codex-security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
Codex Security is an AI-powered security sub-agent CLI and TypeScript SDK from OpenAI that autonomously discovers, validates, and fixes security vulnerabilities in codebases. It uses large language models (including GPT-5.6, Claude, and others) to perform both quick and deep multi-agent security scans with configurable workers and discovery runs. The tool integrates with Linear for issue tracking, supports multiple inference providers (OpenAI, OpenRouter, Fireworks, AWS Bedrock), and can be used locally, in CI pipelines, or as containerized bulk scans. Developers can customize scan behavior with prompt files, knowledge bases, and fine-tuned stopping conditions.
Key Features
Use Cases
- 01Automated security audits of codebases in CI/CD pipelines using environment API keys
- 02Deep multi-agent vulnerability discovery with extended time limits for large repositories
- 03Importing Linear security issues and automatically generating fixes using patch commands
- 04Comparing security findings across Git revisions to track new, resolved, or persisting vulnerabilities
- 05Bulk scanning multiple repositories with shared security knowledge bases and custom prompts
- 06Using alternative LLM providers like Claude or Qwen for security scanning in air-gapped environments
Related Agents
View morehermes-agent
The agent that grows with you
agency-agents
A complete AI agency at your fingertips - From frontend wizards to Reddit community ninjas, from whimsy injectors to reality checkers. Each agent is a specialized expert with personality, processes, and proven deliverables.
openinterpreter
A coding agent for open models like Kimi K3
cline
Autonomous coding agent as an SDK, IDE extension, or CLI assistant.
codex-security — FAQ
What is Codex Security?+
Codex Security is an AI sub-agent from OpenAI that uses large language models to autonomously scan code for security vulnerabilities, validate findings, and generate fixes. It supports both quick scans and deep multi-agent discovery modes with configurable workers.
How do I install the Codex Security AI sub-agent?+
Install via npm with 'npm install @openai/codex-security', then authenticate using 'npx @openai/codex-security login' or set OPENAI_API_KEY/CODEX_API_KEY environment variables for CI. Requires Node.js 22.13+, 24.x, or 26.x and Python 3.10 or later.
Which AI clients and LLM providers work with Codex Security?+
Codex Security works with OpenAI models (GPT-5.6), Anthropic Claude via OpenRouter, Fireworks AI, and AWS Bedrock. It can be integrated into ChatGPT workflows and supports programmatic use through its TypeScript SDK.
Do I need an API key to use Codex Security?+
You need either ChatGPT sign-in access to Codex Security or an OpenAI/Codex API key. For alternative providers, you'll need their respective API keys (OPENROUTER_API_KEY, FIREWORKS_API_KEY, or AWS credentials). Some cybersecurity features require Trusted Access for Cyber approval.
Is Codex Security free?+
The README does not specify pricing. Access requires approval through Codex Security and may require Trusted Access for Cyber for certain features. Check chatgpt.com/cyber for access details.
Can I use Codex Security with Linear for issue tracking?+
Yes, you can publish scan findings directly to Linear teams and projects using either your Codex sign-in with connected Linear app or a Linear personal API key. The publish command creates issues with vulnerability details, code locations, and remediation guidance.
How do I install codex-security?+
Open the source repository on GitHub and follow its README. codex-security is a agent — MCP Agents Market links you directly to the official repo.
Is codex-security free?+
codex-security is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.