SpyBara
Go Premium

Documentation 2026-07-29 22:01 UTC to 2026-07-30 23:58 UTC

18 files changed +778 −453. View all changes and history on the product overview
2026
Thu 30 23:58 Wed 29 22:01 Tue 28 23:01 Mon 27 18:59 Fri 24 15:00 Thu 23 21:57 Wed 22 20:02 Tue 21 22:02 Mon 20 23:01 Fri 17 22:57 Thu 16 20:57 Wed 15 19:58 Tue 14 17:03 Wed 8 02:01 Mon 6 22:58

amazon-bedrock.md +25 −15

Details

65credential chain. The local client can use these standard AWS SDK credential65credential chain. The local client can use these standard AWS SDK credential

66sources:66sources:

67 67 

681. Shared AWS `config` and `credentials` files.68#### Shared AWS configuration files

69 

70Configure the shared AWS `config` and `credentials` files:

69 71 

70```shell72```shell

71 aws configure73aws configure

72```74```

73 75 

742. Environment variables.76#### Environment variables

77 

78Set the standard AWS SDK credential environment variables:

75 79 

76```shell80```shell

77 export AWS_ACCESS_KEY_ID=<your-access-key-id>81export AWS_ACCESS_KEY_ID=<your-access-key-id>

78 export AWS_SECRET_ACCESS_KEY=<your-secret-access-key>82export AWS_SECRET_ACCESS_KEY=<your-secret-access-key>

79 export AWS_SESSION_TOKEN=<your-session-token>83export AWS_SESSION_TOKEN=<your-session-token>

80```84```

81 85 

823. AWS Management Console credentials.86#### AWS Management Console credentials

87 

88Log in with AWS Management Console credentials:

83 89 

84```shell90```shell

85 aws login91aws login

86```92```

87 93 

884. AWS SSO or a named profile.94#### AWS SSO or a named profile

95 

96Log in with AWS SSO and select the named profile:

89 97 

90```shell98```shell

91 aws sso login --profile codex-bedrock99aws sso login --profile codex-bedrock

92 export AWS_PROFILE=codex-bedrock100export AWS_PROFILE=codex-bedrock

93```101```

94 102 

955. Federated identity configured with `credential_process`. For corporate SSO or103#### Federated identity

96 OIDC federation, configure the AWS profile outside the local client and let104 

97 the AWS SDK resolve credentials. Put browser login, token exchange, caching,105For corporate SSO or OIDC federation, configure a federated identity with

98 and refresh in your AWS profile's `credential_process` helper.106`credential_process` outside the local client and let the AWS SDK resolve

107credentials. Put browser login, token exchange, caching, and refresh in your

108AWS profile's `credential_process` helper.

99 109 

100## Desktop app and IDE extension110## Desktop app and IDE extension

101 111 

Details

4 4 

5Codex Micro is a limited-run collaboration between Codex and Work Louder. It5Codex Micro is a limited-run collaboration between Codex and Work Louder. It

6works with the ChatGPT desktop app, giving you a quick way to check on chats,6works with the ChatGPT desktop app, giving you a quick way to check on chats,

7jump between them, use push-to-talk, and trigger common actions or skills7jump between them, use voice input, and trigger common actions or skills without

8without leaving the keyboard.8leaving the keyboard.

9 9 

10 10

11 11 


24## Set up Codex Micro24## Set up Codex Micro

25 25 

261. Open the ChatGPT desktop app.261. Open the ChatGPT desktop app.

272. Connect Codex Micro to your computer with a USB-C cable or Bluetooth, then272. Press the rear button once to turn on Codex Micro.

28 follow the setup that appears when ChatGPT detects it.283. Connect it with a USB-C cable or [pair it with Bluetooth](#pair-with-bluetooth),

293. On macOS, allow **Input Monitoring** when prompted so ChatGPT can respond to29 then follow the setup that appears when ChatGPT detects it.

304. On macOS, allow **Input Monitoring** when prompted so ChatGPT can respond to

30 key presses.31 key presses.

314. Open **Settings > Codex Micro** to choose which chats the Agent Keys follow,325. Open **Settings > Codex Micro** to choose what the Agent Keys follow or

32 assign actions to the Command Keys and analog directions, and adjust the33 trigger, customize the Command Keys, analog stick, and dial, and adjust

33 lighting.34 lighting and voice controls.

34 35 

35To open these settings again, press and hold the dial for 500 milliseconds or36By default, press and hold the dial for a short while to open these settings. You

36select the Codex Micro icon beside your account name at the bottom of ChatGPT.37can also select the Micro icon beside your account name at the bottom of ChatGPT.

38A custom dial assignment can replace the press-and-hold shortcut.

37 39 

38You'll see **Codex Micro** in Settings after ChatGPT detects the device for the40The device settings remain available after ChatGPT detects a supported Micro for

39first time. If you want to use the device outside ChatGPT, customize those41the first time. Work Louder Input isn't required for the ChatGPT integration.

40controls with [Work Louder Input](https://worklouder.cc/micro-setup).42Use it to customize controls for other apps or configure more layers.

43 

44## Pair with Bluetooth

45 

46Codex Micro provides three Bluetooth channels.

47 

481. Press the rear button once to turn on the Micro.

492. Press and hold the touch control on the bottom-left edge for three seconds.

50 The lighting under the Micro turns blue when Bluetooth mode is active.

513. Tap the touch control to choose Bluetooth channel 1, 2, or 3. A fast-flashing

52 channel light means the Micro is ready to pair.

534. Open your computer's Bluetooth settings and connect to the Micro when it

54 appears.

555. Wait for the channel light to turn solid, which means pairing is complete.

56 

57The connection selector closes after five seconds without input. To switch to

58another paired channel, open the selector again, choose the channel, and wait

59for it to close. To pair that channel again, press and hold the touch control

60for three seconds until its light begins flashing.

61 

62To use USB-C instead, open the connection selector and tap the touch control

63until the lighting under the Micro turns white. Connecting a USB-C cable while

64the Micro is still in Bluetooth mode charges it but doesn't switch it to the

65wired connection.

66 

67For hardware diagrams, see the [Work Louder Codex Micro setup

68guide](https://worklouder.cc/openai-micro-setup).

41 69 

42<a id="read-and-switch-tasks-with-agent-keys"></a>70<a id="read-and-switch-tasks-with-agent-keys"></a>

43 71 


46Each of the six frosted Agent Keys can follow a chat and light up to show its74Each of the six frosted Agent Keys can follow a chat and light up to show its

47current status. Press an Agent Key once to switch to that chat without bringing75current status. Press an Agent Key once to switch to that chat without bringing

48ChatGPT forward. Press it twice within 350 milliseconds to switch chats and76ChatGPT forward. Press it twice within 350 milliseconds to switch chats and

49bring the ChatGPT window forward.77bring the ChatGPT window forward. To focus ChatGPT with the first press, turn on

78**Focus ChatGPT with a single tap** in the device settings.

50 79 

51| Light | Status | Meaning |80| Light | Status | Meaning |

52| ----- | ---------------- | ----------------------------------------- |81| ----- | ---------------- | ----------------------------------------- |


60The selected chat's key pulses with its status light.89The selected chat's key pulses with its status light.

61 90 

62Out of the box, the keys follow your six most recently updated chats, whether91Out of the box, the keys follow your six most recently updated chats, whether

63or not they're pinned. You can change **Agent source** in **Settings > Codex92or not they're pinned. Change **Agent keys** in the device settings to use a

64Micro** to use a different arrangement:93different arrangement:

65 94 

66- **Most recent chats**: Follow the six most recently updated chats, pinned or95- **Most recent chats**: Follow the six most recently updated chats, pinned or

67 unpinned.96 unpinned.

68- **Pinned chats**: Follow the first six chats in **Pinned**.97- **Pinned chats**: Follow the first six chats in **Pinned**.

69- **Priority chats**: Put chats waiting for input, unread chats, and active98- **Priority chats**: Put chats waiting for input, unread chats, and active

70 chats first.99 chats first.

71- **Custom assignments**: Choose the chat assigned to each Agent Key. Press an100- **Custom assignments**: Assign a chat, shortcut, physical key action, or enabled

72 unassigned Agent Key to open a new chat. When you start the chat, ChatGPT101 skill to each Agent Key. Press an unassigned Agent Key to open a new chat.

73 assigns it to that key.102 When you start the chat, ChatGPT assigns it to that key.

74 103 

75The status colors stay the same. You can decide which chats the Agent Keys104The status colors stay the same for keys that follow chats. With **Custom

76follow, but you can't turn them into extra Command Keys.105assignments**, an Agent Key can trigger an action instead.

77 106 

78## Use and customize Command Keys107## Use and customize Command Keys

79 108 


99 128 

100 129 

101The Mic key uses your computer's microphone. Codex Micro doesn't have a130The Mic key uses your computer's microphone. Codex Micro doesn't have a

102microphone of its own. Hold the key while you speak, then release it to stop.131microphone of its own. By default, it uses **Push to talk**: hold the key while

103For hands-free recording, press it twice within 350 milliseconds to keep132you speak, then release it to stop. For hands-free recording, press it twice

104recording. Press it again to stop.133within 350 milliseconds to keep recording. Press it again to stop.

105 134 

106A sea-green light moves around the keyboard while you record. It changes to a135A sea-green light moves around the keyboard while you record. It changes to a

107moving white light while ChatGPT processes your speech, then turns solid white136moving white light while ChatGPT processes your speech, then turns solid white

108when the prompt is ready. Press the Codex key to send it.137when the prompt is ready. Press the Codex key to send it.

109 138 

110In **Settings > Codex Micro**, select a Command Key, then choose its keycap and139If **Voice Chat** is available under **Microphone key**, choose it to use the

111action. You can open the browser or terminal, review changes, commit with Git,140Mic key to start a Voice Chat or toggle your microphone; press and hold it to

112create a pull request, attach files or photos, manage scheduled tasks, change141end the chat. Turn on **Use separate microphone keys** to map the two switches

113reasoning effort, or open **Skills**. If you choose a keycap that's already used142under the wide Mic key independently.

143 

144In the device settings, select a Command Key in the **Layout** preview, then

145choose its keycap and action. You can open the browser or terminal, manage

146chats, review changes, run Git and pull request actions, attach files or photos,

147open plugins or scheduled tasks, change reasoning effort, run an enabled skill,

148or assign another shortcut. If you choose a keycap that's already used

114somewhere else, ChatGPT swaps the two instead of using one keycap twice.149somewhere else, ChatGPT swaps the two instead of using one keycap twice.

115 150 

116After you remap a key, swap the physical keycap to match its new action.151After you remap a key, swap the physical keycap to match its new action.

152Select **Reset layout** to restore the default Command Key and analog stick

153assignments without changing the Agent Key mode or custom chat assignments.

117 154 

118 155

119 156 


132actions. Codex Micro starts with the mappings shown here.169actions. Codex Micro starts with the mappings shown here.

133 170 

134Choose any available ChatGPT desktop command or enabled skill for each171Choose any available ChatGPT desktop command or enabled skill for each

135direction in **Settings > Codex Micro**.172direction in the device settings.

136 173 

137 174

138 175 


151 188 

152 189 

153 190 

154The dial moves through the composer controls and options, with **Reasoning**191The dial uses **Composer navigation** by default. Turn it to move through

155selected by default. Turn the dial to change the selection, then press it to192composer controls and options, then press it to open or select the focused

156open or select the focused control. When a composer control or menu is open,193control. When a composer control or menu is open, the Agent Key immediately to

157the Agent Key immediately to the right of the dial lights red. Press that key194the right of the dial lights red. Press that key to cancel.

158to cancel.195 

196Choose one of four dial modes in the device settings:

197 

198| Mode | Behavior |

199| -------------------------- | ------------------------------------------------------------------------------ |

200| **Composer navigation** | Move through composer controls and select the focused control. |

201| **Reasoning only** | Adjust reasoning effort and open its slider or advanced options. |

202| **Conversation scrolling** | Scroll the active chat; press the dial to jump to the latest message. |

203| **Custom assignments** | Assign an action or skill to the left turn, right turn, press, and long press. |

159 204 

160In **Settings > Codex Micro**, choose whether the dial uses **Composer205Pressing and holding the dial opens the device settings in every mode except

161navigation** or **Reasoning only**. In **Reasoning only** mode, turning the dial206**Custom assignments**, where it runs the action assigned to the long press.

162opens and adjusts reasoning effort. Press the dial to open the slider or its

163advanced options.

164 207 

165## Adjust lighting208## Adjust lighting

166 209 

167In **Settings > Codex Micro**, adjust the brightness and choose how long the210{/* vale Microsoft.Auto = NO */}

168lights stay on when you're not using Codex Micro. They come back on when you

169use the keyboard or an Agent Key changes status. By default, the lights turn

170off after three minutes.

171 211 

172When the keyboard reports its battery status, you can see it in **Settings >212In the device settings, adjust **Brightness** and choose an **Auto-dim**

173Codex Micro** and in the Codex Micro icon's sidebar tooltip.213interval from 30 seconds to one hour, or turn automatic dimming off. The lights

214come back on when you use the Micro or an Agent Key changes status. By default,

215the lights turn off after three minutes.

216 

217{/* vale Microsoft.Auto = YES */}

218 

219When the Micro reports its battery status, you can see it in the device settings

220and beside the Micro icon in the sidebar.

174 221 

175## Add more layers222## Add more layers

176 223 

177Codex uses layer 1. Use [Work Louder224ChatGPT uses layer 1. Use [Work Louder

178Input](https://worklouder.cc/micro-setup) to configure up to five more layers225Input](https://worklouder.cc/micro-setup) to configure up to five more layers

179with shortcuts and actions for other apps.226with shortcuts and actions for other apps.

180 227 

181## Troubleshoot Codex Micro228## Troubleshoot Codex Micro

182 229 

183### Pair the keyboard again

184 

185Use the bottom-left touch control to start pairing again. The rear button

186controls power and doesn't start pairing.

187 

1881. Hold the bottom-left touch control for three seconds to enter communication

189 mode.

1902. Tap the control to choose Bluetooth channel 1, 2, or 3.

1913. Hold the control for three seconds on that channel. The channel light flashes

192 while pairing and turns solid when paired.

193 

194### Fix Input Monitoring on macOS230### Fix Input Monitoring on macOS

195 231 

196If **Settings > Codex Micro** shows that Input Monitoring isn't set up, select232If the device settings show that Input Monitoring isn't set up, select **Open

197**Open System Settings**, then follow these steps:233System Settings**, then follow these steps:

198 234 

1991. Open **System Settings > Privacy & Security > Input Monitoring**.2351. Open **System Settings > Privacy & Security > Input Monitoring**.

2002. Turn on access for ChatGPT if it's already listed. If it's missing, drag2362. Turn on access for ChatGPT if it's already listed. If it's missing, drag

201 **ChatGPT** from Applications into the list, or select **Add (+)** and choose237 **ChatGPT** from Applications into the list, or select **Add (+)** and choose

202 **ChatGPT**.238 **ChatGPT**.

2033. Quit and reopen ChatGPT, then confirm ChatGPT detects Codex Micro on layer 1.2393. Quit and reopen ChatGPT, then confirm it detects the Micro on layer 1.

204 240 

205For more about this macOS permission, see [Apple's Input Monitoring241For more about this macOS permission, see [Apple's Input Monitoring

206guide](https://support.apple.com/guide/mac-help/mchl4cedafb6/mac).242guide](https://support.apple.com/guide/mac-help/mchl4cedafb6/mac).

207 243 

208### Get more Work Louder help244### Fix connection interference

245 

246ChatGPT retries automatically when it detects a Micro but can't connect or loses

247communication. If the problem continues, reconnect the Micro and check whether

248a keyboard utility or security tool blocks access to it.

209 249 

210For help with Bluetooth, cables, power, or resetting the keyboard, see250{/* vale Vale.Spelling = NO */}

211the [Creator Micro 2 setup guide from Work Louder](https://worklouder.cc/micro-setup).

212For direct support, email [hello@worklouder.cc](mailto:hello@worklouder.cc).

213 251 

214## Get Codex Micro252On macOS, Work Louder notes that Karabiner and Logitech Options+ can interfere

253with Micro communication when those apps have Input Monitoring permission. To

254test for interference, quit the keyboard utility or temporarily turn off its

255Input Monitoring access, then reconnect the Micro. If your organization manages

256your computer, ask your IT administrator to check the device rules.

215 257 

216You can buy Codex Micro through [OpenAI Supply258{/* vale Vale.Spelling = YES */}

217Co](https://openai.com/supply/co-lab/work-louder/) while supplies last.259 

260### Get more Work Louder help

218 261 

219{/* vale Microsoft.We = NO */}262For help with Bluetooth, cables, power, or resetting the keyboard, see the [Work

220{/* vale write-good.TooWordy = NO */}263Louder Codex Micro setup guide](https://worklouder.cc/openai-micro-setup). For

264direct support, email

265[hello@worklouder.cc](mailto:hello@worklouder.cc).

221 266 

222We expect orders to begin shipping shortly after purchase.267## Get a compatible Micro

223 268 

224{/* vale Microsoft.We = YES */}269Check Codex Micro availability through [OpenAI Supply

225{/* vale write-good.TooWordy = YES */}270Co](https://openai.com/supply/co-lab/work-louder/). The ChatGPT desktop app also

271supports [Creator Micro 2](https://worklouder.cc/creator-micro-2), available

272directly from Work Louder.

security.md +28 −6

Details

17For a prescriptive first local scan, start with the [Codex Security plugin17For a prescriptive first local scan, start with the [Codex Security plugin

18quickstart](https://learn.chatgpt.com/docs/security/plugin).18quickstart](https://learn.chatgpt.com/docs/security/plugin).

19 19 

20## Use Codex Security in the desktop app

21 

22Install and enable the Codex Security plugin to open **Security** in the

23desktop-app sidebar. The Security workbench keeps your scans, findings, and

24repositories in one place while Codex runs each scan in a task.

25 

26- Use **Scans** to start scans, follow their progress, and review saved results.

27- Use **Findings** to inspect issues and evidence across completed scans.

28- Use **Repositories** to review repository history and open findings.

29 

30See [Use the Security workbench](https://learn.chatgpt.com/docs/security/plugin/workbench) for the

31complete desktop-app workflow.

32 

20### Explore plugin use cases33### Explore plugin use cases

21 34 

22- [Run a security scan](https://learn.chatgpt.com/docs/security/plugin/scans) for a repository or one scoped folder.35- [Run a security scan](https://learn.chatgpt.com/docs/security/plugin/scans) for a repository or one scoped folder.


29- [Propose security hardening](https://learn.chatgpt.com/docs/security/plugin/security-hardening) from scan results or other security evidence.42- [Propose security hardening](https://learn.chatgpt.com/docs/security/plugin/security-hardening) from scan results or other security evidence.

30- [See what's new](https://learn.chatgpt.com/docs/security/plugin/changelog) in the Codex Security plugin.43- [See what's new](https://learn.chatgpt.com/docs/security/plugin/changelog) in the Codex Security plugin.

31 44 

32The plugin runs in your Codex chat. Codex Security cloud scans connected45The desktop Security workbench and Codex CLI use the Codex Security plugin.

33 GitHub repositories through Codex cloud. For Codex sandboxing, approvals,46 Codex Security cloud scans connected GitHub repositories through Codex cloud.

34 network controls, and admin settings, see [Agent approvals &47 For Codex sandboxing, approvals, network controls, and admin settings, see

35 security](https://learn.chatgpt.com/docs/agent-approvals-security).48 [Agent approvals & security](https://learn.chatgpt.com/docs/agent-approvals-security).

36 49 

37## Codex Security CLI and SDK50## Codex Security CLI and SDK

38 51 

39The Codex Security CLI and SDK are in limited beta and available only to52The CLI and TypeScript SDK are available as the public

40approved customers and partners. Contact your account team for access.53[`@openai/codex-security`](https://github.com/openai/codex-security) package.

54Install the package:

55 

56```bash

57npm install @openai/codex-security

58```

59 

60Running scans requires Codex Security access. For best results, use an account

61verified for [Trusted Access for Cyber](https://chatgpt.com/cyber).

41 62 

42Use the same scanner as the plugin across repositories and over time. The CLI63Use the same scanner as the plugin across repositories and over time. The CLI

43discovers GitHub repositories, resumes bulk scans, tracks findings across64discovers GitHub repositories, resumes bulk scans, tracks findings across


90## Related docs111## Related docs

91 112 

92- [Codex Security plugin quickstart](https://learn.chatgpt.com/docs/security/plugin) walks through installation and a first local scan.113- [Codex Security plugin quickstart](https://learn.chatgpt.com/docs/security/plugin) walks through installation and a first local scan.

114- [Security workbench](https://learn.chatgpt.com/docs/security/plugin/workbench) explains saved scans, findings, repositories, and scan activity in the desktop app.

93- [Codex Security CLI quickstart](https://learn.chatgpt.com/docs/security/cli) walks through setup, preflight, and a first terminal scan.115- [Codex Security CLI quickstart](https://learn.chatgpt.com/docs/security/cli) walks through setup, preflight, and a first terminal scan.

94- [Run bulk security scans](https://learn.chatgpt.com/docs/security/cli/bulk-scans) explains GitHub discovery, CSV inventories, campaign results, and resume behavior.116- [Run bulk security scans](https://learn.chatgpt.com/docs/security/cli/bulk-scans) explains GitHub discovery, CSV inventories, campaign results, and resume behavior.

95- [Codex Security CLI FAQ](https://learn.chatgpt.com/docs/security/cli/faq) answers common questions about scans, findings, coverage, and costs.117- [Codex Security CLI FAQ](https://learn.chatgpt.com/docs/security/cli/faq) answers common questions about scans, findings, coverage, and costs.

security/cli.md +67 −25

Details

7repositories you own or have permission to assess, review findings over time,7repositories you own or have permission to assess, review findings over time,

8and check changes before they land.8and check changes before they land.

9 9 

10The Codex Security CLI and SDK are in beta and require access. Follow the10The `@openai/codex-security` package is public. Running scans requires Codex

11 installation instructions provided with your access. For an interactive scan11 Security access. For an interactive scan in Codex, start with the [Codex

12 in Codex, start with the [Codex Security plugin12 Security plugin quickstart](https://learn.chatgpt.com/docs/security/plugin). For connected GitHub

13 quickstart](https://learn.chatgpt.com/docs/security/plugin). For connected GitHub repositories, see13 repositories, see [Codex Security cloud setup](https://learn.chatgpt.com/docs/security/setup).

14 [Codex Security cloud setup](https://learn.chatgpt.com/docs/security/setup).

15 14 

16## Check the prerequisites15## Check the prerequisites

17 16 


21 20 

22## Set up and verify the CLI21## Set up and verify the CLI

23 22 

24Follow the installation instructions provided for your Codex Security access.23Install the published package:

24 

25```bash

26npm install @openai/codex-security

27```

28 

25Check the installed version:29Check the installed version:

26 30 

27```bash31```bash


34npx @openai/codex-security --help38npx @openai/codex-security --help

35```39```

36 40 

37Use `npx @openai/codex-security scan --help` or `npx @openai/codex-security export --help` for the41Use `npx @openai/codex-security scan --help` or

38complete command help. The [CLI reference](https://learn.chatgpt.com/docs/security/cli/reference)42`npx @openai/codex-security export --help` for complete command help. The

39covers each argument, output format, and exit code.43[CLI reference](https://learn.chatgpt.com/docs/security/cli/reference) covers each argument, output

44format, and exit code.

40 45 

41## Sign in46## Sign in

42 47 


52npx @openai/codex-security login --device-auth57npx @openai/codex-security login --device-auth

53```58```

54 59 

55For CI and other automated workflows, use an OpenAI API key instead:60For CI and other automated workflows, set an OpenAI API key:

56 61 

57```bash62```bash

58export OPENAI_API_KEY="<your-api-key>"63export OPENAI_API_KEY="<your-api-key>"

59```64```

60 65 

61Keep API keys in your shell or secret manager. Codex Security can also reuse an66Keep API keys in your shell or secret manager. Codex Security can also reuse an

62existing file-backed Codex sign-in.67existing file-backed Codex sign-in. When both a stored ChatGPT sign-in and an

68environment API key are available, interactive scans with text output ask

69which to use. CI, JSON and JSONL scans, and other unattended scans use the

70API key by default.

63 71 

64If a ChatGPT sign-in and `OPENAI_API_KEY` or `CODEX_API_KEY` are both72To use your ChatGPT sign-in when an API key is also set, select it explicitly:

65available, interactive scans with text output ask which credential to use. CI,

66JSON and JSONL scans, and other scans without an interactive terminal use the

67environment API key by default. Dry runs don't prompt or load credentials.

68 

69To use your stored sign-in for a scan, pass `--auth chatgpt`:

70 73 

71```bash74```bash

72npx @openai/codex-security scan . --auth chatgpt75npx @openai/codex-security scan . --auth chatgpt

73```76```

74 77 

75To use an environment API key, pass `--auth api-key`:78To require the environment API key, select API-key authentication:

76 79 

77```bash80```bash

78npx @openai/codex-security scan . --auth api-key81npx @openai/codex-security scan . --auth api-key


102state directory. Results can include source excerpts and vulnerability details,105state directory. Results can include source excerpts and vulnerability details,

103so choose a private location and an appropriate retention policy.106so choose a private location and an appropriate retention policy.

104 107 

108If the default state directory isn't writable, select a writable directory

109outside the scanned repository:

110 

111```bash

112export CODEX_SECURITY_STATE_DIR=/path/outside/repository/codex-security-state

113```

114 

105Check the repository, target, and output directory before starting a scan:115Check the repository, target, and output directory before starting a scan:

106 116 

107```bash117```bash


119npx @openai/codex-security scan "$REPOSITORY" --output-dir "$SCAN_DIR"129npx @openai/codex-security scan "$REPOSITORY" --output-dir "$SCAN_DIR"

120```130```

121 131 

122The CLI writes the scan result to stdout and sends progress and its completion132By default, the CLI writes scan progress and its completion summary to stderr.

123summary to stderr. A completed scan prints a summary like this:133It doesn't print the full scan result to stdout. A completed scan prints a

134summary like this:

124 135 

125```text136```text

126codex-security: Findings: 2 (1 high, 1 medium). Coverage: complete.137codex-security: Findings: 2 (1 high, 1 medium). Coverage: complete.

127codex-security: Elapsed: 42s. Workers: 3/6.138codex-security: Elapsed: 42s.

139codex-security: Report: /path/outside/repository/codex-security-results/report.md

128codex-security: Results: /path/outside/repository/codex-security-results140codex-security: Results: /path/outside/repository/codex-security-results

129codex-security: Next: codex-security export /path/outside/repository/codex-security-results --export-format sarif

130```141```

131 142 

132For a local package installation, run the suggested export command with143Token usage and estimated cost appear when available. To print the complete

133`npx @openai/codex-security`.144result as machine-readable JSON, request structured output explicitly:

145 

146```bash

147npx @openai/codex-security scan "$REPOSITORY" --output-dir "$SCAN_DIR" --json

148```

134 149 

135Scans are report-only by default, so findings remain available for local150Scans are report-only by default, so findings remain available for local

136review. You may want to add a severity threshold when you are ready to [run scans in151review. You may want to add a severity threshold when you are ready to [run scans in

137CI](https://learn.chatgpt.com/docs/security/cli/ci).152CI](https://learn.chatgpt.com/docs/security/cli/ci).

138 153 

154## Choose a model and reasoning effort

155 

156Scans use `gpt-5.6-sol` with `xhigh` reasoning effort by default. Select a

157different model and effort when the task requires them:

158 

159```bash

160npx @openai/codex-security scan "$REPOSITORY" \

161 --model gpt-5.6-terra \

162 --effort high

163```

164 

165Supported effort levels are `minimal`, `low`, `medium`, `high`, and `xhigh`.

166 

139## Review the results167## Review the results

140 168 

141Open `report.md` for the readable result. The scan directory also contains the169Open `report.md` for the readable result. The scan directory also contains the


169Use a path scan when a repository contains separate services or packages:197Use a path scan when a repository contains separate services or packages:

170 198 

171```bash199```bash

172npx @openai/codex-security scan "$REPOSITORY" --path services/billing --path packages/auth200npx @openai/codex-security scan "$REPOSITORY" \

201 --path services/billing \

202 --path packages/auth

173```203```

174 204 

175Review committed changes between the base revision and `HEAD`:205Review committed changes between the base revision and `HEAD`:


193npx @openai/codex-security scan "$REPOSITORY" --mode deep223npx @openai/codex-security scan "$REPOSITORY" --mode deep

194```224```

195 225 

226Deep mode supports repository and path targets, not diff or working-tree scans.

227 

196## Add architecture and security context228## Add architecture and security context

197 229 

198Provide architecture documents, threat models, or security policies as scan230Provide architecture documents, threat models, or security policies as scan


296npx @openai/codex-security scans show SCAN_ID328npx @openai/codex-security scans show SCAN_ID

297```329```

298 330 

331To mark a reviewed finding as a false positive, explain why the finding doesn't

332apply:

333 

334```bash

335npx @openai/codex-security findings false-positive FINDING_OCCURRENCE_ID \

336 --reason "The route already checks permissions"

337```

338 

339Later scans consider that explanation but still recheck the current code.

340 

299Run the same scan against the current checkout using its original configuration:341Run the same scan against the current checkout using its original configuration:

300 342 

301```bash343```bash

Details

2 2 

3> For the complete documentation index, see [llms.txt](https://learn.chatgpt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to the page URL.3> For the complete documentation index, see [llms.txt](https://learn.chatgpt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to the page URL.

4 4 

5Use `codex-security bulk-scan` to review repositories in one5Use `npx @openai/codex-security bulk-scan` to review repositories in one

6campaign. Discover repositories from a GitHub account or organization, or6campaign. Discover repositories from your personal GitHub account or an

7provide a CSV that pins every repository to an exact Git revision.7organization, or provide a CSV that pins every repository to an exact Git

8revision.

8 9 

9The Codex Security CLI is in beta and requires access. Follow the [CLI10The `@openai/codex-security` package is public. Running scans requires Codex

10 quickstart](https://learn.chatgpt.com/docs/security/cli) to install the CLI and sign in before11 Security access. Follow the [CLI quickstart](https://learn.chatgpt.com/docs/security/cli) to install

11 starting a bulk scan.12 the CLI and sign in.

12 13 

13## Choose a repository source14## Choose a repository source

14 15 

15| Source | When to use it |16| Source | When to use it |

16| ---------------- | ------------------------------------------------------------------------ |17| ---------------- | --------------------------------------------------------------------------------------- |

17| GitHub discovery | Choose repositories interactively from a GitHub account or organization. |18| GitHub discovery | Choose repositories interactively from your personal GitHub account or an organization. |

18| CSV inventory | Run a repeatable, automated campaign against exact repository revisions. |19| CSV inventory | Run a repeatable, automated campaign against exact repository revisions. |

19 20 

20Both workflows save progress, preserve per-repository results, and let you21Both workflows save progress, preserve per-repository results, and let you


36 37 

37The CLI guides you through these steps:38The CLI guides you through these steps:

38 39 

391. Choose a GitHub account or organization.401. Choose your personal GitHub account or an organization.

402. Review repositories active within the last 90 days.412. Review repositories active within the last 90 days.

413. Search the repository list and select repositories to scan.423. Search the repository list and select repositories to scan.

424. Choose a directory for scan results.434. Choose a directory for scan results.


107complete only when its scan has complete coverage and all required result108complete only when its scan has complete coverage and all required result

108artifacts exist.109artifacts exist.

109 110 

111## Choose a model and reasoning effort

112 

113Bulk scans use `gpt-5.6-sol` with `xhigh` reasoning effort by default. To

114choose another model and effort for a CSV campaign:

115 

116```bash

117npx @openai/codex-security bulk-scan repositories.csv \

118 --output-dir /path/outside/repositories/security-scans \

119 --workers 4 \

120 --model gpt-5.6-terra \

121 --effort high

122```

123 

124The same options work during interactive repository discovery:

125 

126```bash

127npx @openai/codex-security bulk-scan --model gpt-5.6-terra --effort high

128```

129 

130Supported effort levels are `minimal`, `low`, `medium`, `high`, and `xhigh`.

131 

110## Review campaign results132## Review campaign results

111 133 

112The output directory contains the pinned campaign, an append-only results134The output directory contains the pinned campaign, an append-only results

security/cli/ci.md +19 −29

Details

7severity. Start with advisory results, review scan quality and runtime, then7severity. Start with advisory results, review scan quality and runtime, then

8add a severity policy that fits your repository.8add a severity policy that fits your repository.

9 9 

10The Codex Security CLI is in beta and requires access. Follow the installation10Install the public `@openai/codex-security` package. Running scans still

11 instructions provided with your access.11 requires Codex Security access.

12 12 

13This guide uses GitHub Actions. The same scan and export commands work in other13This guide uses GitHub Actions. The same scan and export commands work in other

14CI systems.14CI systems.


18Store an OpenAI API key as a repository or organization secret named18Store an OpenAI API key as a repository or organization secret named

19`CODEX_SECURITY_API_KEY`.19`CODEX_SECURITY_API_KEY`.

20 20 

21Map this secret directly to the scan step's `CODEX_API_KEY` environment21Map this secret directly to the scan step's `OPENAI_API_KEY` environment

22variable. Keep the credential scoped to that variable within the scan process.22variable. Keep the credential scoped to the scan process and use

23 23`--auth api-key` to select it explicitly.

24Set the `CODEX_SECURITY_PACKAGE` repository or organization variable to an

25approved package source provided with your access, such as a trusted archive

26location or registry package specification. The source must be available to

27the runner before it checks out the repository.

28 24 

29The runner needs:25The runner needs:

30 26 

31- Node.js 22 or later.27- Node.js 22 or later.

32- Python 3.10 or later.28- Python 3.10 or later.

33- The Codex Security CLI, installed outside the repository checkout using the29- The published `@openai/codex-security` package, installed outside the

34 instructions provided with your access.30 repository checkout.

35- The pull-request head and base history so Git can calculate the merge base.31- The pull-request head and base history so Git can calculate the merge base.

36- [GitHub Code Security](https://docs.github.com/en/code-security/code-scanning/integrating-with-code-scanning/uploading-a-sarif-file-to-github)32- [GitHub Code Security](https://docs.github.com/en/code-security/code-scanning/integrating-with-code-scanning/uploading-a-sarif-file-to-github)

37 enabled for private or internal repositories when you upload SARIF.33 enabled for private or internal repositories when you upload SARIF.

38 34 

39The example skips pull requests from forks and Dependabot. These workflows

40 don't receive normal Actions secrets, and Dependabot receives a read-only

41 `GITHUB_TOKEN` by default. Keep scan credentials available only to trusted

42 workflows.

43 

44## Add the GitHub Actions workflow35## Add the GitHub Actions workflow

45 36 

46Create `.github/workflows/codex-security.yml`. Before checking out the pull37Create `.github/workflows/codex-security.yml`. Before checking out the pull

47request, install the approved package under `$RUNNER_TEMP/codex-security` so38request, install `@openai/codex-security@0.1.3` under

48the trusted executable is available at39`$RUNNER_TEMP/codex-security` so the trusted executable is available at

49`$RUNNER_TEMP/codex-security/node_modules/.bin/codex-security`:40`$RUNNER_TEMP/codex-security/node_modules/.bin/codex-security`:

50 41 

51```yaml42```yaml


74 python-version: "3.14"65 python-version: "3.14"

75 66 

76 - name: Install Codex Security67 - name: Install Codex Security

77 env:

78 CODEX_SECURITY_PACKAGE: ${{ vars.CODEX_SECURITY_PACKAGE }}

79 run: |68 run: |

80 set -euo pipefail69 set -euo pipefail

81 if test -z "$CODEX_SECURITY_PACKAGE"; then

82 echo "Set the CODEX_SECURITY_PACKAGE repository or organization variable." >&2

83 exit 1

84 fi

85 npm install \70 npm install \

86 --prefix "$RUNNER_TEMP/codex-security" \71 --prefix "$RUNNER_TEMP/codex-security" \

87 --ignore-scripts \72 --ignore-scripts \

88 --no-audit \73 --no-audit \

89 --no-fund \74 --no-fund \

90 "$CODEX_SECURITY_PACKAGE"75 @openai/codex-security@0.1.3

91 76 

92 - name: Verify Codex Security77 - name: Verify Codex Security

93 env:78 env:


106 91 

107 - name: Scan the pull request92 - name: Scan the pull request

108 env:93 env:

109 CODEX_API_KEY: ${{ secrets.CODEX_SECURITY_API_KEY }}94 OPENAI_API_KEY: ${{ secrets.CODEX_SECURITY_API_KEY }}

110 CODEX_SECURITY_BIN: ${{ runner.temp }}/codex-security/node_modules/.bin/codex-security95 CODEX_SECURITY_BIN: ${{ runner.temp }}/codex-security/node_modules/.bin/codex-security

96 CODEX_SECURITY_STATE_DIR: ${{ runner.temp }}/codex-security-state

111 BASE_SHA: ${{ github.event.pull_request.base.sha }}97 BASE_SHA: ${{ github.event.pull_request.base.sha }}

112 HEAD_SHA: ${{ github.event.pull_request.head.sha }}98 HEAD_SHA: ${{ github.event.pull_request.head.sha }}

113 SCAN_DIR: ${{ runner.temp }}/codex-security-results99 SCAN_DIR: ${{ runner.temp }}/codex-security-results


117 "$CODEX_SECURITY_BIN" scan . \103 "$CODEX_SECURITY_BIN" scan . \

118 --diff "$BASE_REVISION" \104 --diff "$BASE_REVISION" \

119 --head "$HEAD_SHA" \105 --head "$HEAD_SHA" \

106 --auth api-key \

120 --output-dir "$SCAN_DIR" \107 --output-dir "$SCAN_DIR" \

121 --json > "$RUNNER_TEMP/codex-security.json"108 --json > "$RUNNER_TEMP/codex-security.json"

122 109 


163target exact. `persist-credentials: false` keeps the repository token out of150target exact. `persist-credentials: false` keeps the repository token out of

164the checked-out Git configuration. Installing the CLI before checkout and151the checked-out Git configuration. Installing the CLI before checkout and

165running its absolute path keeps repository-controlled executables away from152running its absolute path keeps repository-controlled executables away from

166the scan credential. Pinning each action to a verified commit prevents an153the scan credential. `--auth api-key` explicitly selects the scoped API key.

167upstream tag change from changing the workflow.154The scan saves its history in a writable state directory outside the

155repository.

168 156 

169`--json` writes one complete JSON document to stdout, so the workflow can save157`--json` writes one complete JSON document to stdout, so the workflow can save

170it directly. Progress, completion summaries, and errors remain on stderr. This158it directly. Progress, completion summaries, and errors remain on stderr. This


228 directory already contains results.216 directory already contains results.

229- **Missing credentials:** Confirm the `CODEX_SECURITY_API_KEY` repository217- **Missing credentials:** Confirm the `CODEX_SECURITY_API_KEY` repository

230 secret is available to the trusted workflow and mapped directly to the scan218 secret is available to the trusted workflow and mapped directly to the scan

231 step's `CODEX_API_KEY` environment variable.219 step's `OPENAI_API_KEY` environment variable.

220- **Scan history error:** Set `CODEX_SECURITY_STATE_DIR` to a writable

221 directory outside the repository.

232- **Python setup error:** Confirm that the runner uses Python 3.10 or later.222- **Python setup error:** Confirm that the runner uses Python 3.10 or later.

233- **Incomplete coverage:** Review `coverage.json`, including deferred surfaces223- **Incomplete coverage:** Review `coverage.json`, including deferred surfaces

234 and open questions, then rerun with an appropriate target or environment.224 and open questions, then rerun with an appropriate target or environment.

Details

10 10 

11### Who can use the CLI11### Who can use the CLI

12 12 

13The Codex Security CLI and SDK are in limited beta. Approved customers and13The `@openai/codex-security` package is public. Install the CLI and SDK:

14partners receive installation instructions with their access. Contact your14 

15account team if you need access.15```bash

16npm install @openai/codex-security

17```

18 

19Running scans requires Codex Security access. For best results, use an account

20verified for [Trusted Access for Cyber](https://chatgpt.com/cyber).

16 21 

17### Why does a scan use an API key after sign-in22### Why does a scan use an API key after sign-in

18 23 


28npx @openai/codex-security scan . --auth chatgpt33npx @openai/codex-security scan . --auth chatgpt

29```34```

30 35 

36To require an API key from `OPENAI_API_KEY` or `CODEX_API_KEY`:

37 

38```bash

39npx @openai/codex-security scan . --auth api-key

40```

41 

31To make your stored credentials the automatic default, run42To make your stored credentials the automatic default, run

32`unset OPENAI_API_KEY CODEX_API_KEY`. For all supported authentication modes,43`unset OPENAI_API_KEY CODEX_API_KEY`. For all supported authentication modes,

33see the [CLI reference](https://learn.chatgpt.com/docs/security/cli/reference#select-scan-authentication).44see the [CLI reference](https://learn.chatgpt.com/docs/security/cli/reference#select-scan-authentication).


107artifacts together. See [Scan118artifacts together. See [Scan

108artifacts](https://learn.chatgpt.com/docs/security/cli/reference#scan-artifacts) for the full layout.119artifacts](https://learn.chatgpt.com/docs/security/cli/reference#scan-artifacts) for the full layout.

109 120 

121### What if the CLI can't save scan history

122 

123Codex Security keeps scan history in a workbench database. If the default

124state directory isn't writable, choose a private directory outside the

125repository:

126 

127```bash

128export CODEX_SECURITY_STATE_DIR=/path/outside/repository/codex-security-state

129```

130 

110### How do scans distinguish new and known findings131### How do scans distinguish new and known findings

111 132 

112Match findings that share a root cause across the two scans:133Match findings that share a root cause across the two scans:


136Record why that finding doesn't apply:157Record why that finding doesn't apply:

137 158 

138```bash159```bash

139npx @openai/codex-security findings mark-false-positive FINDING_OCCURRENCE_ID \160npx @openai/codex-security findings false-positive FINDING_OCCURRENCE_ID \

140 --reason "The framework escapes this input before it reaches the query"161 --reason "The framework escapes this input before it reaches the query"

141```162```

142 163 

Details

6output formats, and exit behavior. For a guided first scan, start with the6output formats, and exit behavior. For a guided first scan, start with the

7[CLI quickstart](https://learn.chatgpt.com/docs/security/cli).7[CLI quickstart](https://learn.chatgpt.com/docs/security/cli).

8 8 

9The Codex Security CLI is in beta and requires access. Follow the installation9The `@openai/codex-security` package is public. Running scans requires Codex

10 instructions provided with your access.10 Security access.

11 11 

12When you install the package in a local project, invoke the executable as12Install the published package in your project:

13`npx @openai/codex-security`. Use `codex-security` directly when the executable is13 

14available on your `PATH`.14```bash

15npm install @openai/codex-security

16```

17 

18Invoke the installed package as `npx @openai/codex-security`. You can use

19`codex-security` directly when the executable is available on your `PATH`.

15 20 

16## Command overview21## Command overview

17 22 


107working tree.112working tree.

108 113 

109```text114```text

110usage: codex-security scan [-h] [--path PATH | --diff BASE | --working-tree]115usage: codex-security scan [-h] [--auth {auto,chatgpt,api-key}]

116 [--path PATH | --diff BASE | --working-tree]

111 [--head HEAD] [--base BASE]117 [--head HEAD] [--base BASE]

112 [--auth {auto,chatgpt,api-key}]

113 [--knowledge-base PATH]118 [--knowledge-base PATH]

114 [--mode {standard,deep}] [--model MODEL]119 [--mode {standard,deep}] [--model MODEL]

120 [--effort {minimal,low,medium,high,xhigh}]

115 [--output-dir DIR]121 [--output-dir DIR]

116 [--archive-existing]122 [--archive-existing]

117 [--plugin-path PATH] [--python PATH]123 [--plugin-path PATH] [--python PATH]

118 [--codex KEY=VALUE] [--fail-on-severity LEVEL]124 [--codex KEY=VALUE] [--fail-on-severity LEVEL]

119 [--max-cost USD] [--dry-run] [--json] [repository]125 [--max-cost USD] [--dry-run]

126 [--json] [--format {toon,json,yaml,jsonl}]

127 [--full-output] [repository]

120```128```

121 129 

122`repository` defaults to the current directory.130`repository` defaults to the current directory.


223| `--max-cost USD` | Stop a scan when its estimated model cost exceeds the specified USD amount. |231| `--max-cost USD` | Stop a scan when its estimated model cost exceeds the specified USD amount. |

224| `--dry-run` | Check the repository, target, output directory, and Codex configuration without starting a scan. |232| `--dry-run` | Check the repository, target, output directory, and Codex configuration without starting a scan. |

225| `--json` | Print manifest, findings, coverage, paths, and turn metadata as one JSON document. |233| `--json` | Print manifest, findings, coverage, paths, and turn metadata as one JSON document. |

234| `--format FORMAT` | Print the complete scan result as `toon`, `json`, `yaml`, or `jsonl`. |

235| `--full-output` | Print the complete result using the default structured output format. |

226 236 

227The cost limit is an estimate, not a hard spending cap. Requests already in237The cost limit is an estimate, not a hard spending cap. Requests already in

228progress can finish above the limit, and partial scan results remain available.238progress can finish above the limit, and partial scan results remain available.


234contain source excerpts and vulnerability details, so manage their permissions244contain source excerpts and vulnerability details, so manage their permissions

235and retention accordingly.245and retention accordingly.

236 246 

237The output directory can be new or empty. On macOS and Linux, an existing247The workbench keeps scan history in

238directory must be private to the current user. A scan can replace an existing248`$CODEX_HOME/state/plugins/codex-security/workbench.sqlite3`. Setting

239result directory with `--archive-existing`.249`CODEX_SECURITY_STATE_DIR` also moves the workbench database.

250 

251The output directory must be outside the scanned directory and any enclosing

252Git worktree. A scan can replace an existing result directory with

253`--archive-existing`.

254 

255To preserve earlier results before reusing an output directory:

240 256 

241```bash257```bash

242npx @openai/codex-security scan . \258npx @openai/codex-security scan . \


260probing the plugin's Python interpreter:276probing the plugin's Python interpreter:

261 277 

262```bash278```bash

263npx @openai/codex-security scan . --output-dir /path/outside/repository/results --dry-run279npx @openai/codex-security scan . \

280 --output-dir /path/outside/repository/results \

281 --dry-run

264```282```

265 283 

266### Configure the runtime284### Configure the runtime


269Codex configuration value.287Codex configuration value.

270 288 

271| Argument | Description |289| Argument | Description |

272| -------------------- | -------------------------------------------------------------------------------------------------------- |290| ------------------------------------------ | -------------------------------------------------------------------------------------------------------- |

273| `--model MODEL` | Select the model for the scan. |291| `--auth {auto,chatgpt,api-key}` | Select the scan credentials. The default is `auto`. |

292| `--model MODEL` | Select the OpenAI model. The default is `gpt-5.6-sol`. |

293| `--effort {minimal,low,medium,high,xhigh}` | Select the model's reasoning effort. The default is `xhigh`. |

274| `--plugin-path PATH` | Use a Codex Security plugin directory or ZIP to override the bundled plugin. |294| `--plugin-path PATH` | Use a Codex Security plugin directory or ZIP to override the bundled plugin. |

275| `--python PATH` | Select the Python interpreter for the plugin runtime. |295| `--python PATH` | Select the Python interpreter for the plugin runtime. |

276| `--codex KEY=VALUE` | Override an isolated Codex configuration value. Values use TOML syntax. Repeat the flag for more values. |296| `--codex KEY=VALUE` | Override an isolated Codex configuration value. Values use TOML syntax. Repeat the flag for more values. |

277 297 

298To select a different model and reasoning effort without writing TOML:

299 

300```bash

301npx @openai/codex-security scan . --model gpt-5.6-terra --effort high

302```

303 

278Quote string values passed through `--codex` so the TOML parser receives a304Quote string values passed through `--codex` so the TOML parser receives a

279string:305string:

280 306 

281```bash307```bash

282npx @openai/codex-security scan . --codex 'model="<model>"'308npx @openai/codex-security scan . --codex 'model="gpt-5.6-terra"'

283```309```

284 310 

285Codex Security owns plugin-loading configuration and rejects conflicting

286overrides. Use `--plugin-path` to select a plugin.

287 

288## `codex-security install-hook`311## `codex-security install-hook`

289 312 

290Install a Git pre-commit security check for the current repository:313Install a Git pre-commit security check for the current repository:


314```text337```text

315usage: codex-security bulk-scan [input] [--output-dir DIR]338usage: codex-security bulk-scan [input] [--output-dir DIR]

316 [--workers N] [--mode {standard,deep}]339 [--workers N] [--mode {standard,deep}]

340 [--model MODEL]

341 [--effort {minimal,low,medium,high,xhigh}]

317 [--max-attempts N] [--plugin-path PATH]342 [--max-attempts N] [--plugin-path PATH]

318 [--python PATH] [--codex KEY=VALUE]343 [--python PATH] [--codex KEY=VALUE]

319```344```

320 345 

321Run `codex-security bulk-scan` without arguments or options to select346Run `npx @openai/codex-security bulk-scan` without arguments to select

322repositories interactively. This flow requires a GitHub CLI sign-in.347repositories interactively. This flow requires a GitHub CLI sign-in.

323 348 

349To choose a model and reasoning effort during interactive discovery:

350 

351```bash

352npx @openai/codex-security bulk-scan --model gpt-5.6-terra --effort high

353```

354 

324For a prepared repository list, provide a CSV and `--output-dir`:355For a prepared repository list, provide a CSV and `--output-dir`:

325 356 

326```bash357```bash


419Record a reviewed finding as a false positive:450Record a reviewed finding as a false positive:

420 451 

421```text452```text

422usage: codex-security findings mark-false-positive OCCURRENCE_ID453usage: codex-security findings false-positive OCCURRENCE_ID

423 --reason REASON454 --reason REASON

424```455```

425 456 


432Record a specific explanation for the false positive:463Record a specific explanation for the false positive:

433 464 

434```bash465```bash

435npx @openai/codex-security findings mark-false-positive FINDING_OCCURRENCE_ID \466npx @openai/codex-security findings false-positive FINDING_OCCURRENCE_ID \

436 --reason "The framework escapes this input before it reaches the query"467 --reason "The framework escapes this input before it reaches the query"

437```468```

438 469 


484Write SARIF to stdout:515Write SARIF to stdout:

485 516 

486```bash517```bash

487npx @openai/codex-security export /path/to/scan --export-format sarif --source-root . --output -518npx @openai/codex-security export /path/to/scan \

519 --export-format sarif \

520 --source-root . \

521 --output -

488```522```

489 523 

490Export findings as JSON:524Export findings as JSON:


508Check whether a candidate finding is valid:542Check whether a candidate finding is valid:

509 543 

510```bash544```bash

511npx @openai/codex-security validate findings.json "Possible SQL injection in src/query.ts:42"545npx @openai/codex-security validate findings.json \

546 "Possible SQL injection in src/query.ts:42"

512```547```

513 548 

514Generate a fix with the bundled remediation skill:549Generate a fix with the bundled remediation skill:

515 550 

516```bash551```bash

517npx @openai/codex-security patch findings.json "Missing authorization check in src/routes.ts:18"552npx @openai/codex-security patch findings.json \

553 "Missing authorization check in src/routes.ts:18"

518```554```

519 555 

520Each argument can contain literal text or point to a file. Both commands work556Each argument can contain literal text or point to a file. Both commands work


523comparison alone doesn't prove that a fix worked. External tools can use these559comparison alone doesn't prove that a fix worked. External tools can use these

524commands without rebuilding the scanner.560commands without rebuilding the scanner.

525 561 

562Use `--effort` to select reasoning effort for either command:

563 

564```bash

565npx @openai/codex-security validate "Possible SQL injection" --effort high

566```

567 

526## `codex-security login`, `logout`, and `info`568## `codex-security login`, `logout`, and `info`

527 569 

528Sign in interactively:570Sign in interactively:


572 614 

573## Read scan output615## Read scan output

574 616 

575The CLI writes structured command results to stdout and sends progress,617By default, scans send progress, completion summaries, and errors to stderr

576completion summaries, and errors to stderr. This lets terminal users read a618without writing the complete scan result to stdout. Request `--json`,

577summary while automation captures a clean JSON or SARIF document.619`--format`, or `--full-output` to send structured scan results to stdout.

578 620 

579### Completion summary621### Completion summary

580 622 

581A completed scan writes its finding count, severity breakdown, coverage,623A completed scan writes its finding count, severity breakdown, coverage,

582elapsed time, result directory, and next step to stderr. It includes worker624elapsed time, report path, and result directory to stderr. It includes token

583counts and token usage when available:625usage and estimated cost when available:

584 626 

585```text627```text

586codex-security: Findings: 4 (1 critical, 2 high, 1 informational). Coverage: complete.628codex-security: Findings: 4 (1 critical, 2 high, 1 informational). Coverage: complete.

587codex-security: Elapsed: 1s. Workers: 3/6.629codex-security: Elapsed: 1s.

588codex-security: Tokens: 1,250 input, 200 cached, 30 output.630codex-security: Tokens: 1,250 input, 200 cached, 30 output.

631codex-security: Report: /path/to/scan/report.md

589codex-security: Results: /path/to/scan632codex-security: Results: /path/to/scan

590codex-security: Next: codex-security export /path/to/scan --export-format sarif

591```633```

592 634 

593Informational findings count toward the summary total. Severity policies635Informational findings count toward the summary total. Severity policies


671| `143` | SIGTERM terminated a scan. |713| `143` | SIGTERM terminated a scan. |

672 714 

673Any scan with `partial` or `unknown` coverage returns `2`, even without a715Any scan with `partial` or `unknown` coverage returns `2`, even without a

674severity policy. Completed scans still write the available results to stdout.716severity policy. When you request structured output, completed scans still

675The CLI prints the location of any partial output after an interruption or717write the available results to stdout. The CLI prints the location of any

676runtime error.718partial output after an interruption or runtime error.

677 719 

678## Authentication and prerequisites720## Authentication and prerequisites

679 721 

680Set `OPENAI_API_KEY` or `CODEX_API_KEY`, sign in with `codex-security login`, or722Set `OPENAI_API_KEY` or `CODEX_API_KEY`, sign in with

681use an existing file-backed Codex sign-in. When a ChatGPT sign-in and an723`npx @openai/codex-security login`, or use an existing file-backed Codex

682environment API key are both available, interactive scans with text output ask724sign-in.

683which credential to use. CI, JSON and JSONL scans, and other scans without an725 

684interactive terminal use the environment API key by default. Dry runs don't726For credential selection, see [Select scan

685prompt or load credentials. Use `--auth` to select the credential explicitly.727authentication](#select-scan-authentication).

728 

686For CI, keep the API key scoped to the scan step and use a trusted workflow.729For CI, keep the API key scoped to the scan step and use a trusted workflow.

687 730 

688The CLI requires Node.js 22 or later. Running a scan or exporting findings also731The CLI requires Node.js 22 or later. Running a scan or exporting findings also

security/plugin.md +60 −57

Details

10Follow this quickstart to install the plugin and run a read-only scan of a local10Follow this quickstart to install the plugin and run a read-only scan of a local

11repository in Codex.11repository in Codex.

12 12 

13This page covers the plugin that runs in a local Codex chat. To scan a13This page covers the Codex Security plugin in the desktop app or Codex CLI. To

14 connected GitHub repository in Codex cloud, see [Codex Security cloud14 scan a connected GitHub repository in Codex cloud, see [Codex Security cloud

15 setup](https://learn.chatgpt.com/docs/security/setup).15 setup](https://learn.chatgpt.com/docs/security/setup).

16 16 

17## Install the plugin17## Install the plugin

18 18 

19<ContentModeSwitch group="codex-surface" id="app">19<ContentModeSwitch group="codex-surface" id="app">

20 20 

211. Open the repository you want to assess in Codex in the [ChatGPT desktop211. Open [Codex in the ChatGPT desktop app](https://learn.chatgpt.com/docs/app).

22 app](https://chatgpt.com/download/).

232. Open **Plugins**, search for **Codex Security**, or use the button below:222. Open **Plugins**, search for **Codex Security**, or use the button below:

24 23 

25 24


36 35

37 36 

38 37 

393. Start a new Codex chat for that repository. Don't continue an existing chat.383. Confirm the plugin is enabled, then open **Security** in the sidebar.

40 39 

41</ContentModeSwitch>40</ContentModeSwitch>

42 41 


56 55 

57 56 

58 57 

58The hosted desktop-app catalog and public Codex CLI marketplace can offer

59 different plugin versions. Check the [plugin

60 changelog](https://learn.chatgpt.com/docs/security/plugin/changelog) before you rely on a feature or

61 start a long-running scan. If **Security** doesn't appear in the desktop-app

62 sidebar, update the app and plugin and confirm that the plugin is enabled.

63 

59## Run your first scan64## Run your first scan

60 65 

61For the best scan quality, use `gpt-5.6-sol`66For the best scan quality, use `gpt-5.6-sol`


63 68 

64<ContentModeSwitch group="codex-surface" id="app">69<ContentModeSwitch group="codex-surface" id="app">

65 70 

66<VideoPlayer71<figure className="not-prose my-8">

67 src="/videos/codex/security/scan-setup-to-findings.mp4"72 <CodexScreenshot

68 poster="/videos/codex/security/scan-setup-to-findings-poster.webp"73 alt="Native Codex Security workbench showing the new scan setup before a repository scan starts"

69/>74 lightSrc={scanOverview.src}

75 darkSrc={scanOverviewDark.src}

76 maxHeight="520px"

77 />

78 <figcaption className="mt-3 text-sm text-secondary">

79 Choose a repository and configure a new security scan before you start it.

80 </figcaption>

81</figure>

70 82 

71<WorkflowSteps variant="headings">83<WorkflowSteps variant="headings">

72 84 

731. Ask for an ordinary scan851. Open the scan setup

74 86 

75 Send this prompt in the new chat:87 Select **Security** in the sidebar, open **Scans**, and select **+ Scan**.

76 88 

77```text892. Choose the codebase and scan area

78 Run a Codex Security scan on this repository.

79```

80 90 

812. Confirm the setup91 Select an existing repository or use another folder. Choose **Codebase**,

92 leave **Deep scan** off, and select the entire repository or one folder.

93 Confirm that the branch and revision identify the code you intended to scan.

82 94 

83 Codex opens a setup workspace before it starts. For your first run, use these953. Add relevant context

84 settings:

85 - **Scan type:** `Codebase`

86 - **Deep scan:** Off

87 - **Scan area:** `Entire codebase`

88 - **Threat model scoping guidance:** Leave blank unless you already know a

89 specific attack vector or application area that deserves priority.

90 96 

91 Confirm that **Codebase**, **Current branch**, and **Last commit** identify97 Choose the model and reasoning effort. Open **Additional context** only when

92 the repository you intended to scan. Then select **Start scan**.98 you need to describe a specific attack vector, security-sensitive area, or

99 repository detail that should guide the review.

93 100 

94 <figure className="not-prose my-6">101 <figure className="not-prose my-6">

95 102 <CodexScreenshot

96 103 alt="Native Codex Security scan setup with additional context enabled and example attack vectors, focus areas, and security guidance"

97 <img104 lightSrc={scanSetup.src}

98 src={scanSetup.src}105 darkSrc={scanSetupDark.src}

99 alt="Codex Security setup workspace configured to scan an entire codebase"106 maxHeight="460px"

100 className="block h-auto w-full"

101 />107 />

102

103 

104 <figcaption className="mt-3 text-sm text-secondary">108 <figcaption className="mt-3 text-sm text-secondary">

105 Configure the scan target, scan area, branch, and optional threat model109 Turn on additional context to describe attack vectors, focus areas, and

106 guidance before starting the scan.110 relevant security guidance.

107 </figcaption>111 </figcaption>

108 </figure>112 </figure>

109 113 

1103. Let the scan finish1144. Start the scan

111 115 

112 Keep the scan running until the workspace reports that it is complete. If116 Select **Start scan** and follow the scan phases in the Security workbench.

113 Codex identifies a configuration limitation, review the limitation and the117 Select **View activity** to inspect the Codex task that performs the scan.

114 exact proposed change before you approve a configuration update.

115 118 

1164. Review the result1195. Review the result

117 120 

118 Use the UI to browse findings, or open `report.md` as the entry point to the121 Open the completed scan to inspect findings, coverage, and available report

119 complete scan directory.122 artifacts. Use **Findings** to review issues across scans or **Repositories**

123 to inspect a repository's scan history.

120 124 

121 <figure className="not-prose my-6">125 <figure className="not-prose my-6">

122 126 <CodexScreenshot

123 127 alt="Completed Codex Security scan showing findings in the native workbench"

124 <img128 lightSrc={findingsWorkspace.src}

125 src={findingsWorkspace.src}129 darkSrc={findingsWorkspaceDark.src}

126 alt="Completed Codex Security findings workspace for OWASP Juice Shop"130 maxHeight="520px"

127 className="block h-auto w-full"

128 />131 />

129

130 

131 <figcaption className="mt-3 text-sm text-secondary">132 <figcaption className="mt-3 text-sm text-secondary">

132 Browse findings by severity, category, directory, patch status, and133 Review scan results, findings, and coverage in the Security workbench.

133 review status.

134 </figcaption>134 </figcaption>

135 </figure>135 </figure>

136 136 


172 172 

173<ContentModeSwitch group="codex-surface" id="app">173<ContentModeSwitch group="codex-surface" id="app">

174 174 

175Every completed scan opens a findings workspace. Use it to review findings and175Completed scans remain available in **Scans**. Review their findings and

176coverage without inspecting raw artifacts. The scan also creates the files176coverage in the Security workbench, or inspect related findings and repository

177history in **Findings** and **Repositories**. The scan also creates the files

177below.178below.

178 179 

179</ContentModeSwitch>180</ContentModeSwitch>


188 189 

189 190 

190- `report.md`, the primary readable entry point to the scan results.191- `report.md`, the primary readable entry point to the scan results.

191- `findings/<slug>/`, with one detailed vulnerability report per reportable192- `findings/<slug>/`, when detailed vulnerability reports and supporting

192 finding and supporting proof-of-concept files when available.193 proof-of-concept files are available.

193- `hardening/`, with a structural hardening portfolio and supporting proposals194- `hardening/`, when structural hardening guidance and supporting proposals or

194 or diagrams when the scan has reportable findings.195 diagrams are available.

195- Structured scan data in `scan-manifest.json`, `findings.json`, and196- Structured scan data in `scan-manifest.json`, `findings.json`, and

196 `coverage.json` for automation and integrations. You normally don't need to197 `coverage.json` for automation and integrations. You normally don't need to

197 open these files yourself.198 open these files yourself.


201 202 

202## Choose your next workflow203## Choose your next workflow

203 204 

205- [Use the Security workbench](https://learn.chatgpt.com/docs/security/plugin/workbench) to manage

206 saved scans, findings, repositories, and scan activity in the desktop app.

204- [Run a scan from the CLI](https://learn.chatgpt.com/docs/security/cli) if you have beta access and207- [Run a scan from the CLI](https://learn.chatgpt.com/docs/security/cli) if you have beta access and

205 need a repeatable terminal workflow with structured results.208 need a repeatable terminal workflow with structured results.

206- [Run a standard or scoped scan](https://learn.chatgpt.com/docs/security/plugin/scans) to review a209- [Run a standard or scoped scan](https://learn.chatgpt.com/docs/security/plugin/scans) to review a

Details

11 11 

12## Run a manual review12## Run a manual review

13 13 

14For uncommitted changes, ask Codex:14In the desktop app, open **Security**, select **Scans**, and select **+ Scan**.

15Choose the repository, then select **Changes**. Review uncommitted changes, a

16single commit, or a base and head revision. **Deep scan** isn't available for a

17changes scan.

18 

19You can also ask Codex to review uncommitted changes in a conversation:

15 20 

16```text21```text

17Use $codex-security:security-diff-scan to review my current uncommitted changes for security regressions.22Use $codex-security:security-diff-scan to review my current uncommitted changes for security regressions.


30 35 

31<WorkflowSteps>36<WorkflowSteps>

32 37 

331. Confirm **Scan type** is `Changes`.381. Select **Changes**.

342. Confirm the checked-out **Codebase**, **Current branch**, and **Last commit**.392. Confirm the checked-out repository, current branch, and latest commit.

353. Under **Changes to review**, choose:403. Under **Changes to review**, choose:

36 - `Uncommitted changes` for the current working tree.41 - `Uncommitted changes` for the current working tree.

37 - The latest commit for a single-commit review.42 - The latest commit for a single-commit review.


93`$TMPDIR/codex-security-scans/<repository>/<scan-id>/`:98`$TMPDIR/codex-security-scans/<repository>/<scan-id>/`:

94 99 

95| File | Contents |100| File | Contents |

96| -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |101| -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |

97| `report.md` | Primary readable entry point to the complete scan directory. |102| `report.md` | Primary readable entry point to the complete scan directory. |

98| `findings/<slug>/` | One detailed vulnerability report per reportable finding, with supporting proof-of-concept files when available. |103| `findings/<slug>/` | One detailed vulnerability report per reportable finding, with supporting proof-of-concept files when available. |

99| `hardening/` | Structural hardening portfolio and supporting proposals or diagrams when the scan has reportable findings. |104| `hardening/` | Structural hardening portfolio and supporting proposals or diagrams when the scan has reportable findings. |

100| `findings.json` | Findings with stable identifiers, severity, confidence, source locations, and remediation. Use it to create pull-request comments or feed downstream tools. |105| `findings.json` | Findings with stable identifiers, severity, confidence, source locations, and remediation. Feed approved internal security workflows or downstream tools. |

101| `scan-manifest.json` | Sealed scan receipt with the reviewed target, revisions, and artifact hashes. |106| `scan-manifest.json` | Sealed scan receipt with the reviewed target, revisions, and artifact hashes. |

102| `coverage.json` | Reviewed and deferred surfaces, exclusions, and coverage completeness. |107| `coverage.json` | Reviewed and deferred surfaces, exclusions, and coverage completeness. |

103 108 


140 145 

141Choose the example for your CI provider:146Choose the example for your CI provider:

142 147 

148Scan results can include sensitive vulnerability details. Keep artifacts

149private, and publish findings only after reviewing the audience, content, and

150required approvals.

151 

143<Tabs152<Tabs

144 id="codex-security-ci-examples"153 id="codex-security-ci-examples"

145 param="ci"154 param="ci"


166 runs-on: ubuntu-latest175 runs-on: ubuntu-latest

167 permissions:176 permissions:

168 contents: read177 contents: read

169 pull-requests: write

170 steps:178 steps:

171 - uses: actions/checkout@v5179 - uses: actions/checkout@v5

172 with:180 with:


194 --sandbox workspace-write \202 --sandbox workspace-write \

195 "Use \$codex-security:security-diff-scan to review changes from $BASE_REVISION to $HEAD_REVISION for security regressions. Do not modify the checkout."203 "Use \$codex-security:security-diff-scan to review changes from $BASE_REVISION to $HEAD_REVISION for security regressions. Do not modify the checkout."

196 204 

197 - name: Comment with findings

198 if: always()

199 env:

200 GH_TOKEN: ${{ github.token }}

201 PR_NUMBER: ${{ github.event.pull_request.number }}

202 run: |

203 findings="$(find "${{ runner.temp }}/codex-security/codex-security-scans" -name findings.json -print -quit 2>/dev/null || true)"

204 test -n "$findings" || exit 0

205 jq -r '

206 "## Codex Security findings",

207 "",

208 if (.findings | length) == 0 then "No findings reported."

209 else .findings[] | "- **\(.severity.level | ascii_upcase)**: \(.title) (`\(.locations[0].path):\(.locations[0].startLine)`)\n \(.summary)"

210 end

211 ' "$findings" | gh pr comment "$PR_NUMBER" --body-file -

212 

213 - uses: actions/upload-artifact@v4205 - uses: actions/upload-artifact@v4

214 if: always()206 if: always()

215 with:207 with:


223 215

224 216 

225 217 

226Create masked `CODEX_SECURITY_API_KEY` and `GITLAB_TOKEN` CI/CD variables. The218Create a masked `CODEX_SECURITY_API_KEY` CI/CD variable and review the scan

227GitLab token needs API access to create a merge-request note.219artifacts privately before sharing findings.

228 220 

229```yaml221```yaml

230codex-security-review:222codex-security-review:


235 script:227 script:

236 - |228 - |

237 codex_security_api_key="$CODEX_SECURITY_API_KEY"229 codex_security_api_key="$CODEX_SECURITY_API_KEY"

238 unset CODEX_SECURITY_API_KEY GITLAB_TOKEN230 unset CODEX_SECURITY_API_KEY

239 export CODEX_HOME="/tmp/codex-home-$CI_JOB_ID"231 export CODEX_HOME="/tmp/codex-home-$CI_JOB_ID"

240 export TMPDIR="/tmp/codex-security-$CI_JOB_ID"232 export TMPDIR="/tmp/codex-security-$CI_JOB_ID"

241 export BASE_REVISION="$CI_MERGE_REQUEST_DIFF_BASE_SHA"233 export BASE_REVISION="$CI_MERGE_REQUEST_DIFF_BASE_SHA"


247 "Use \$codex-security:security-diff-scan to review changes from $BASE_REVISION to $HEAD_REVISION for security regressions. Do not modify the checkout."239 "Use \$codex-security:security-diff-scan to review changes from $BASE_REVISION to $HEAD_REVISION for security regressions. Do not modify the checkout."

248 after_script:240 after_script:

249 - |241 - |

250 gitlab_token="$GITLAB_TOKEN"242 unset CODEX_SECURITY_API_KEY

251 unset CODEX_SECURITY_API_KEY GITLAB_TOKEN

252 scan_root="/tmp/codex-security-$CI_JOB_ID/codex-security-scans"243 scan_root="/tmp/codex-security-$CI_JOB_ID/codex-security-scans"

253 findings="$(find "$scan_root" -name findings.json -print -quit 2>/dev/null || true)"

254 if [ -n "$findings" ]; then

255 jq -r '

256 "## Codex Security findings",

257 "",

258 if (.findings | length) == 0 then "No findings reported."

259 else .findings[] | "- **\(.severity.level | ascii_upcase)**: \(.title) (`\(.locations[0].path):\(.locations[0].startLine)`)\n \(.summary)"

260 end

261 ' "$findings" > codex-security-comment.md

262 curl --fail --request POST \

263 --header "PRIVATE-TOKEN: $gitlab_token" \

264 --form "body=<codex-security-comment.md" \

265 "$CI_API_V4_URL/projects/$CI_PROJECT_ID/merge_requests/$CI_MERGE_REQUEST_IID/notes"

266 fi

267 if [ -d "$scan_root" ]; then244 if [ -d "$scan_root" ]; then

268 tar -czf codex-security-artifacts.tar.gz -C "$scan_root" .245 tar -czf codex-security-artifacts.tar.gz -C "$scan_root" .

269 fi246 fi

Details

21 21 

22## Start the deep scan22## Start the deep scan

23 23 

24For a repository-wide review, send:24In the desktop app, open **Security**, select **Scans**, and select **+ Scan**.

25Choose a repository or another folder, select **Codebase**, and turn on

26**Deep scan**. The scan covers the entire selected repository or folder.

27 

28You can also start a repository-wide deep scan from a Codex conversation:

25 29 

26```text30```text

27Use $codex-security:deep-security-scan to run a deep security scan of this repository.31Use $codex-security:deep-security-scan to run a deep security scan of this repository.


33Use $codex-security:deep-security-scan to run a deep security scan of /absolute/path/to/repository/services/payments.37Use $codex-security:deep-security-scan to run a deep security scan of /absolute/path/to/repository/services/payments.

34```38```

35 39 

36For a scoped deep scan in the ChatGPT desktop app, the selected folder becomes40For a scoped deep scan in the desktop app, select the folder as the codebase.

37the **Codebase**. The scan area covers the entire selected folder.41The scan covers the entire selected folder.

38 42 

39## Confirm setup and preflight43## Confirm setup and preflight

40 44 

45For the best scan quality, use `gpt-5.6-sol`

46with `xhigh` reasoning effort.

47 

41<WorkflowSteps>48<WorkflowSteps>

42 49 

431. Confirm **Scan type** is `Codebase` and **Deep scan** is on.501. Select **Codebase** and turn on **Deep scan**.

442. Confirm that **Codebase** is the repository or exact folder you intended to512. Confirm that the repository or selected folder is the code you intended to

45 scan.52 scan.

463. Add threat-model guidance only for concrete attack vectors, sensitive533. Choose a model and reasoning effort.

544. Open **Additional context** for concrete attack vectors, sensitive

47 application areas, or repository context that the code can't reveal.55 application areas, or repository context that the code can't reveal.

484. Select **Start scan**.565. Select **Start scan**.

495. Review the capability preflight. If it proposes a configuration change,576. Review any setup or capability warning before you approve a configuration

50 review the exact change and let Codex apply it only if it matches your58 change.

51 environment. Start a new chat if Codex tells you a restart is required.

52 59 

53</WorkflowSteps>60</WorkflowSteps>

54 61 

55Deep scans require delegated workers and at least six usable worker slots. If62Deep scans require delegated workers. If the current runtime doesn't meet the

56the current runtime doesn't meet those requirements, use a standard scan or63capability requirements, use a standard scan or try again when enough capacity

57move the task to a runtime that passes the capability preflight.64is available.

58 65 

59On supported desktop-app versions, discovery workers inherit your selected66Discovery workers inherit your selected model and reasoning settings. Follow

60model and reasoning settings. Keep the scan active until Codex reports that it67the saved scan from **Scans**, or select **View activity** to inspect its Codex

61is complete. Reopening or rerunning a saved scan doesn't pin the plugin version68task. Check the [plugin changelog](https://learn.chatgpt.com/docs/security/plugin/changelog) before you

62or guarantee that work interrupted by an update will resume. Check the [plugin69update the plugin or start a long-running scan.

63changelog](https://learn.chatgpt.com/docs/security/plugin/changelog) before you update the plugin or70 

64start another deep scan.71<figure className="not-prose my-8">

65 72 <CodexScreenshot

66<VideoPlayer73 alt="Native Codex Security workbench showing a deep scan and its active review phase"

67 src="/videos/codex/security/deep-scan-progress.mp4"74 lightSrc={deepScanProgress.src}

68 poster="/videos/codex/security/deep-scan-progress-poster.webp"75 darkSrc={deepScanProgressDark.src}

69/>76 maxHeight="520px"

77 />

78 <figcaption className="mt-3 text-sm text-secondary">

79 Track the active deep-scan phase and inspect its Codex activity before

80 reviewing the completed result.

81 </figcaption>

82</figure>

70 83 

71## Review the result84## Review the result

72 85 

73Deep scans use the same findings workspace and complete scan directory as86Deep scans use the same saved scan details and complete scan directory as

74standard scans. Start with `report.md`, which links to one detailed report for87standard scans. Open the completed scan in **Scans** or review its findings in

75each reportable finding and a structural hardening portfolio when findings88**Findings**. When available, `report.md` links to one detailed report for each

76remain. Keep the linked `findings/` and `hardening/` directories with the89reportable finding and a structural hardening portfolio when findings remain.

77report when sharing or archiving the result.90Keep the linked `findings/` and `hardening/` directories with the report when

91sharing or archiving the result.

78 92 

79Review the coverage summary before the findings. Even a deep scan has limits,93Review the coverage summary before the findings. Even a deep scan has limits,

80so check deferred surfaces and remaining proof gaps before drawing a94so check deferred surfaces and remaining proof gaps before drawing a

Details

11 11 

12Neither workflow changes the sealed scan bundle.12Neither workflow changes the sealed scan bundle.

13 13 

14Available export formats and workspace controls depend on your Codex surface14Available artifact links and export formats depend on your Codex surface and

15 and installed plugin version. Check the [plugin15 installed plugin version. Check the [plugin

16 changelog](https://learn.chatgpt.com/docs/security/plugin/changelog) before you use a format in16 changelog](https://learn.chatgpt.com/docs/security/plugin/changelog) before you use a format in

17 automation.17 automation.

18 18 

19## Export a portable artifact19## Export a portable artifact

20 20 

21Open the completed findings workspace, select **Export**, and choose a format:21In the desktop app, open a completed scan from **Security** > **Scans**. Use its

22available artifact links to inspect `report.md`, `findings.json`,

23`scan-manifest.json`, `coverage.json`, or a SARIF report when present.

24 

25To create another supported format, ask Codex to export findings from the

26completed scan without modifying its sealed bundle:

27 

28```text

29Export the findings from [completed scan directory] as [JSON, CSV, or SARIF]. Do not modify the sealed scan bundle or upload its contents.

30```

31 

32Choose the format that fits your destination:

22 33 

23| Format | Use it for |34| Format | Use it for |

24| ------ | ----------------------------------------------------------------- |35| ------ | ----------------------------------------------------------------- |


26| CSV | Review findings and current local triage state in a spreadsheet. |37| CSV | Review findings and current local triage state in a spreadsheet. |

27| SARIF | Send findings to tools that support the SARIF interchange format. |38| SARIF | Send findings to tools that support the SARIF interchange format. |

28 39 

29Select **Export findings**, then use the returned artifact path. If another

30tool needs the complete scan context, keep the original `scan-manifest.json`,

31`findings.json`, and `coverage.json` together. The plugin generates SARIF

32locally. Exporting doesn't upload findings to a code-scanning service.

33 

34<figure className="not-prose my-8">40<figure className="not-prose my-8">

35 41 <CodexScreenshot

36 42 alt="Completed Codex Security scan showing the real coverage, findings, manifest, Markdown, and SARIF artifacts"

37 <img43 lightSrc={exportFindingsFormats.src}

38 src={exportFindingsFormats.src}44 darkSrc={exportFindingsFormatsDark.src}

39 alt="Export findings dialog with JSON, CSV, and SARIF format options"45 maxHeight="360px"

40 className="block h-auto w-full"

41 />46 />

47 <figcaption className="mt-3 text-sm text-secondary">

48 Open the coverage, findings, scan manifest, Markdown report, or SARIF

49 artifact from a completed scan.

50 </figcaption>

51</figure>

42 52 

53Select **Markdown report** to open `report.md` in your configured external

54editor. The editor depends on your system settings; the example below shows the

55generated report contents.

43 56 

57<figure className="not-prose my-8">

58 <CodexScreenshot

59 alt="Example generated security report showing the scan scope, threat model, and validated findings"

60 lightSrc={exportFindingsReport.src}

61 darkSrc={exportFindingsReportDark.src}

62 maxHeight="600px"

63 />

44 <figcaption className="mt-3 text-sm text-secondary">64 <figcaption className="mt-3 text-sm text-secondary">

45 Export completed findings as JSON, CSV, or SARIF for downstream review and65 Review the scan scope, threat model, validated findings, and detailed report

46 tooling.66 links in the generated Markdown report.

47 </figcaption>67 </figcaption>

48</figure>68</figure>

49 69 

70Use the returned artifact path. If another tool needs the complete scan

71context, keep the original `scan-manifest.json`, `findings.json`, and

72`coverage.json` together. Exporting doesn't upload findings to a code-scanning

73service.

74 

50## Track selected findings75## Track selected findings

51 76 

52Run `$codex-security:track-findings` with one validated finding or an77Run `$codex-security:track-findings` with one validated finding or an


124eventually public and remove credentials, private evidence, and unnecessary149eventually public and remove credentials, private evidence, and unnecessary

125exploit details before approval.150exploit details before approval.

126 151 

127<VideoPlayer152Review and approve external actions in the Codex conversation. Approval

128 src="/videos/codex/security/issue-preview-before-approval.mp4"153doesn't create a separate issue or advisory screen in the Security workbench.

129 poster="/videos/codex/security/issue-preview-before-approval-poster.webp"

130/>

131 154 

132## Verify the tracked item155## Verify the tracked item

133 156 

Details

3> For the complete documentation index, see [llms.txt](https://learn.chatgpt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to the page URL.3> For the complete documentation index, see [llms.txt](https://learn.chatgpt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to the page URL.

4 4 

5Use Codex Security to turn an accepted security finding into a focused,5Use Codex Security to turn an accepted security finding into a focused,

6verified patch. You can work in the findings workspace or run the remediation6verified patch. You can work in the Security workbench or run the remediation

7workflow from a prompt, the command line, or CI/CD. Codex validates the issue7workflow from a prompt, the command line, or CI/CD. Codex validates the issue

8and, when testing is safe and practical, adds a focused regression test that8and, when testing is safe and practical, adds a focused regression test that

9fails before the fix and passes after it. It also checks that legitimate9fails before the fix and passes after it. It also checks that legitimate


18 18 

19## Fix a finding in the UI19## Fix a finding in the UI

20 20 

21Open an accepted finding in the findings workspace to generate, review, apply,21Open an accepted finding from **Findings** or a completed scan in **Scans**.

22and verify its patch.22Review its evidence, then use **Patch** to generate, review, apply, and verify

23one focused fix.

23 24 

24<WorkflowSteps variant="headings">25<WorkflowSteps variant="headings">

25 26 


31 32 

322. Review the proposed diff332. Review the proposed diff

33 34 

34 Read every changed source, regression test, and validation artifact. Select35 Read every changed source, regression test, and validation artifact. Reject

35 **Open diff in editor** to review the full patch in your editor. Reject

36 broad refactors, unrelated cleanup, or changes that weaken another security36 broad refactors, unrelated cleanup, or changes that weaken another security

37 control.37 control.

38 38 

393. Apply the patch locally393. Apply the patch locally

40 40 

41 Select **Apply patch locally** only after the diff is acceptable. Codex41 Select **Apply patch** only after the diff is acceptable. Codex applies the

42 applies the exact generated patch to the working tree and records that state.42 exact generated patch to the working tree and records that state. Review the

43 Review the working-tree diff before continuing.43 working-tree diff before continuing.

44 44 

454. Verify the fix454. Verify the fix

46 46 


60</WorkflowSteps>60</WorkflowSteps>

61 61 

62<figure className="not-prose my-8">62<figure className="not-prose my-8">

63 63 <CodexScreenshot

64 64 alt="Native Codex Security workbench showing the generated patch for an accepted finding"

65 <img65 lightSrc={fixFindingPatch.src}

66 src={fixFindingPatch.src}66 darkSrc={fixFindingPatchDark.src}

67 alt="Codex Security proposed patch for an accepted finding"67 maxHeight="460px"

68 className="block h-auto w-full"

69 />68 />

70

71 

72 <figcaption className="mt-3 text-sm text-secondary">69 <figcaption className="mt-3 text-sm text-secondary">

73 Review the proposed source and test changes before applying the patch70 Review the generated security fix before applying it to your checkout.

74 locally.

75 </figcaption>71 </figcaption>

76</figure>72</figure>

77 73 

Details

11 11 

12## Choose the scan area12## Choose the scan area

13 13 

14In the desktop app, open **Security**, select **Scans**, and select **+ Scan**.

15Choose an existing repository or another folder, then select **Codebase**.

16 

14Scan the whole repository when you need broad coverage and the repository is a17Scan the whole repository when you need broad coverage and the repository is a

15reasonable review unit:18reasonable review unit. For a monorepo, choose one folder when a service,

19package, or component has a clear owner and security boundary.

20 

21You can also start a scan from a Codex conversation:

16 22 

17```text23```text

18Use $codex-security:security-scan to scan this repository for security vulnerabilities.24Use $codex-security:security-scan to scan this repository for security vulnerabilities.

19```25```

20 26 

21Scan a folder when a monorepo is too large or one service, package, or component27To focus that conversation on a particular folder, identify the component:

22has a clear owner and security boundary:

23 28 

24```text29```text

25Use $codex-security:security-scan to scan this repository for security vulnerabilities, focusing on the services/billing component.30Use $codex-security:security-scan to scan this repository for security vulnerabilities, focusing on the services/billing component.


29 34 

30## Configure the scan35## Configure the scan

31 36 

37For the best scan quality, use `gpt-5.6-sol`

38with `xhigh` reasoning effort.

39 

32<WorkflowSteps>40<WorkflowSteps>

33 41 

341. Confirm **Scan type** is `Codebase` and leave **Deep scan** off.421. Select **Codebase** and leave **Deep scan** off.

352. Confirm the **Codebase**, **Current branch**, and **Last commit**.432. Confirm the selected repository, current branch, and latest revision.

363. Set **Scan area** to `Entire codebase` or enter one repository-relative443. Set **Scan area** to the entire repository or choose one folder.

37 folder.454. Choose a model and reasoning effort.

384. Add threat-model guidance only when it changes the review. Useful guidance465. Open **Additional context** only when it changes the review. Useful context

39 names attacker-controlled inputs, trust boundaries, sensitive actions, or a47 names attacker-controlled inputs, trust boundaries, sensitive actions, or a

40 specific area to prioritize.48 specific area to prioritize.

415. Select **Start scan**.496. Select **Start scan**.

42 50 

43</WorkflowSteps>51</WorkflowSteps>

44 52 


64 or proof gaps.72 or proof gaps.

654. **Impact and path analysis** evaluates each candidate's realistic paths,734. **Impact and path analysis** evaluates each candidate's realistic paths,

66 impact, and severity.74 impact, and severity.

675. **Detailed reporting** creates one source-backed vulnerability report per755. **Reporting** records validated findings, coverage, and scan metadata.

68 reportable finding, with supporting proof-of-concept files when available.76 Detailed per-finding reports are optional for standard scans.

696. **Structural hardening** analyzes the complete finding set and creates a776. **Structural hardening**, when available, analyzes the finding set and

70 design portfolio when reportable findings remain.78 creates design guidance.

717. **Finalization** validates the structured scan contract and generates797. **Finalization** validates the structured scan contract and generates

72 `report.md`, which links the detailed reports and hardening portfolio.80 `report.md`, including links to any detailed reports or hardening guidance.

73 81 

74Codex reports phase and coverage progress as the scan runs. Wait for the82The workbench shows the active scan phase and any progress the plugin reports.

75complete result instead of judging early candidates or stopping because one83Select **View activity** to inspect the Codex task. Wait for the complete

76phase takes longer than another.84result instead of judging early candidates or stopping because one phase takes

85longer than another.

77 86 

78## Review the completed scan87## Review the completed scan

79 88 


874. Dismiss findings whose evidence doesn't support the claimed path or impact.964. Dismiss findings whose evidence doesn't support the claimed path or impact.

885. Select one accepted finding before starting a fix.975. Select one accepted finding before starting a fix.

89 98 

90 99<figure className="not-prose my-8">

91 100 <CodexScreenshot

92 <figure>101 alt="Codex Security finding showing its severity, validation status, root cause, and attack path"

93 102 lightSrc={findingAttackPath.src}

94 103 darkSrc={findingAttackPathDark.src}

95 <img104 maxHeight="520px"

96 src={findingsWorkspace.src}

97 alt="Completed Codex Security findings workspace for OWASP Juice Shop"

98 className="block h-auto w-full"

99 />

100

101 

102 <figcaption className="mt-3 text-sm text-secondary">

103 The completed workspace summarizes scan status, coverage, severity, and

104 artifacts before listing the findings.

105 </figcaption>

106 </figure>

107 

108 <figure>

109

110 

111 <img

112 src={findingAttackPath.src}

113 alt="Codex Security finding evidence and attack-path analysis for OWASP Juice Shop"

114 className="block h-auto w-full"

115 />105 />

116

117 

118 <figcaption className="mt-3 text-sm text-secondary">106 <figcaption className="mt-3 text-sm text-secondary">

119 A finding connects the relevant source to its entry point, reachability,107 Review the finding's severity, validation status, root cause, and attack

120 likelihood, impact, and any limits or counterevidence.108 path.

121 </figcaption>109 </figcaption>

122 </figure>110</figure>

123 

124 

125 

126## Reopen or rerun a previous scan

127 111 

128In the ChatGPT desktop app, open a completed scan from the security scan list112## Reopen a previous scan

129to review its saved findings workspace. To update the results, rerun the saved

130configuration against the current code. The rerun creates a new scan and leaves

131the earlier scan and its artifacts unchanged.

132 113 

133Scan history, rerun controls, and other workspace features depend on your Codex114Open **Security**, then select a saved scan from **Scans** to review its

134surface and installed plugin version. A rerun doesn't pin that version or115findings, coverage, and available report artifacts. To assess the latest code,

135guarantee that interrupted work will resume after a plugin update. Check the116start a new scan for the same repository. The new scan doesn't replace the

136[plugin changelog](https://learn.chatgpt.com/docs/security/plugin/changelog) before you start or rerun117earlier scan or its artifacts.

137a long-running scan.

138 118 

139## Use the results119## Use the results

140 120 

141Use the findings workspace to review findings, coverage, and follow-up areas121Use the Security workbench to review findings, coverage, and follow-up areas

142without inspecting raw JSON. Open `report.md` for the readable entry point to122without inspecting raw JSON. Open `report.md` when available for the readable

143the complete scan directory. Keep the directory together when you share or123entry point to the complete scan directory. Keep the directory together when

144archive it: the report links to detailed reports in `findings/` and, when124you share or archive it: the report links to detailed reports in `findings/`

145reportable findings exist, structural hardening guidance in `hardening/`.125and structural hardening guidance in `hardening/` when those optional artifacts

126are available.

146 127 

147Behind the workspace, each scan preserves `scan-manifest.json`, `findings.json`,128Behind the workspace, each scan preserves `scan-manifest.json`, `findings.json`,

148and `coverage.json` for automation and integrations. You normally don't need to129and `coverage.json` for automation and integrations. You normally don't need to

149open these files yourself.130open these files yourself.

150 131 

151The findings workspace can also create portable JSON, CSV, and SARIF files. See132For portable artifacts or external issue tracking, see [Export or track

152[Export or track findings](https://learn.chatgpt.com/docs/security/plugin/export-findings).133findings](https://learn.chatgpt.com/docs/security/plugin/export-findings).

153 134 

154## Next step135## Next step

155 136 

Details

8evidence without executing the code.8evidence without executing the code.

9 9 

10Run this workflow from a Codex project scoped to the repository you want to10Run this workflow from a Codex project scoped to the repository you want to

11assess. Codex must be able to read the repository's source code. Jira, Linear,11assess. Codex must be able to read the repository's source code. Jira and Linear

12and GitHub connectors provide finding data, but they don't replace access to12connectors can provide finding data, while GitHub findings require authenticated

13the source code.13GitHub REST access. Neither replaces access to the source code.

14 14 

15Under the hood, Codex starts from the cited code or version information. It15Under the hood, Codex starts from the cited code or version information. It

16traces the claimed attacker-controlled source, relevant security controls,16traces the claimed attacker-controlled source, relevant security controls,

17dangerous sink, and reachable path. It also checks the product surface and trust17dangerous sink, and reachable path. It also checks the product surface and trust

18boundary, looks for counterevidence, and records proof gaps. Codex then returns18boundary, looks for contradictory evidence, and records proof gaps. Codex then returns

19one verdict per finding and ranks the findings that need action or further19one verdict per finding and ranks the findings that need action or further

20review.20review.

21 21 

22This differs from `$codex-security:validation`, which can build or run code,22This differs from `$codex-security:validation`, which can build or run code,

23create a focused test or proof of concept, or exercise a real interface to23create a focused test or proof of concept, or exercise a real interface to

24reproduce or disprove a finding. Use triage to classify and prioritize an24reproduce or disprove a finding. Use triage to classify and rank an

25existing backlog. Use validation when runtime evidence could resolve a finding25existing backlog. Use validation when runtime evidence could resolve a finding

26that static evidence leaves uncertain.26that static evidence leaves uncertain.

27 27 


37| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |37| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |

38| Pasted or local findings | SARIF results, a CVE or GHSA, an advisory, a scanner ticket, a bug bounty report, a Codex Security finding artifact, or a plain-language vulnerability claim. | No connector required. |38| Pasted or local findings | SARIF results, a CVE or GHSA, an advisory, a scanner ticket, a bug bounty report, a Codex Security finding artifact, or a plain-language vulnerability claim. | No connector required. |

39| Jira or Linear | Exact security or vulnerability issue URLs or identifiers, Jira JQL, or a Linear team, project, or search phrase. Codex retrieves the selected issue content before triage. | [Jira through Atlassian Rovo](codex://plugins/plugin_connector_692de805e3ec8191834719067174a384) or [Linear](codex://plugins/plugin_asdk_app_69a089a326dc8191b32a3f2553f5be2c) with read access. |39| Jira or Linear | Exact security or vulnerability issue URLs or identifiers, Jira JQL, or a Linear team, project, or search phrase. Codex retrieves the selected issue content before triage. | [Jira through Atlassian Rovo](codex://plugins/plugin_connector_692de805e3ec8191834719067174a384) or [Linear](codex://plugins/plugin_asdk_app_69a089a326dc8191b32a3f2553f5be2c) with read access. |

40| GitHub | A repository and one finding source: code scanning, `Dependabot` vulnerabilities and malware, security advisories and private vulnerability reports, or all sources. If you don't specify a repository, Codex uses the GitHub repository attached to the current Codex project when available. GitHub Issues aren't included in the default GitHub sources; provide a specific issue or ask for GitHub Issues explicitly when you want to triage them. | [GitHub](codex://plugins/plugin_connector_1p_1a69035c238881919c4190932b2df699) with access to the selected repository and finding type. |40| GitHub | A repository and one finding source: code scanning, `Dependabot` vulnerabilities and malware, security advisories and private vulnerability reports, or all sources. If you don't specify a repository, Codex uses the GitHub repository attached to the current Codex project when available. GitHub Issues aren't included in the default GitHub sources; provide a specific issue or ask for GitHub Issues explicitly when you want to triage them. | Authenticated GitHub REST access, such as `gh auth token`, `GH_TOKEN`, or `GITHUB_TOKEN`, with permission to read the selected repository and finding type. |

41 41 

42Codex keeps one result for every supplied finding, in input order, so each42Codex keeps one result for every supplied finding, in input order, so each

43source finding stays traceable. It doesn't merge or drop findings that look43source finding stays traceable. It doesn't merge or drop findings that look

Details

13 13 

14- The findings, disclosure notes, or assessment documents to review.14- The findings, disclosure notes, or assessment documents to review.

15- The target source tree and affected revision or release.15- The target source tree and affected revision or release.

16- Existing PoCs, logs, traces, screenshots, or crash output.16- Existing PoCs, logs, traces, screenshots, or diagnostic output.

17- Fix commits or diffs when available.17- Fix commits or diffs when available.

18- The authorization boundary for any testing.18- The authorization boundary for any testing.

19 19 


54 54 

55## Use reports from a scan55## Use reports from a scan

56 56 

57When a standard, deep, or change scan has reportable findings, Codex runs this57When a deep or change scan has reportable findings, Codex runs this workflow

58workflow once per finding during final reporting. The scan writes each report to58once per finding during final reporting. Detailed reports are optional for

59standard scans. When Codex generates detailed reports, it writes each report to

59`findings/<slug>/<slug>.md`, stores supporting files under60`findings/<slug>/<slug>.md`, stores supporting files under

60`findings/<slug>/poc/`, and links the report from `report.md`.61`findings/<slug>/poc/`, and links the report from `report.md`.

61 62 

security/plugin/workbench.md +112 −0 created

Details

1# Use the Codex Security workbench

2 

3> For the complete documentation index, see [llms.txt](https://learn.chatgpt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to the page URL.

4 

5The Security workbench brings your scans, findings, and repositories together

6in the Codex desktop app. Codex performs scan analysis in a regular task, while

7the workbench keeps the scan and its results available when you return.

8 

9Install and enable the [Codex Security plugin](https://learn.chatgpt.com/docs/security/plugin), then

10select **Security** in the desktop-app sidebar.

11 

12If **Security** doesn't appear, confirm that the plugin is installed and

13 enabled. Update the desktop app and plugin if needed, and check whether your

14 workspace administrator allows the plugin.

15 

16## Start a scan

17 

18For the best scan quality, use `gpt-5.6-sol`

19with `xhigh` reasoning effort.

20 

21<WorkflowSteps>

22 

231. Open **Scans** and select **+ Scan**.

242. Select an existing repository or choose another folder.

253. Choose **Codebase** to scan a repository or **Changes** to review a

26 Git-backed change.

274. For a standard codebase scan, select the entire repository or a folder.

285. For a deep scan, first select the repository or folder as the codebase, then

29 turn on **Deep scan**. Deep scans review the entire selected codebase.

306. For a changes scan, select uncommitted changes, a commit, or a revision

31 range. **Deep scan** isn't available for changes scans.

327. Choose a model and reasoning effort. Open **Additional context** to describe

33 relevant attack vectors, focus areas, or other security context.

348. Select **Start scan**.

35 

36</WorkflowSteps>

37 

38<figure className="not-prose my-8">

39 <CodexScreenshot

40 alt="Codex Security workbench showing the setup for a new repository scan"

41 lightSrc={scanOverview.src}

42 darkSrc={scanOverviewDark.src}

43 maxHeight="520px"

44 />

45 <figcaption className="mt-3 text-sm text-secondary">

46 Choose a repository and configure a scan in the Security workbench.

47 </figcaption>

48</figure>

49 

50See [Run a security scan](https://learn.chatgpt.com/docs/security/plugin/scans), [Run a deep security

51scan](https://learn.chatgpt.com/docs/security/plugin/deep-scans), or [Review code changes for

52security](https://learn.chatgpt.com/docs/security/plugin/code-changes) for details about each scan

53type.

54 

55## Follow scan progress

56 

57The scan page shows the current phase and any scan progress the plugin reports.

58For a standard scan, phases include threat modeling, discovery, validation,

59impact and path analysis, reporting, and finalization.

60 

61Select **View activity** to open the Codex task that runs the scan. You can

62leave the workbench and return to **Scans** without losing a saved scan. To stop

63work intentionally, open the scan and select **Stop scan**.

64 

65When the scan completes, open its results to review the target, revision,

66findings, coverage, and available report artifacts.

67 

68<figure className="not-prose my-8">

69 <CodexScreenshot

70 alt="Completed Codex Security scan showing findings, scan coverage, and report artifacts"

71 lightSrc={findingsWorkspace.src}

72 darkSrc={findingsWorkspaceDark.src}

73 maxHeight="520px"

74 />

75 <figcaption className="mt-3 text-sm text-secondary">

76 Review findings, severity, scan coverage, and artifacts after a scan

77 completes.

78 </figcaption>

79</figure>

80 

81## Review findings across scans

82 

83Open **Findings** to inspect saved findings across repositories and scans.

84Search or filter the list, then select a finding to review its summary, source

85evidence, validation, and impact.

86 

87Use **Summary** for the finding details and **Patch** when you want to generate,

88review, apply, or verify a focused fix. See [Fix and verify security

89findings](https://learn.chatgpt.com/docs/security/plugin/fix-findings) for the remediation workflow.

90 

91The **Findings** tab shows findings from saved Codex Security scans. Imported

92 tickets and other existing security issues remain part of the separate

93 [backlog triage workflow](https://learn.chatgpt.com/docs/security/plugin/triage-backlog).

94 

95## Inspect repository history

96 

97Open **Repositories** to browse available repositories and folders. Select a

98repository to inspect its scan history, latest scanned revision, and open

99findings. From repository details, open a previous scan or view the findings

100associated with that repository.

101 

102If a repository has no scans, start a scan from its details or select **+ Scan**

103in the workbench.

104 

105## Start a scan from a conversation

106 

107You can also ask Codex to run the installed Codex Security plugin in a regular

108conversation. Scans that use the shared plugin workbench appear in **Scans**,

109so you can return to their progress and results from the Security workbench.

110 

111For terminal-based scans and automation, see the [Codex Security CLI

112quickstart](https://learn.chatgpt.com/docs/security/cli).

security/sdk.md +33 −12

Details

10The SDK uses ECMAScript modules (ESM) and runs server-side with Node.js 22 or10The SDK uses ECMAScript modules (ESM) and runs server-side with Node.js 22 or

11later. Scanning also requires Python 3.10 or later.11later. Scanning also requires Python 3.10 or later.

12 12 

13The Codex Security SDK is in beta and requires access. Follow the installation13The Codex Security SDK is [publicly available on

14 instructions provided with your access. For general coding agents, see the14 GitHub](https://github.com/openai/codex-security). Running scans requires

15 [Codex SDK guide](https://learn.chatgpt.com/docs/codex-sdk). For terminal and CI workflows, see the15 Codex Security access. For general coding agents, see the [Codex SDK

16 [Codex Security CLI quickstart](https://learn.chatgpt.com/docs/security/cli).16 guide](https://learn.chatgpt.com/docs/codex-sdk). For terminal and CI workflows, see the [Codex

17 Security CLI quickstart](https://learn.chatgpt.com/docs/security/cli).

17 18 

18## Set up the SDK19## Set up the SDK

19 20 

20Follow the installation instructions provided for your Codex Security access.21Install the SDK:

21Then set `OPENAI_API_KEY` or `CODEX_API_KEY`, or use an existing file-backed

22Codex sign-in before starting a scan.

23 22 

24Depending on your account and repository, full-repository scans may also23```bash

25require [Trusted Access for Cyber](https://chatgpt.com/cyber), which signing in24npm install @openai/codex-security

26or providing an API key does not grant.25```

26 

27Before starting a scan, set `OPENAI_API_KEY` or `CODEX_API_KEY`, or use an

28existing file-backed Codex sign-in.

29 

30For best results, use an account verified for [Trusted Access for

31Cyber](https://chatgpt.com/cyber). Signing in or providing an API key does not

32grant Trusted Access.

27 33 

28## Run a scan34## Run a scan

29 35 


335 pluginPath: "/path/to/codex-security-plugin",341 pluginPath: "/path/to/codex-security-plugin",

336 pythonPath: "/path/to/python",342 pythonPath: "/path/to/python",

337 codexOverrides: {343 codexOverrides: {

338 model: "<model>",344 model: "gpt-5.6-terra",

345 model_reasoning_effort: "high",

339 },346 },

340});347});

341```348```

342 349 

343`pluginPath` accepts a plugin directory or ZIP. `pythonPath` selects the350`pluginPath` accepts a plugin directory or ZIP. `pythonPath` selects the

344plugin interpreter. `codexOverrides` merges supported values into the isolated351plugin interpreter. `codexOverrides` merges supported values into the isolated

345Codex configuration.352Codex configuration. Scans use `gpt-5.6-sol` with extra-high reasoning effort

353by default. Set `model` and `model_reasoning_effort` in `codexOverrides` to use

354a different model or reasoning effort.

346 355 

347The client also exposes supported authentication methods:356The client also exposes supported authentication methods:

348 357 


359selected sign-in flow. The SDK can reuse a file-backed Codex sign-in. API keys368selected sign-in flow. The SDK can reuse a file-backed Codex sign-in. API keys

360are a useful fit for CI and server-side automation.369are a useful fit for CI and server-side automation.

361 370 

371When both an API key and a stored sign-in are available, the SDK uses the API

372key by default. To use your ChatGPT sign-in instead, select it for the scan:

373 

374```ts

375const result = await security.run("/path/to/repository", {

376 auth: "chatgpt",

377});

378```

379 

380Set `auth: "api-key"` to require an environment API key. `preflight` accepts

381the same `auth` option.

382 

362## Handle scan errors383## Handle scan errors

363 384 

364Catch the exported error class that matches the action your application can385Catch the exported error class that matches the action your application can