the plugin across repositories and over time. The CLI discovers GitHub repositories, resumes bulk scans, tracks findings across scans, and records false-positive feedback. Add your architecture and security policies, set an estimated cost limit, or run checks in CI and before commits. Use the TypeScript SDK to build scanning, progress reporting, and cost controls into an application or developer tool.

Codex Security Cloud

Codex Security Cloud is a plugin for scanning connected GitHub repositories in Codex cloud. It’s available in research preview on the web and in the desktop app.

Open Plugins to find and install Codex Security Cloud. Follow Cloud setup to connect GitHub and start your first scan.

Track open findings and fixes across repositories. This example uses fictional repositories, findings, and counts.

How Codex Security Cloud works

Choose One-Time Scan to review a repository once, or Continuous Scanning to monitor new commits. Codex uses repository context to identify likely vulnerabilities and validates issues in an isolated environment when possible.

Use Scans to follow progress, Findings to review issues, and Repositories to manage monitoring. Review proposed patches before creating a pull request.

Codex Security Cloud access and prerequisites

Use a workspace with Codex Security Cloud access, a connected GitHub repository, and a compatible Codex cloud environment. You can connect GitHub and create an environment during scan setup.

If access is unavailable, check with your workspace administrator.