OpenAI Open-Sourced Its Security Scanner
Canonical version: OpenAI Open-Sourced Its Security Scanner.
Last week OpenAI pushed a repository called Codex Security to GitHub without an announcement, blog post or tweet. The Hacker News thread about it reached 560 points before OpenAI said a word.
OpenAI posted about it five days later:
We quietly released the open-source Codex Security CLI, but Hacker News found it before we had a chance to share it here...
I like that they said it out loud.
What Codex Security is
Codex Security is a CLI and TypeScript SDK, Apache-2.0, that scans your code for vulnerabilities using GPT-5.6 Sol. It scans whole organizations, keeps findings between runs, deduplicates, tracks false positives, verifies that your fix actually closed the hole, and plugs into CI.
The security skills are open source too: thirteen of them, guiding how the model looks for each vulnerability class. One commenter in the thread said those prompts represent billions of tokens of optimization work, now sitting in a public repo.
The system behind it shipped as Aardvark back in March 2026, as a research preview for ChatGPT Enterprise, Business and Edu customers. By April, OpenAI reported it had helped fix more than 3,000 critical vulnerabilities. The open client is the new part.
The scanning service is not open
Apache-2.0 covers the CLI, the SDK and the skills. Running an actual scan needs Codex Security service access, which is still a permissioned beta. Without that access, you can read the prompts but can't run a scan.
I understand the reasoning for a tool that finds exploitable bugs at scale.
Two problems early users reported
Cost. One person watched 25% of their weekly Pro credits go into a 42-minute scan that never finished. Another described using five years of Pro usage in five minutes. A third spent over $100 with --max-cost set, and the limit was exceeded anyway. Scans run silently with no progress output, and a failed scan does not resume, so you pay again from zero.
In my opinion, a --max-cost limit that doesn't hold is worse than none, because you trust it and stop watching the scan.
Refusals. The tool locates a vulnerability, then the model's own safety guardrails block it from describing what the vulnerability is. To get fewer refusals you apply to a program called Trusted Access for Cyber. One maintainer said they applied twice and heard nothing back.
The workaround is an access allowlist rather than a technical fix. I don't think this problem is specific to Codex: a defensive tool built on a general model can't tell your intent from an attacker's.
Anthropic shipped one too, six days earlier
On 22 July, Anthropic released the Claude Security plugin for Claude Code (see Claude Code Security Review). The two vendors took different approaches:
- OpenAI built the org-scale tool, open-sourced the prompts, and restricted access to the service
- Anthropic built the developer-loop tool, kept it closed, and ran it on inference you already pay for
To me, the bigger difference is timing. Codex Security scans repositories periodically. The Claude plugin scans at commit time, before anything lands. Pre-commit is the cheapest possible moment to fix something, and moving checks earlier is the same argument I keep coming back to in Loop Engineering: run checks before review.
What I'd do
If you want to try Codex Security, point it at one small repository with a hard spend limit set outside the tool, rather than at your whole organization or in an overnight run.
Read the skills either way. Even if you never run a scan, thirteen well-tuned prompt libraries for vulnerability classes are worth an hour of your time.
I'd also hold the criticism a little loosely. This was an unannounced early build that its own vendor had not finished documenting, and OpenAI's response ("this is an early release, and we're listening") is the right one. Budget enforcement and resumable scans are exactly the kind of thing that gets fixed fast once a team knows people are watching.
The refusals are harder to fix, because they come from a policy decision.
That's it for today! ✨
References
- Codex Security repository: https://github.com/openai/codex-security
- Hacker News discussion: https://news.ycombinator.com/item?id=49089755
- OpenAI's acknowledgement: https://x.com/OpenAI/status/2082263717916586117
- The Decoder, on the Aardvark history: https://the-decoder.com/openai-open-sources-codex-security-cli-to-help-developers-find-and-fix-vulnerabilities-from-the-command-line/
Related
About Sébastien
Ready to get to the next level?
Found this valuable? Share it with someone who needs it.