Context-heavy vulnerability review
Investigate flaws whose impact depends on application trust boundaries, data flows and surrounding business logic.
Independent tool overview
Codex Security is OpenAI's application-security agent for building repository-specific threat models, exploring attack paths, validating suspected vulnerabilities and proposing reviewable patches.
Visit the official Codex Security site ↗
Overview
Codex Security is a research-preview application-security product inside Codex. It connects to selected GitHub repositories, analyzes the code and commit history, and builds an editable threat model describing entry points, trust boundaries, sensitive data and high-impact paths. That context guides its search for vulnerabilities instead of relying only on static signatures.
For a suspected issue, the agent can attempt reproduction in an isolated validation environment, record an attack path and proof-of-concept evidence, and propose a minimal patch. The patch does not modify the repository automatically; a human must review it and can turn it into a pull request. This workflow can add valuable security depth, but it remains one control in a broader program—not a replacement for dependency scanning, secrets detection, dynamic testing, architecture review or professional penetration testing.
Use cases
The strongest fit depends on the job you need the product to complete, not the size of its feature list.
Investigate flaws whose impact depends on application trust boundaries, data flows and surrounding business logic.
Analyze current code plus commit history to look for existing vulnerabilities and relevant architectural context.
Give security reviewers reproduction evidence and explicit assumptions instead of only a rule match and severity label.
Generate a minimal patch proposal and revalidate the issue after a reviewed fix is merged.
Start with a small repository set and dedicated reviewers before integrating results into a wider vulnerability program.
Capabilities
Enable selected GitHub repositories for initial and ongoing analysis through Codex Security.
Generate a project-specific model of entry points, trust boundaries, sensitive assets and high-impact code paths that teams can inspect and correct.
Scan commits in reverse chronological order to build context and search for vulnerabilities already present in repository history.
Use language-model reasoning, large context, tools and test-time compute to explore realistic code and attack paths.
Attempt to reproduce potential issues in an isolated environment before surfacing them as validated findings.
Show how attacker-controlled input may travel from an entry point to a sensitive outcome, including likelihood, impact and assumptions.
Record reproduction results and execution details that reviewers can use to judge exploitability and priority.
Generate a focused remediation suggestion intended to address the root cause without silently changing the repository.
Allow a reviewed proposal to become a pull request in the team's normal code-review process.
Re-run validation after a confirmed issue is patched and merged to help close the remediation loop.
Enterprise and Edu admins can gate Codex Cloud, Codex Security use and scan administration through roles or SCIM-synced groups.
Process
Step 1
Start with a small set of repositories and reviewers, using lower-risk code first if GitHub Cloud access is new to the organization.
Step 2
Authorize only required repositories and roles, review data handling, and separate scan administration from ordinary finding access.
Step 3
Add deployment assumptions, real trust boundaries, sensitive assets, authentication context and excluded test-only behavior.
Step 4
Inspect the attack path, reproduction details, assumptions, severity and affected code instead of accepting the label alone.
Step 5
Review the diff, run unit, integration, regression and security tests, and confirm the fix does not break intended behavior.
Step 6
Use the normal pull-request and release process, revalidate the fix, then update the threat model and security backlog from reviewer feedback.
Cost
OpenAI does not publish a standalone Codex Security fee or per-scan rate. The research preview is available through eligible ChatGPT subscriptions, subject to rollout, workspace controls and usage limits. Plan prices below are the broader ChatGPT subscription prices, not a dedicated security-scanning quote.
$200/month
Individual-plan eligibility for the Codex Security research preview.
$20/user/month annual or $25 monthly
A self-serve team workspace with Codex access and business data protections.
$100/user/month annual or $125 monthly
A higher-usage Business seat for teams with heavier agentic workloads.
Custom pricing
For organizations needing advanced governance, contractual controls and flexible usage.
Custom pricing
Institutional access for universities with administrative controls.
Pricing checked . Check current pricing at the source ↗
Assessment
Compare
The right alternative depends on the specific output, workflow, controls and budget your project requires.
Coding
Choose Claude Security to compare another agentic vulnerability-scanning and patch workflow, including its supported integrations and beta boundaries.
Explore Claude Security →Coding
Choose Dryrun Security for pull-request-focused application security and code-context analysis within supported repository workflows.
Explore DryRun Security →Coding
Choose Claude Code Review when the broader need is automated pull-request review and code-quality feedback rather than dedicated vulnerability discovery and validation.
Explore Claude Code Review →Questions
Codex Security is OpenAI's research-preview application-security agent. It builds a threat model, scans a GitHub repository and its history, investigates attack paths, validates suspected vulnerabilities and proposes patches for human review.
OpenAI's current help article lists ChatGPT Pro, Business, Enterprise and Edu users, subject to rollout, workspace permissions and applicable usage limits.
No. It proposes a patch that a human can review and turn into a pull request. The normal review, testing and merge process still applies.
Codex Security attempts to reproduce a suspected issue in an isolated environment and records execution and proof-of-concept details. Reviewers still need to judge whether the assumptions match production.
No. OpenAI says it uses model reasoning and tools rather than fuzzing or signature-based scanning. A mature program should combine it with complementary automated controls and qualified human testing.
There is no separate public Codex Security price. Access is tied to eligible ChatGPT subscriptions, and actual availability, limits or additional credits should be confirmed in the account or enterprise agreement.
Yes. OpenAI says teams can inspect and edit it so entry points, trust boundaries, assets and deployment assumptions match the real system.
Start with a small repository set and dedicated reviewers. Measure confirmed findings, false positives, missed benchmark issues, triage time, patch quality, regressions, access-control fit and credit consumption before wider rollout.
Bottom line
Codex Security is a promising addition for teams that want deeper context and validation than a conventional alert feed provides. Editable threat models, attack-path evidence, sandbox reproduction and reviewable patches create a sensible closed loop. Its value depends on disciplined human review and a layered security program: use it to add coverage and reduce triage effort, never to certify that a repository is safe.
Visit Codex Security website ↗
Luma Agents

My Computer - Manus' new desktop app bringing its AI agent to your local machine

Hermes Agent - Nous Research's open-source autonomous agent with persistent memory and cross-platform messaging

NemoClaw - Nvidia's open-source security and privacy layer for OpenClaw autonomous agents

Get access to all our AI courses, hundreds of real-world AI use cases, live expert-led workshops, an exclusive network of AI early adopters, and more.
Get unlimited access to all of our current & upcoming industry-specific AI courses for the duration of your subscription.
To keep up with the rapid pace of AI, our team publishes AI implementation guides daily. Our library contains 300+ practical use cases to automate real-world work.
Join weekly, live, interactive sessions with industry leaders who are at the forefront of AI for hands-on implementation guidance and exclusive insights.
Network with an exclusive community of AI-first professionals who are working smarter with AI. Learn how early adopters are using AI in their work and businesses.