This FAQ covers the Codex Security Cloud plugin. For local scans and workflows that run in a Codex task, see the Codex Security plugin quickstart.
Getting started
What is Codex Security Cloud?
Codex Security Cloud scans connected GitHub repositories, validates likely vulnerabilities, and presents findings with evidence and remediation guidance. Use its plugin on the web or in the desktop app to run repository scans and monitor new commits.
How do I open Codex Security Cloud?
Open Plugins to find and install Codex Security Cloud, then open it. See Cloud setup for the full workflow.
Is this the same plugin as local Codex Security?
No. The Codex Security Cloud plugin scans connected GitHub repositories in Codex cloud. The Codex Security plugin runs local scans in a Codex task.
What if access is unavailable?
Check with your workspace administrator.
How does Codex Security work?
Codex Security runs analysis in an ephemeral, isolated container and temporarily clones the target repository. It performs code-level analysis and returns structured findings with a description, file and location, criticality, root cause, and a suggested remediation.
For findings with verification steps, it runs commands or tests in the sandbox and attaches the results as evidence.
Does it replace SAST?
No. Codex Security complements SAST. It adds semantic, LLM-based reasoning and automated validation, while existing SAST tools still provide broad deterministic coverage.
Features
What is the analysis pipeline?
- Analysis builds a threat model for the repository.
- Scanning reviews the repository once or monitors commit changes for likely issues.
- Validation tries to reproduce likely vulnerabilities in a sandbox to reduce false positives.
- Remediation provides guidance and, where available, proposed patches to review before opening a PR.
What languages are supported?
Codex Security is language-agnostic. In practice, performance depends on the model’s reasoning ability for the language and framework used by the repository.
What outputs do I get after the scan completes?
You get ranked findings with criticality, validation evidence, remediation guidance, and a proposed patch when one is available.
How is customer code isolated?
Each analysis and validation job runs in an ephemeral Codex container with session-scoped tools. Artifacts are extracted for review, and the container is torn down after the job completes.
Does Codex Security auto-apply patches?
No. When a finding has a proposed patch, review it before selecting Create draft pull request.
Does the project need to be built for scanning?
No. Codex Security can produce findings from repository and commit context without a compile step. During auto-validation, it may try to build the project inside the container if that helps reproduce the issue. For environment setup details, see Codex cloud environments.
How does Codex Security reduce false positives and avoid broken patches?
Codex Security uses two stages. First, the model ranks likely issues. Then auto-validation tries to reproduce each issue in a clean container. Findings that successfully reproduce are marked as validated, which helps reduce false positives before human review.
How do repository scans and commit monitoring differ?
A Repository scan runs once across the repository. Commit changes monitors new commits and can review existing commit history. See Monitor new commits.
How long do scans take?
Scan time varies with repository size and validation work. Check Scans for progress and status.
Can I pause commit monitoring?
Yes. Open Repositories, select the repository, and open Monitoring settings. Set monitoring to Paused and select Save.
What is a threat model?
A threat model is the scan-time security context for a repository. It combines a concise project overview with attack-surface details such as entry points, trust boundaries, auth assumptions, and risky components. For more detail, see Improving the threat model.
How is a threat model generated?
Codex Security analyzes the repository’s code to summarize its architecture and security entry points.
Does it replace manual security review?
No. Codex Security accelerates review and helps rank findings, but it does not replace code-level validation, exploitability checks, or human threat assessment.
Can I edit the threat model?
For a monitored repository, Codex Security creates the initial threat model. Open the repository’s Monitoring settings to update it as the architecture, risks, and business context change. For the editing workflow, see Improving the threat model.
What does the proposed patch contain?
The proposed patch contains a minimal actionable diff with filename and line context when a remediation can be generated for the finding.
Does the patch directly modify my PR branch?
No. The workflow generates a diff, patch file, or suggested change for maintainers and reviewers to inspect before applying.
Validation
What is auto-validation?
Auto-validation is the phase that tries to reproduce a suspected issue in an isolated container. It records whether reproduction succeeded or failed and captures logs, commands, and related artifacts as evidence.
What happens if validation fails?
The finding remains unvalidated. Logs and reports still capture what was attempted so engineers can retry, investigate further, or adjust the reproduction steps.