#codex-security-feedback

374 messages · Page 1 of 1 (latest)

keen cairnBOT
storm patrol
#

hi

oak spoke
#

hi

opal schooner
#

guys how2use codex security lol

oak spoke
#

lowkey, its been great, it has patched a lot for me, a great feature!

trail moat
#

meow

amber sedge
#

Nice. Hi

heavy obsidian
#

Yoo

radiant nymph
#

tbh, didn't worked much well for me

rose shale
#

wow

gloomy nacelle
#

My feedback is to give it as a trial for plus accounts, otherwise I have nothing to cmpare it with

green wave
#

capybarathink I have never used Codex 😍

opal schooner
light idol
#

how do we get added?

jaunty pike
#

@opal schooner If you have Pro or a Business account it should just be in Codex web for you?

zinc roost
#

I don't even know what codex is in the first place (I don't use ai to code haha)

ebon pawn
#

How can I use Codex Security? My codex macOS app doesn’t has this agent

jaunty pike
#

@oak spoke That is great to hear. Of course, always interested in both good and bad feedback!

frigid folio
prime zinc
#

Didn't know this is a thing, very epic, looking forward to playing with it

opal schooner
#

doesn’t it just create a security audit of the whole codebase?

light idol
jaunty pike
#

Right now this is a "web" only feature (i.e. it relies on Codex environments, etc.)

winged zodiac
heavy obsidian
#

Yea once it’s on plus I’ll make sure to give some feedback, it’s a very good idea to have codex helping with security

winged zodiac
#

Exactly

ebon pawn
autumn spoke
#

Currently using codex for a full local first img studio gone threw my pro quota a few times but still worth it the new updates seem cleaner and faster

heavy obsidian
#

You need pro or a business plan

winged zodiac
#

Or Edu I'm fairly sure

hollow egret
wraith creek
#

Its not yet in codex vs ext😭

craggy flare
rose shale
neon matrix
#

I’m sorry, but Codex isn’t exactly very good at design yet. It still needs a lot more improvement overall, especially when it comes to creating polished, modern, and well thought out UI work.

umbral drum
#

I haven't used Codex Security because I'm a Plus user, not a Pro.🥀

stuck scroll
#

honestly the product is trash--i had it scan three repos and nothing shows up in the scans list

turbid crater
stuck scroll
#

it's like it doesn't even work

silent bison
craggy flare
frigid gorge
#

security is working good, the advantage here is context aware security findings, instead of being generic,
Would really love to see it in CLI though!

hollow egret
#

We really need a 40$ plan for those who want to support more but cannot afford 200$.
Thats better than having people spend the other 20$ on claude sub instead

neon matrix
hollow egret
jaunty pike
neon matrix
#

Just some feedback hello .

jaunty pike
#

Those are all questions for the larger codex team - I only deal with Codex security 🙂

#

@frigid gorge did you know you can edit the threat model?

stuck scroll
#

@jaunty pike there is no error--just literally blank lists in the left sidebar. and the repos can't be selected again because it says they are already being scanned. this is on Enterprise for a large company.

#

"no findings to show", "no scans to show"

ebon pawn
#

Is there any expected date to Codex Security gets released for Plus subscription?

hollow egret
jaunty pike
#

@stuck scroll Out of curiosity, how large are the repos? "No scans to show" would indicate the scan was not there? That sounds like an error in the backend.

craggy flare
hollow egret
jaunty pike
#

Codex security is not really a "malware" scanner so much as a "code security issue" scanner and workflow.

craggy flare
hollow egret
lime pivot
#

@jaunty pike cool product: how does scanning commits work? Is it different from Codex PR reviews?

jaunty pike
#

It's fairly different - without delving into a sales pitch or tradecraft internals - one big difference is the validation workflows to reduce false positives.

tame pagoda
#

@jaunty pike It's fantastic but would be better if there was a way to import the issue into the Codex app to work on. When does it stop scanning? Or should it go forever? I may be misunderstanding but I thought it said I had 5 scans? Is that 5 repos that can be scanned?

#

OHWAIT. Hang on. It fixes too? I thought it just highlighted errors

jaunty pike
#

Yes.

#

You can click a button to get a PR made

tame pagoda
#

Very impressed. Only problem is the carpal tunnel I'm about to get with all these PRs 😂

jaunty pike
#

Or you can click a button to get a cut and paste clipboard note and just paste that into your tool of choice for fixing

lime pivot
jaunty pike
#

But "just make Codex fix" is what I do

willow lotus
#

Initial impression of the security scanning is that it doesn't understand architecture, and only looks at how things fit together. Lots of "security issues" that were identified are just blatent false positives or not understanding the purpose of the applciation that was built.

It did find some edge cases that I previously didn't think of that were useful. The "threat modeling" seems like an ok starting point, but vs an actual threat model it's severely lacking if you've done them before.

Happy to explore more if needed, I've been working in security for a while now.

jaunty pike
#

For sure - did you know you can edit that threat model?

hollow egret
jaunty pike
#

I can't really talk about the internals (and they wouldn't make sense with public terminology anyways)

hollow egret
#

Xhigh is very false positive ish model that acts like shizo buts good at ui

#

Medium/high are much better overall otherwise

tame pagoda
willow lotus
jaunty pike
#

To be fair, I am happy to hear people's experience with the models1

hollow egret
craggy flare
willow lotus
#

Like I go in and edit the text output of the threat model? Would this look at the scan differently? Is that how this is meant to be used? Or do you mean you can edit the text

jaunty pike
#

Yes, you can edit the threat model and that affects the scan results. For example, if you go to Codex Security, then "Scans" then pick a scan, you can click "Edit" and then you get to edit it.

#

Although you don't HAVE to do this

#

But if you are getting poor results because for whatever reason you got a threat model that you don't agree with, that is one way to re-align it

willow lotus
#

That's interesting. Definitely will have to mess with it more

jaunty pike
#

I work directly for OpenAI on this product @craggy flare

craggy flare
jaunty pike
#

Both! 🙂

wind lava
#

Hi @jaunty pike,

I haven’t used Codex Security yet, but I’m curious about its purpose.

I recently vibe-coded a mini-CRM system for our company. Our ICT partner says this could be risky because the code wasn’t written through a traditional development process.

Could Codex Security be used to analyze an application like this and verify whether it’s secure and safe to run in a company environment?

willow lotus
#

One thing that I have in my repo is a lot of documentation going over why things are done in certain ways, and the purpose of many different parts that LLMs in general don't understand as well as a map of the structure of the repo. It is a production application with thousands of users for a side project of mine. I was exploring it for enterprise use for repos.

In general what do you think has been the feedback from it so far? What are the strengths/weaknesses @jaunty pike

Happy if you can point to resources I can read as well

jaunty pike
#

Certainly there are no guarantees in life, but I feel safer when Codex Security looks at something. We use it internally and it finds things.

hollow egret
marsh sky
#

First you need to give us access if you want to hear feedback lol
PRO user here, paying significantly more than default accounts that got access to the model 😉

jaunty pike
#

I don't yet have enough information to really say what the strengths and weaknesses are. Pro users should already have access!

hollow egret
craggy flare
jaunty pike
#

Every Pro/Business/Enterprise/EDU should have access to five free repo scans right now

willow lotus
near forge
hollow egret
sharp sapphire
#

Worked great for me. I had made two repos for aa business that held sensitive data and ditd tranasactions. i had hacked the repo myself using shannon and some other tools and it covered alot, and then codex security found 1 additional hole the others had not. so it was better than shannon! -- I come from an art background so this additinoal tool made me feel good about the work I was sharing.

jaunty pike
#

I can't comment on future business plans, but we've publicly stated we are doing a free month

#

Thats great to hear @sharp sapphire

hollow egret
#

Or is it rolling out to plus too rn?

jaunty pike
#

Currently it's "Pro and similar", more than that I can't comment on.

near forge
#

Will Codes Security come to the Codex apps on Win/Mac?

jaunty pike
#

A great question and one I hope to answer in the coming months.

#

As you might be able to see, we are working very quickly at improving Codex in many ways.

hollow egret
#

Does the security consume normal quota like reviews do?

jaunty pike
#

Right now it consumes nothing.

hollow egret
jaunty pike
#

This is something I have no further information on.

hollow egret
jaunty pike
#

Currently I believe you would be limited to 5 (at a time?) I am actually not sure. 🙂

thick field
#

how do we use codex security?

grave dagger
#

This is about a codex security skill that open Ai released or security through codex use in general?

craggy flare
jaunty pike
thick field
jaunty pike
#

@craggy flare Scans are continuous. So 5 repos -> every commit to main branch is scanned.

#

@thick field Do you have Pro/Ent/Bus account or Plus?

thick field
#

i have a plus account

jaunty pike
#

That is why then

thick field
#

oh i see

willow lotus
#

@jaunty pike Do yo look at private messages at all? May be something to alert to someone as a potential misuse.

jaunty pike
#

Apologies I am not in charge of things other than "Gathering feedback, answerin questions, fixing bugs" 🙂

grave dagger
turbid crater
craggy flare
jaunty pike
#

It can take a few minutes (maybe half an hour sometimes) to get started?

olive halo
#

why is this a paid feature and not avaible on free tier?

latent yoke
#

Tried signing up a few weeks ago, app apparently hates my drivers license. 4 times trying, so been unable to try, but… Will try again tonight.

hollow egret
#

(Its a temp promo rn)

olive halo
#

but why paid only and not on the temp promo

hollow egret
halcyon rivet
#

My team's biggest complaint so far is that there's no way to properly "export" the finding into a clean format like a markdown report or a zip archive

#

Also we're seeing a bunch of false positives and don't see any way to rate findings in the interface, except for the "adjust severity" thing.

stuck igloo
#

I used codex to solve 41 security errors in supabase in a oneshot sql, so thats nice. Didn't even break my database or anything

halcyon rivet
jaunty pike
#

@halcyon rivet Is there an underlying theme to when it gives you a false positive?

#

The adjust severity thing is how I write notes about particular bugs, although that is being worked on by teh team

willow lotus
#

Are you guys monitoring people using this to scan public repos to look for exploits?
I'd be very concerned about that for open source software that is heavily used especially. Ideally any scans would be opened up as a PR or similar so that the maintainers know that it's being scanned or similar.
Mostly a safety issue, or do you feel like this is nothing new compared to the SAST/DAST/SCA scanning that can be done anyways against repos?

jaunty pike
#

We are doing our best to get the open source community (who get free access) to also use Codex Security, but the attacker community has been an early adopter of these types of tools and already has this kind of thing

willow lotus
#

When you say have this kind of thing, what competing software is there with it atm? I'm not aware of any so just curious

jaunty pike
#

The offensive community is quite active, and it's hard to say there's a donuts to donuts comparison, but there are a lot of projects in this space!

willow lotus
#

Mostly on the blue side so will have to ask some of my red team buddies then, thanks

halcyon rivet
#

we got like ~30 findings from codex security on the first run, processed about half of them and so far 1/3rd are good. that's a good result actually in that codebase but there's room to grow 🙂

atomic yoke
#

sometimes i have to press okay to everything

#

sometimes not, that confusing me a lot

marsh sky
hollow egret
marsh sky
unique field
#

Codex Security is web only for now

marsh sky
marsh sky
#

It means it needs actual repo access, I guess, not local

near forge
marsh sky
#

I have pro
Just checked -

  1. It needs you to connect a factual online repo
  2. While that would somewhat be something i could go with.,.. tos 2.4 was then immediately killing the joy again ahah
#

So.. corrected - yes pro has access to the model 🙂

sweet zenith
#

What I understand is that plus can’t use codex security yet?

stuck scroll
marsh sky
#

in bananas

turbid crater
#

Hm, ours finished with only two findings. (I find this really quite hard to believe given the size and scope of our repo). I was under the impression that it scanned the whole repo, but it only scans the last N commits, is that right?

unique field
#

Yes (based on time I think). So the last three months of activity say.

rough path
#

My scans have said they have been running all weekend, is it a bug? Should I stop, delete and scan again?

willow lotus
#

@jaunty pike I did want to say I appreciate you for making this and look forward to the future of it.

willow lotus
#

It should say "Done scanning, will scan future commits" or something

frigid gorge
rough path
rich sun
#

Think product is not that great

rough path
#

It only scans commits not the repo?

cyan hill
#

Can we put more coding support in the chatgpt app instead of ide

#

Lots of devs dont access ide for coding

unique field
#

But it uses the whole repo. Think of the commit as just a seed of context ?

vale meteor
#

What’s the url?

#

The link in the FAQ goes to a 404

unique field
#

Bill you need pro. 🙂

long mulch
#

You guys wanna see what some of the highest tier mitigation in seconds looks like for a FEDRAMP application

unique field
#

I'm confused by your question but sure ?

long mulch
#

Absolutely amazing, I've been working on this project for 7 days of me programming and months of AI and our teams research.

#

Now what it found there would have taken us a month to find internally.

#

Now to test it on the native Codex application I just built.

vale meteor
long mulch
#

This is a top notch report right here, show your friends. That is true true understanding of a LARGE LARGE codebase.

#

Hats off boys, now to go play some more.

dense pagoda
#

I forked a friend's repo and added a scan for it. It was in the queued section but after refreshing the page, it's gone, but i see this when i hover the question mark. i can't remove it, and it deducted one of my available scans. is it still running? anyone run into this?

edit: nevermind, it finally showed up

hybrid steppe
#

How to use this? I use Codex cloud only.

long mulch
#

Codex -> Security -> Create Environment

#

Top right, near the word Codex

stray sentinel
#

Super impressed with the bugs found from a run! Thanks for the quality ship and taking feedback. The validation reports and scoring are all great.

#1 Feature request: Exportability. Print to PDF doesn’t work well with the scan page. And even that would not include findings. It would be really nice to take this run as a point-in-time pentest finding with a sampling of findings into a markdown or PDF report.

lost jetty
#

Love the new security scanning feature — especially helpful for someone without a strong security background.

One thing I ran into while fixing issues:

  • I submitted PRs for all findings marked Medium or higher, and most fixes have been merged.
  • However, the Findings list still shows a few Medium issues even though the fixes are merged.
  • At the same time, the Scans page summary still reports the original number of Medium issues.

So the UI currently shows something like:

  • Scan summary: higher number of Medium findings
  • Findings list: smaller number remaining after fixes

It’s unclear whether:

  • the scan results haven’t been refreshed after merges, or
  • findings are tied to the original scan snapshot.

Would be great if the dashboard updated automatically or clearly indicated when a re-scan is required to clear resolved findings.

turbid crater
#

Can I really not share my findings with other team members?

#

(We're on the Team plan)

halcyon rivet
turbid crater
alpine shale
#

Hey. Thanks for opening codex security, it's really promising

I am curious, would there be a way to customize the scan? For example if I have a bunch of skills for domain specific issues, would there be a way to integrate them in the scan easily?

halcyon rivet
#

Not sure if it’ll work though as it scans the commits specifically

alpine shale
bronze agate
#

Will Codex Security be released for use with Codex CLI?

zinc dome
#

it can only find minor defect. i hope it can has more defend system like the startup recently openai purchase.

wary talon
#

Great at finding small regressions in addition to small security issues. Not sure if you want to classify regressions | security in the UI (the model does in the description)

plain quail
rose steppe
#

I am enjoying this feature as I am learning to build a long time project into a secure open facing repo with baked in security. There is still so much for me to learn and this tool is helping me make better design choices as it matures.

jaunty pike
#

I don't think we use "skills" yet tbh

oak garden
#

How long does Codex Security take approximately for a scan?

jaunty pike
#

Scans are continuous - but we look "backwards" a bit as well.

jaunty pike
#

@alpine shale Currently we don't use "skills" but we can certainly add that to the list 🙂

#

@lost jetty Thanks for the note: In theory there is an agent that looks to see if things have been fixed and then removes the finding from your view when they are...in practice I think it's not working as well as we'd like.

wary talon
#

@jaunty pike I have ~ 2500
commits in a repo. 500 scanned when I initially created the scan, and about 200 scanned tonight. What’s the expected time for a full scan? Is there a time wise look back (ie only commits last 12mo)?

foggy tiger
alpine shale
unique field
jaunty pike
#

(To be fair, I've only done minor testing against blockchain-related things, but the system did quite well at those tests)

long mulch
#

Smart cookie. That’ll get you some eyes.

vague solar
#

Used it a bit - haven't gotten too many useful insights. Some repos that should have tons of insights to find only have a few minor suggestions.

I have the same feedback for code review - the results have always felt lackluster compared to the models themselves. Asking codex directly can find tons of issues.

I know how it is, and you can't throw an army of 5.4-xhigh agents to scan a codebase and every commit, but it'd be nice if a codebase scan and higher thinking/parallel workers was an option. I'd be fine with it using my sub usage or paying for extra usage to get better results

unique field
#

I mean we throw a small army of agents at everything 🙂 what kind of bugs are you expecting to find ?

vague solar
# unique field I mean we throw a small army of agents at everything 🙂 what kind of bugs are yo...

DM'd a small note - no need to reply there.

Lots of auth, sessions, permissions commits recently and it only caught 1 high. I'm flattered, but I know my code isn't that good. A prompt on 5.4-high to "analyze <component> and report security issues" was able to find a bunch of issues across auth: totp , session handling and invalidation, jwt issues, role and permissions permissiveness, etc. Security flaws, not just code bugs

jaunty pike
#

Is Codex Security the reason anyone here first logged into Codex Web?

hollow egret
#

Feedback: A good (and useful) pr marketing stunt would be running few codex and few claude reviews, then showing all the bugs codex found that claude couldnt, and the price difference!

#

Users would have proof which one is better 🥳
Furthermore id have another bonus reason to hate on anthropic!

gleaming oyster
#

For my small business each employee maintains an individual Pro subscription to use with Codex. It seems with this setup we are excluded from Codex Security. It would be useful if we could access the research preview.

jaunty pike
#

You should have access because you have Pro - but I don't think you'll be able to share findings?

jaunty pike
#

FWIW we have many many features and improvements in the queue - just loading up the PR's - so we hope to have even better results for you shortly! And we appreciate all the feedback from everyone!

marsh sky
#

My biggest feedback would be “I can’t keep track of 5 places at the same time“, so I didn’t even use it even if my pro sub gives me access to

Having it in the CLI would be very welcome because I simply can’t afford to leave CLI > study a gui > go back to CLI > potentially repeat many more such loops

#

I know that’s not a model feedback but perhaps it can be forwarded as a general product feedback

glossy widget
#

The lack of .codexignore or .agentsignore support in Codex CLI is baffling at this point. The community has been asking for this since day one and it keeps getting ignored. This is basic, foundational stuff. Every comparable tool ships with some form of ignore file support because developers need control over what the agent can and can't touch. Without it, Codex is genuinely hard to use safely in any real codebase.
At some point this stops being an oversight and starts looking like willful neglect. Please just build it.

naive pecan
jaunty pike
#

Yeah I mean, I also commit to codex-cli but not on this stuff 🙂

jaunty pike
#

Useful or no?

lost jetty
#

Also, I have had some rendering issues. This has happened more than once.

jaunty pike
#

The UI is definitely getting some cleanup. Hopefully this gets fixed as part of that 🙂

neon prism
#

How i can access to codex sécurité ?
Requird plus plan?

umbral drum
calm glen
#

5.3-codex is better then 5.4

naive pecan
#

Is there a way to give feedback to a security issue? It marked "not checking the email validity for sso logins" as issue, but we just trust SSO logins and therefore don't send a verification email. I would like to give feedback for this finding so it will not resurface sometime.

jaunty pike
#

Yes, you can slide that litle slidey thing for criticality and then a window will pop up on that and it will allow you to enter information there, or you could just edit the threat model and specifically add your knowledge there (easiest, tbh).

naive pecan
#

TIL I can edit the threat model and there is a button to adjust … thanks a lot, I must have been blind the last days 🙂

jaunty pike
#

No it's one of my pain points in terms of nobody knowing they can do that

#

We have some bigger changes coming soon to address that but hopefully that will help while you wait 🙂

naive pecan
#

I created a few PRs now and merged them. Do I just wait or do I close the issue? And is there a way to filter for issues with/out PR?

#

And one more: one PR did get created, but it's still showing up as "create pr", is there a way to link it?

jaunty pike
#

I think there IS a way to filter for issues that don't have a PR? Does this not work?

#

If you wait, I believe the fix checker should eventually remove the issue from the list (but it has to get around to it). I think the other issue you are having is more "a bug" in the sense that the Codex backend didn't connect properly to the issue when it created the PR? This is probably something that we've fixed already but let me know if this happens a lot!

naive pecan
# jaunty pike I think there IS a way to filter for issues that don't have a PR? Does this not ...

This does filter for "patch avail", that is if codex has created a patch. The filter works, but it doesn't show "PR created".

My workflow would be: I go over the list and look for things I think needs fixing first (probably bumping them up in severity, but sometimes just "gut feeling"). Then create a PR. That would be the point were I no longer need to look at that issue in codex security anymore, because it's now "in the code".
-> I would like to filter out those.

And "gladly" I have a repo with still 30 reported issues to try out all these things.

naive pecan
alpine shale
#

A few ideas for improvements:

  • Having a “2 steps” process mode, where I can receive an alert once the threat model is generated, so that I can review it and then launch the actual analysis after I updated the threat model
  • Sharing more info about the “status”, what does “scanning” mean? Looks like its scanning git history, and I assume new commits, but it would be great to have more details, to know when I should start doing the triage. Right now, I launch it, I wait a bit, and if I see some findings, I start triaging, but I have no idea if its done with the current commit etc
  • Generating alerts (ex: by email), once some status are reached (ex: once the first commit on main is analyzed)
  • Having time estimate for run completion would be great too (even rough estimate). Like should I wait 2 min, 15 min, 3 hours?
  • Having a “open a chatgpt session” with the threat model would avoid having to copy/paste. A killer feature would be for a chat that has also access to the source code

Also I noticed the “scans” list is sometimes a bit out of sync (ex: recent scan shows up, then disappears, then appears again). That said, it’s minor, and seems to happen only within the first minute(s) of a launch

naive pecan
oak egret
#

k

hollow egret
#

not sure if this security issue or not, but codex app lacks manual /compact which makes the app borderline unusable for any serious work

plain quail
plain quail
naive pecan
hexed harbor
#

Please build a proper OpenAI IDE.

Not just an extension or a chat panel inside someone else’s editor, but a full development environment where the model is built into the actual engineering workflow: understanding the whole project, preserving context across sessions, making safe code changes, running checks, working with architecture, contracts, tests, and local tools.

Right now the market feels fragmented: the editor is separate, the agents are separate, the plugins are separate, and context gets lost all the time. What is needed is a cohesive product where AI is not a decorative add-on, but a real development layer.

What matters most:
— stable work with large codebases
— a proper agent orchestration model
— strict control over changes before they are applied
— transparent logs of model actions
— solid local integration with the toolchain, git, tests, and runtime

In short: an IDE, not another “smart assistant” tab.

misty hearth
hexed harbor
#

I can't speak to the specifics of the application as a programmer, but I know this specifically optimizes the answer to the next question.

naive pecan
sacred wadi
#

Hello - Does anyone knows how frequently the applications for Codex for Open Source are reviewed ?

hexed harbor
hexed harbor
#

I think most problem in gpt disk 💿 configs

#

I mean open ai need building MORE N MORE SERVERS in something new county I mean

#

Or... I think they can use old config models like a "LOCAL DISK" ysee

#

I hope my words help something

#

@silk hound

hexed harbor
#

gpt@misl

hexed harbor
#

@silk hound

jaunty pike
#

@sacred wadi I actually don't know - did you apply and not hear back?

naive pecan
#

is codex security included in the pro-$100-plan?

crude bone
#

Any chance to have Codex security for security researchers?

gloomy nacelle
#

any answer to the security on 100 plan?

pallid lantern
#

Why should permissions stay only default or full access but not with ranges and more specific scopes ?

carmine ruin
pallid lantern
carmine ruin
# pallid lantern The thing is there is no intermediary safety where you can access a project full...

You’re pointing at a real gap in a lot of agent-style permission systems: they often jump from “restricted / ask for approval” straight to “full trust inside a sandbox”, without a comfortable middle mode for practical development work.

And you’re right—real dev workflows absolutely need something in between.

What you’re describing is basically a “developer-safe autonomy mode”

Not full system access, not constant permission prompts—something like:

Access to a specific project directory
Ability to inspect environment (installed packages, dependencies, configs)
Ability to create isolated environments (venv/conda/docker-like)
Ability to run builds/tests within that boundary
No broader filesystem or system escape

This is very reasonable—and common in human tooling—but harder for agents.

carmine ruin
carmine ruin
#

Ideal Codex Permission Model (4 tiers)
Tier 0 — Observe Only (Read-Only Intelligence Mode)

Best for: exploration, onboarding, analysis

Capabilities:

Read project files (scoped to workspace)
Inspect structure, dependencies, configs
Run safe introspection commands (lint, tree, package listing)
No writes, no installs, no system changes

Blockers:

No file modification
No network access
No environment mutation

Mental model:

“You can look, but you cannot touch.”

carmine ruin
# pallid lantern sure

Why this model works better than today’s “default vs full”

  1. It matches real developer mental models

Developers don’t think in:

“approve every command” ❌
“give full system access” ❌

They think in:

“this project environment” ✔
“this dependency graph” ✔
“this repo scope” ✔

Tier 1 matches that directly.

  1. It aligns with real OS isolation primitives

Modern systems already support this:

Docker / containers
devcontainers
filesystem mounts
Linux namespaces / Windows SIDs

So Tier 1 is not theoretical—it’s implementable.

(And many Codex sandbox implementations already approximate this idea internally.)

  1. It removes the biggest pain point: constant interruption

Today’s “default mode” forces:

per-file approvals
repeated prompts
workflow fragmentation

Tier 1 eliminates that entirely without increasing system risk.

  1. It cleanly separates two different security problems

Most systems confuse:

filesystem safety (project isolation)
behavior safety (what the agent chooses to do)

This model separates them:

Layer Problem it solves
Tier 1 filesystem + workspace isolation
Tier 2 controlled autonomy
Tier 3 execution autonomy

That separation is what current Codex UX often collapses.

#

It's ready! Just follow my instruction

pallid lantern
carmine ruin
pallid lantern
#

Do you suggest I pick one of those "Docker / containers
devcontainers
filesystem mounts
Linux namespaces / Windows SIDs" and build within it but does this mean I should install codex in a container ? btw virtual env are limited to those but others could be better prepared because in the cloud many environments are missing

pallid lantern
carmine ruin
# pallid lantern Do you suggest I pick one of those "Docker / containers devcontainers filesystem...

Yes—but with an important clarification: you usually don’t want to “install Codex in a container” in the same way you install a normal CLI tool and assume that solves everything.

What you actually want is:

Run Codex inside a containerized development environment, where the container is the “permission boundary,” not Codex itself.

Codex (or any agent) is just the actor. The container/dev environment is the safety + reproducibility layer.
What you should choose (practical recommendation)
Best default: Dev Containers (recommended starting point)

Use:

VS Code Dev Containers
Docker-based dev environment

Why this is the best starting point:

Very easy to set up
Designed specifically for “project-isolated dev environments”
Works well with AI agents
Reproducible across machines and cloud

Think of it as:

“a prebuilt sandbox workspace for your project”

lofty lion
carmine ruin
lofty lion
carmine ruin
carmine ruin
#

Which Linux version? (Arch,Mint, etc.)

pallid lantern
carmine ruin
carmine ruin
pallid lantern
pallid lantern
carmine ruin
hollow egret
#

where can i find security? i got pro now

carmine ruin
hollow egret
naive pecan
naive pecan
#

no – and I hope I don't have to, I failed that for API already, something isn't working with my id card (and I have no idea what)

hollow egret
#

I verified, it said passed, then openai website said failed

#

The id ver is js broken

naive pecan
#

maybe, a coworker could verify (same country, same type of id), mine didn't work in two different accounts

alpine shale
#

I haven't used codex security in a few weeks, and I went back on it this week, pretty cool the see the improvements made to the UI

haughty tangle
#

Hi everyone,
I have been trying to get Codex to stop reading my envs in like a global agents.md but had no luck yet

any tips?

summer kraken
#

codex --config 'permissions.deny=["Read(**/.env)"]'

I think this should work too

haughty tangle
noble frost
# haughty tangle I had not tried those options.

Keep in mind, if Codex can launch the app and observe its behavior, secrets can still leak indirectly through stdout, stack traces, debug pages, generated files, or follow-up commands.

The only 100% safe way is to not have codex run it. (along with not giving it access to env)
If you dont need to have codex run it, then just have a script which deploys the app somewhere where codex cant access and keep the env there.

hexed harbor
#

How legal will it be to try to hack openai?:)

#

I mean for sharing problems ofc

austere radish
fiery dawn
robust lake
#

Anybody else seeing real slowdowns when chonical is enabled?

white imp
#

I lost my chat session today even the chat session i archeved

fickle hornet
#

yoo guys, i was tryna verify on https://chatgpt.com/cyber but when i scan my id its always denied, does anyone have the same issue?

lofty lion
fickle hornet
fallen wyvern
#

Hi everyone im a developer

noble frost
#

suuuuure

noble frost
#

just insane amount of scammers on discord last few days 😄

daring yacht
#

There's no information on the site about cost-per-unit, and I understand that's still in the air. But as someone who might upgrade from Plus to Pro or Enterprise, or even work with an Edu, based on anticipated usage of these security features and others, I have no grounding for even considering the topic. Is there any internal speculation that we can banter around about whether the model is something like tokens-plus, or credits per scan, or credits per file? How might tiers be aligned between Pro, Business, Enterprise, and Edu?
Can ya give us anything on this? Thanks!

swift vine
#

please fix
"Failed to resume chat
cannot resume running thread 019e23c1-f4ed-75a1-b911-b2d4d662a435 with stale path: requested C:\Users\MR THINH\.codex\sessions\2026\05\14\rollout-2026-05-14T06-52-54-019e23c1-f4ed-75a1-b911-b2d4d662a435.jsonl, active \\?\C:\Users\MR THINH\.codex\sessions\2026\05\14\rollout-2026-05-14T06-52-54-019e23c1-f4ed-75a1-b911-b2d4d662a435.jsonl"

naive belfry
noble frost
naive belfry
#

that is what I supposed xD

#

yea.. the amount of scam bots that we delete every day is disheartening

wise portal
#

Guys codex has severe bug

#

Of making the system completely slow

#

It just runs with cmds

shrewd sail
#

Is there an API endpoint to point Codex to, to start working through and closing these with feedback? Or is it all still web UI only?

naive pecan
daring yacht
rustic anvil
#

hey y'all, i tried verifying my identity for cyber access today and was told i'm ineligible for some reason. i tried "contacting" support but there is no way to contact support at the moment

blazing fiber
# rustic anvil

I am the same, speechless, and when I try to support contact, the "real people" sent to my email with an answer like that We can’t provide additional details about verification outcomes, and Support can’t override the result. You can review the verification requirements and flow here: chatgpt.com/cyber.

lofty lion
tiny tulip