Codex Security Plugin: Scan Your Code for Vulnerabilities in One Click with OpenAI

·Toolin Editorial Team

OpenAI's Codex Security plugin scans your code for vulnerabilities inside Codex, verifies exploitability, and proposes fixes — with a complete getting-started walkthrough.

Codex Security Plugin: Scan Your Code for Vulnerabilities in One Click with OpenAI

Code security review is famously tedious and easy to get wrong. OpenAI has turned it into a Codex plugin — Codex Security, currently in research preview. It scans your codebase, finds vulnerabilities, verifies whether they're actually exploitable, and then suggests fixes. Per StackHawk's tally, during private testing it scanned 1.2 million commits and surfaced more than 10,000 high-severity findings. Here's how to use it.

The Problem It Solves

The chronic weakness of traditional security scanners is false positives: they surface a pile of "possible vulnerabilities," and developers still have to verify each one by hand. Codex Security's core pitch is inserting a step between "detect" and "report" — verification: it actually tests whether the vulnerability can be exploited, filters out the false positives, and hands you only "real issue + evidence + fix."

Official definition: Codex Security is a security review plugin for Codex that scans code for vulnerabilities, validates legitimate findings, and presents the evidence and remediation guidance as a reviewable workspace. Use it for a security checkup on code you own before shipping.

Step 1: Install the Plugin

Open the repository you want to review in the Codex App, then install the Codex Security plugin (an official install entry point is provided).

After installing, you must start a new thread — Codex loads plugins when a thread starts, so the plugin won't take effect in an existing one.

💡 Tip: If you use the Codex CLI, start Codex in the repository, then open the plugin browser:

codex
/plugins

Search for Codex Security, choose Install plugin, then start a new thread.

Step 2: Run Your First Scan

For the best scan quality, the official recommendation is the gpt-5.5 model with high or xhigh reasoning effort.

Send this directly in the new thread:

Run a Codex Security scan on this repository.

Codex opens a configuration workspace before the scan starts. For a first run, these settings are recommended:

  • Scan type: Codebase
  • Deep scan: Off (run a standard scan first for quick results)
  • Scan area: Entire codebase
  • Threat model scoping guidance: leave blank unless you already know a specific attack vector or application domain that needs priority attention

Confirm that Codebase / Current branch / Last commit point at the repository you want scanned, then click Start scan.

Step 3: Wait for the Scan to Finish

The scan takes time; keep the thread running until the workspace reports completion. If Codex identifies a configuration constraint, it will first lay out the specific constraint and the proposed change, and only modify the config after you confirm.

Step 4: Review the Results

When the scan completes, a findings workspace opens, letting you browse findings and coverage without digging through the raw files. You can filter by severity, category, directory, patch status, and review status.

Each scan also produces these artifacts:

  • report.md: a complete, portable report for sharing or archiving
  • Structured scan data: scan-manifest.json, findings.json, and coverage.json, for automation and integrations (you usually won't open these by hand)

Optional Follow-Up Workflows

After the first run, the official docs list several paths to go deeper:

  • Standard / scoped scans: scan the whole repository or a single folder using the default flow
  • Deep scan: more thorough, but takes longer
  • Review code changes: for a PR, a single commit, a branch range, or a workspace patch
  • Triage a backlog: for when you already have a batch of security findings that need re-checking
  • Fix and verify: after accepting a finding, have Codex produce a patch and verify the fix
  • Export / track findings: export JSON, CSV, or SARIF, create Linear / GitHub / Jira tickets that require approval, or even a draft private GitHub Security Advisory

Who It's For

  • Application security teams: treat Codex Security as "a scanner that verifies," cutting the manual effort of triaging false positives
  • Development teams: put a security gate at the PR / commit level so problems never reach main
  • Open-source maintainers: scan historical codebases and triage the security backlog

The One-Line Takeaway

Codex Security's differentiator is "verification" — it doesn't just report vulnerabilities, it tests whether they can genuinely be exploited, then hands over evidence and a patch. Integrated into the Codex workflow, it feels more like a resident security review partner than an install-and-forget scanner. At the research preview stage, it's best to try it out on your own repositories first.