SpyBara
Go Premium

security.md 2026-05-27 00:57 UTC to 2026-05-28 18:58 UTC

23 added, 8 removed.

2026
Sat 30 07:08 Fri 29 18:58 Thu 28 18:58 Wed 27 00:57 Tue 26 18:54 Sat 23 00:54 Fri 22 18:42 Thu 21 18:44 Wed 20 00:58 Tue 19 18:43 Mon 18 22:01 Thu 14 21:00 Wed 13 00:57 Tue 12 01:59 Mon 11 18:00 Thu 7 20:02 Tue 5 23:00 Sat 2 06:45 Fri 1 18:29

Security – Codex

Install plugin in Codex App

For installation steps, supported skills, and review boundaries, see the Codex Security plugin guide.

Explore plugin use cases

The plugin runs in your Codex thread. Codex Security cloud scans connected GitHub repositories through Codex Web. For Codex sandboxing, approvals, network controls, and admin settings, see Agent approvals & security.

Codex Security cloud

Codex Security cloud is currently in research preview. It scans connected GitHub repositories for likely security issues.

It helps teams:

  1. Find likely vulnerabilities by using a repo-specific threat model and real code context.
  2. Reduce noise by validating findings before you review them.
  3. Move findings toward fixes with ranked results, evidence, and suggested patch options.

How Codex Security cloud works

Codex Security scans connected repositories commit by commit. It builds scan context from your repo, checks likely vulnerabilities against that context, and validates high-signal issues in an isolated environment before surfacing them.

You get a workflow focused on:

  • repo-specific context instead of generic signatures
  • validation evidence that helps reduce false positives
  • suggested fixes you can review in GitHub

Codex Security cloud access and prerequisites

Codex Security is available for ChatGPT Enterprise, Edu, Business, and Pro users. It works with connected GitHub repositories through Codex Web. If you need access or a repository isn’t visible, confirm the repository is available through your Codex Web workspace or contact your OpenAI account team.