Tool Open source

Codex Security

Codex Security is an OpenAI CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in authorized code repositories. It scans directories and codebases, including repository changes, uses AI-assisted analysis to trace attack paths and apply custom threat models, validates findings, and can generate reviewable patches and exports in SARIF, JSON, and CSV formats. The CLI supports CI use with an API key and can stop builds at a selected severity threshold.

View repository Visit site Mentioned in 3 videos ↓

Overview

The package also supports configurable deep scans, worker and subagent counts, time limits, containerized bulk scans, and a preview findings service. The service stores findings and embeddings in SQLite, provides paginated listings and a read-only dashboard, identifies potential duplicates through embedding similarity, and allows completed findings to be published and deduplicated through the CLI or SDK. It requires Node.js 22.13.0 or later and Python 3.10 or later, and can use OpenAI or other documented inference providers.

What Codex Security is used for

3 uses taken from transcripts — each links to the moment in the video.

  • An open-source CLI and TypeScript SDK that uses AI to find, validate, and review security issues in code. It can scan repositories, diffs, or paths, trace attack paths, use custom threat models, and export findings in formats such as SARIF, JSON, and CSV.

  • An open-source CLI and TypeScript SDK for finding security issues in authorized repositories. It scans codebases or diffs, validates findings, generates reviewable patches, exports results, and can fail CI at a chosen severity threshold.

  • Provides application security scanning through a CLI and TypeScript SDK. It finds, validates, and helps fix vulnerabilities, while tracking scan history and finding status.

Videos mentioning Codex Security

3 in the library.