Codex Security Plugin: Scan Your Code for Vulnerabilities in One Click with OpenAI
·Toolin Editorial Team
OpenAI's Codex Security plugin scans your code for vulnerabilities inside Codex, verifies exploitability, and proposes fixes — with a complete getting-started walkthrough.
2026-07-09· Toolin Editorial Team
Codex Security Plugin: Scan Your Code for Vulnerabilities in One Click with OpenAI
OpenAI's Codex Security plugin scans your code for vulnerabilities inside Codex, verifies exploitability, and proposes fixes — with a complete getting-started walkthrough.
Code security review is famously tedious and easy to get wrong. OpenAI has turned it into a Codex plugin — Codex Security, currently in research preview. It scans your codebase, finds vulnerabilities, verifies whether they're actually exploitable, and then suggests fixes. Per StackHawk's tally, during private testing it scanned 1.2 million commits and surfaced more than 10,000 high-severity findings. Here's how to use it.
The chronic weakness of traditional security scanners is false positives: they surface a pile of "possible vulnerabilities," and developers still have to verify each one by hand. Codex Security's core pitch is inserting a step between "detect" and "report" — verification: it actually tests whether the vulnerability can be exploited, filters out the false positives, and hands you only "real issue + evidence + fix."
Official definition: Codex Security is a security review plugin for Codex that scans code for vulnerabilities, validates legitimate findings, and presents the evidence and remediation guidance as a reviewable workspace. Use it for a security checkup on code you own before shipping.
The scan takes time; keep the thread running until the workspace reports completion. If Codex identifies a configuration constraint, it will first lay out the specific constraint and the proposed change, and only modify the config after you confirm.
When the scan completes, a findings workspace opens, letting you browse findings and coverage without digging through the raw files. You can filter by severity, category, directory, patch status, and review status.
Each scan also produces these artifacts:
report.md: a complete, portable report for sharing or archiving
Structured scan data: scan-manifest.json, findings.json, and coverage.json, for automation and integrations (you usually won't open these by hand)
After the first run, the official docs list several paths to go deeper:
Standard / scoped scans: scan the whole repository or a single folder using the default flow
Deep scan: more thorough, but takes longer
Review code changes: for a PR, a single commit, a branch range, or a workspace patch
Triage a backlog: for when you already have a batch of security findings that need re-checking
Fix and verify: after accepting a finding, have Codex produce a patch and verify the fix
Export / track findings: export JSON, CSV, or SARIF, create Linear / GitHub / Jira tickets that require approval, or even a draft private GitHub Security Advisory
Codex Security's differentiator is "verification" — it doesn't just report vulnerabilities, it tests whether they can genuinely be exploited, then hands over evidence and a patch. Integrated into the Codex workflow, it feels more like a resident security review partner than an install-and-forget scanner. At the research preview stage, it's best to try it out on your own repositories first.