GitHub radar

OpenAI CLI to scan vulnerabilities with AI Published:

Codex Security is a CLI/TypeScript SDK that lets you use Codex to scan for and remediate security issues in your code (even automating a draft pull request with patches).

01openai/codex-security 10kTypeScript

Codex Security is the official OpenAI CLI and TypeScript SDK for AI-driven code security. Scan your code with Codex to detect security issues, verify them, and generate patch proposals. Enable automatic patching of “high” and “critical” issues with --patch --patch-severity high, commit modified files and create a draft Pull Request on GitHub with --create-pr. Scan all components in your monorepo independently and aggregate issues by root cause with scan-components. Use multiple subagents for deep scan mode (up to 96 hours), or run on OpenAI, Amazon Bedrock, OpenRouter, or any other OpenAI-compatible platform (e.g. Anthropic via OpenRouter). Launched two months ago and already over 10,000 stars! Works with Node.js >= 22 & Python >= 3.10, requires a ChatGPT account with access to Codex Security or an OPENAI_API_KEY.

Why a vibe-coder should care

If you’d like to automate a process where an AI model inspects your code for security vulnerabilities and automatically patches them (without manual intervention), Codex Security handles all steps from detection to PR. Especially powerful for projects where security is currently only checked in CI without a separate check phase.

How to install

Copy this and send it to your agent — Claude Code, Codex, any of them:

Install and run Codex Security: https://github.com/openai/codex-security — do npm install @openai/codex-security, scan the current project with npx @openai/codex-security scan . and show me the found vulnerabilities. You need OPENAI_API_KEY or a ChatGPT account with Codex Security access — ask me if you don't have it.

Runs on a regular laptop — Node.js 22+ and Python 3.10+ required. Scanning goes through the cloud Codex API, no GPU needed.

Open on GitHub