OpenAI has finally become "Open" once again!
Recently, OpenAI officially announced: it has quietly released an open-source code security tool—Codex Security CLI.

Previously, someone on Hacker News discovered it first, sparking instant discussions, and GitHub stars surged to 1.2k.
Seeing that it could no longer be kept hidden, OpenAI had no choice but to come forward and claim it.


GitHub address: https://github.com/openai/codex-security
A few days ago, Jensen Huang personally stepped in, publicly expressing strong support for open-source AI, and soon after, OpenAI officially joined the camp.
Little did we expect that the surprise would come so quickly, as the heavyweight open-source masterpiece was unveiled almost instantly.
It has to be said, Huang's words still carry significant weight!

OpenAI's Code Security Tool is Now Open-Source
The "star" of this open-source release is codex-security, comprising a CLI and a TypeScript SDK.
Its core functionality is very straightforward, focusing on a "combo punch": automatically discovering vulnerabilities in a codebase, verifying them, and fixing them.

It's designed to be ready-to-use; the entire workflow can be run with just three lines of commands:
- npm install @openai/codex-security
- npx codex-security login
- npx codex-security scan .
For CI runs, logging in isn't required; just configure an OPENAI_API_KEY.
The requirements are Node.js 22 or higher, Python 3.10 or higher, plus access to Codex Security.
1.2 Million Commits, 792 Critical Vulnerabilities
Strictly speaking, Codex Security isn't a completely "new species".
It evolved from the private beta project Aardvark in October 2025 and was renamed and launched as a research preview version on March 6th this year.
The most hardcore aspect of this tool lies in its positioning—an application security agent.

Codex Security truly dives deep into the underlying code to understand what your system is actually doing. Its workflow is divided into three steps:
First, it reads the entire repository to generate an editable threat model, figuring out what the project does and where it's most exposed;
Then, based on this context, it searches for vulnerabilities and ranks them by their real-world impact;
Finally, it throws suspicious issues into a sandbox for real stress testing, only reporting those that can be verified.
Looking at its track record, it's indeed quite formidable.
In its first 30 days online, it scanned over 1.2 million commits, uncovering 792 critical severity findings and 10,561 high severity findings.
OpenAI also mentioned that for the same batch of repositories scanned repeatedly, the false positive rate dropped by over 50%.
The First Batch of Early Adopters, Bills Exploded
No matter how grand the official promises are, they can't compare to the "real-world test disasters" that immediately surfaced among developers.
On HN, a developer named gregwebs tested it on a small repository and directly posted the utterly devastating terminal logs.
Preparation started at 0:03, scanning began at 1:20, ran all the way to 52:47, and finally, a line of red text popped up—the repository HEAD changed during scanning, please start over.
Not only did it waste an hour, but this single run also consumed half of his Pro plan's weekly quota.

Another user, Quai, had it worse. The scan hit account rate limits right after starting, and the tool retried for a minute before giving up.
The tool did hint that "partial results have been preserved," but he couldn't find an obvious way to use them in the next scan. This failed run cost about $13.

Why is it so expensive? Just look at the default configuration and the answer becomes clear.
Codex Security defaults to calling gpt-5.6-sol and brutally cranks the "reasoning effort" up to extra-high.
It's important to know that Sol is the most "premium" tier in the GPT-5.6 family, with API pricing as high as $5 per 1M input tokens and $30 per 1M output tokens.

Huang Kicked Things Off, OpenAI Took a Step
Just after Jensen Huang publicly voiced strong support for open-source AI, OpenAI brought out Codex Security.


However, don't interpret this "open-source" move as too generous just yet.
OpenAI's step is quite calculated: they've open-sourced the application-layer shell, while the model layer is still tightly held in their own hands.
Regardless, the Pandora's box of agents taking over code security has been opened.
Next, it's up to developers to see how they can hack and modify this open-source artifact, using the magic of the community to counter OpenAI's own magic.
References:
https://x.com/gdb/status/2082235089539526690?s=20
https://x.com/OpenAI/status/2082263717916586117?s=20
This article is from WeChat public account "AI Era", author: ASI Revelations





