</>MCP Agents Market
Agent

codex-security

by openai9.9kTypeScriptUpdated 2026-08-16

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security

ChatGPTCodex

Codex Security is an AI-powered security sub-agent CLI and TypeScript SDK from OpenAI that autonomously discovers, validates, and fixes security vulnerabilities in codebases. It uses large language models (including GPT-5.6, Claude, and others) to perform both quick and deep multi-agent security scans with configurable workers and discovery runs. The tool integrates with Linear for issue tracking, supports multiple inference providers (OpenAI, OpenRouter, Fireworks, AWS Bedrock), and can be used locally, in CI pipelines, or as containerized bulk scans. Developers can customize scan behavior with prompt files, knowledge bases, and fine-tuned stopping conditions.

Key Features

Multi-agent deep scanning with configurable workers, sub-agents, and discovery run limits up to 96 hours
Support for multiple LLM providers including OpenAI, Anthropic Claude, OpenRouter, Fireworks, and AWS Bedrock
Custom scan prompts via files and knowledge base integration for security policy enforcement
Linear integration for publishing findings as issues with team and project assignment
Scan history and comparison tools that match findings by root cause across scans
TypeScript SDK for programmatic security scans and CI/CD integration
Containerized bulk scanning with Docker Compose for immutable Git revisions
Flexible authentication supporting ChatGPT sign-in, API keys, and system keyrings

Use Cases

  • 01Automated security audits of codebases in CI/CD pipelines using environment API keys
  • 02Deep multi-agent vulnerability discovery with extended time limits for large repositories
  • 03Importing Linear security issues and automatically generating fixes using patch commands
  • 04Comparing security findings across Git revisions to track new, resolved, or persisting vulnerabilities
  • 05Bulk scanning multiple repositories with shared security knowledge bases and custom prompts
  • 06Using alternative LLM providers like Claude or Qwen for security scanning in air-gapped environments

Related Agents

View more

codex-security — FAQ

What is Codex Security?+

Codex Security is an AI sub-agent from OpenAI that uses large language models to autonomously scan code for security vulnerabilities, validate findings, and generate fixes. It supports both quick scans and deep multi-agent discovery modes with configurable workers.

How do I install the Codex Security AI sub-agent?+

Install via npm with 'npm install @openai/codex-security', then authenticate using 'npx @openai/codex-security login' or set OPENAI_API_KEY/CODEX_API_KEY environment variables for CI. Requires Node.js 22.13+, 24.x, or 26.x and Python 3.10 or later.

Which AI clients and LLM providers work with Codex Security?+

Codex Security works with OpenAI models (GPT-5.6), Anthropic Claude via OpenRouter, Fireworks AI, and AWS Bedrock. It can be integrated into ChatGPT workflows and supports programmatic use through its TypeScript SDK.

Do I need an API key to use Codex Security?+

You need either ChatGPT sign-in access to Codex Security or an OpenAI/Codex API key. For alternative providers, you'll need their respective API keys (OPENROUTER_API_KEY, FIREWORKS_API_KEY, or AWS credentials). Some cybersecurity features require Trusted Access for Cyber approval.

Is Codex Security free?+

The README does not specify pricing. Access requires approval through Codex Security and may require Trusted Access for Cyber for certain features. Check chatgpt.com/cyber for access details.

Can I use Codex Security with Linear for issue tracking?+

Yes, you can publish scan findings directly to Linear teams and projects using either your Codex sign-in with connected Linear app or a Linear personal API key. The publish command creates issues with vulnerability details, code locations, and remediation guidance.

How do I install codex-security?+

Open the source repository on GitHub and follow its README. codex-security is a agent — MCP Agents Market links you directly to the official repo.

Is codex-security free?+

codex-security is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches