SpyBara
Go Premium

security.md 2026-06-09 18:50 UTC to 2026-06-10 20:00 UTC

11 added, 6 removed.

2026
Sat 13 00:58 Fri 12 18:02 Thu 11 20:02 Wed 10 20:00 Tue 9 18:50 Sat 6 00:58 Fri 5 18:45 Thu 4 01:09 Wed 3 19:27 Tue 2 19:22

Codex Security

<CtaPillLink href="https://chatgpt.com/plugins/share/676aca3811d54fa7bcdef5255236b3c4" label="Install plugin in Codex App" icon="external" class="my-8" />

For installation steps, supported skills, and review boundaries, see the Codex Security plugin guide.

Explore plugin use cases

The plugin runs in your Codex thread. Codex Security cloud scans connected GitHub repositories through Codex Web. For Codex sandboxing, approvals, network controls, and admin settings, see Agent approvals & security.

Codex Security cloud

Codex Security cloud is currently in research preview. It scans connected GitHub repositories for likely security issues.

It helps teams:

  1. Find likely vulnerabilities by using a repo-specific threat model and real code context.
  2. Reduce noise by validating findings before you review them.
  3. Move findings toward fixes with ranked results, evidence, and suggested patch options.

How Codex Security cloud works

Codex Security scans connected repositories commit by commit. It builds scan context from your repo, checks likely vulnerabilities against that context, and validates high-signal issues in an isolated environment before surfacing them.

You get a workflow focused on:

  • repo-specific context instead of generic signatures
  • validation evidence that helps reduce false positives
  • suggested fixes you can review in GitHub

Codex Security cloud access and prerequisites

Codex Security is available for ChatGPT Enterprise, Edu, Business, and Pro users. It works with connected GitHub repositories through Codex Web. If you need access or a repository isn't visible, confirm the repository is available through your Codex Web workspace or contact your OpenAI account team.