Reintroducing Codex Security plugin! point it at a codebase or diff and it can build a threat model, map attack paths, validate findings, generate + test fixes, and export results to SARIF, GitHub, Jira or Linear. oh, and it all open source on github!!
OpenAI's Vaibhav Srivastav releases open-source Codex Security plugin
It automatically maps attack paths and generates security fixes.
Positive users praise the Codex Security Plugin for AI-driven cyberdefense and self-validating fixes while negative users report it blocking scans on their own codebases with security warnings that waste time.
No Digg Deeper questions have been answered for this story yet.
Most Activity
try the codex security plugin, for applying our models to cyberdefense:
Reintroducing Codex Security plugin! point it at a codebase or diff and it can build a threat model, map attack paths, validate findings, generate + test fixes, and export results to SARIF, GitHub, Jira or Linear. oh, and it all open source on github!!
@reach_vb I ran a Codex Security scan on a project built entirely with Codex. After 53 minutes, it blocked without a usable result, wasting my time and burning 65% of my weekly limit. This makes the scan effectively useless and disadvantageous. @OpenAI @OpenAIDevs @reach_vb @thsottiaux
@reach_vb Yeah, it's great, except it kicked me out in the middle with "security concerns" over scanning our own codebase.
@reach_vb What is the refusal rate, though?
@reach_vb Is this correct regarding usage?
@reach_vb Read aloud! Imagine surviving cancer, brain surgery, learning to walk, talk, and read, but reading is like reading a second language: hard. Imagine your dev boyfriend talking about all the amazing things he’s doing with codex/ChatGPT, but not being able to without TTS.
@gdb At least I can use with 5.6 Sol rather than being downgraded to GPT 5.4 😅
@gdb Will it hold itself back like in the hugging face case, where they had to switch to a Chinese model?
@reach_vb wasn't it already there?
@reach_vb how is opensource and at the same time "license": "Proprietary" ?
@gdb can it handle advanced persistent threats effectively
@gdb Oh nice, been meaning to dig into this — curious how it handles real-world attack patterns.
@reach_vb 开源这点挺加分,先丢个小仓库试试
@gdb Can’t use the Codex security plugin right now. Hit my weekly limit yesterday. If @thsottiaux can reset the limit, I’d love to give it a try.
@reach_vb We caught a database security issue right before our last release. Codex Security can run that review on every diff, check whether the finding is real, write the fix, and test it. That is much more useful than another scanner that just gives you a list of warnings.
@gdb Just in time for me to run a security check on my soon-to-be-released software.
@reach_vb I smell fear
check it out here: https://github.com/openai/plugins/tree/main/plugins/codex-security