Skip to content
Agents tracked: 378 Downloads (7d): 244M down 5.7% GitHub stars: 8.4M VS Code installs: 151M Releases (7d): 407 Agent status: 1 with issues Updated Oct 10, 2026

Codex Security by OpenAI

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security

AI security agents New · New project: repository created Jul 13, 2026Open source · Apache-2.0Free to start

Recently added on Oct 10, 2026. The description, category and pricing were filled in from public metadata and have not been checked by an editor yet.

Price
Free (OSS)
free and open source
Popularity
#1 in Security
Gid Score 73 / 100 · #10 of 378 overall
Trend
Gaining stars
about +15 GitHub stars a day
Development
Actively updated
latest 0.2.0, 4d ago
Community
11K GitHub stars
public signals

What Codex Security does

Key facts

MakerOpenAI
First releasedJuly 2026
LicenseApache-2.0
Main languageTypeScript
Open issues and PRs214

Pricing

Open source under the Apache-2.0 licence; check the website for any paid hosted plans.

, checked Oct 10, 2026. Prices change often; confirm before you buy.

Compare prices of all agents

Quick answers

Compare Codex Security with another agent

vs
# Agent Gid Score Downloads 7d 7d 30d VS Code installs Stars Latest release Price
196
PentAGIVXControl
31 — — — — 25.4K+29/day 2.2.05d ago Free (OSS)
226
StrixStrix
25 9,808 up 11.5% down 49.7% — 67.6K+209/day 1.7.05d ago Free + $29/mo
266
NodeZeroHorizon3.ai
18 — — — — — — Custom
293
XBOWXBOW
11 — — — — — — Usage-based
294 10 536 down 10.4% down 46.4% — 9,846+2/day — Free
307
Dropzone AIDropzone AI
0 — — — — — — Custom

Head to head: Codex Security vs PentAGI · Codex Security vs Strix · Codex Security vs NodeZero · Codex Security vs XBOW

Ratings from people who use Codex Security

No ratings yet. Used Codex Security? Rate it and say what it is good and bad at.

Codex Security news

All AI agent news

  1. New on AgentGid AgentGid

    74 agents added to AgentGid

    Symphony, OpenShell, Codex Security, NemoClaw, Agent Browser, Opensre, Caveman, Brag, Open Code Review, Understand-Anything, Codegraph, BrowserSkill and 62 more

  2. Release GitHub Releases

    Codex Security 0.2.0 released

    Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact…; Scans now check for exposed credentials in source code, including…

What changed: recent Codex Security releases

30 stable releases in the last 90 days · Full changelog

0.2.0
  • Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact…
  • Scans now check for exposed credentials in source code, including unused code and tests, and distinguish suspected exposures from placeholders. This check runs offline, without trying discovered…
  • Use --model and --effort when generating patches, validating findings, verifying fixes, or matching and comparing saved scans. Deep Scan workers and patches generated during a scan also respect…
  • Patch, validation, and fix-verification commands now respect custom model providers and their authentication settings. Amazon Bedrock users get clearer authentication errors and cost estimates for…
  • Scans include previously overlooked C++ headers (.hh and .hxx), server-rendered templates (EJS, ERB, and PHTML), and Vyper source files when selecting code to review. (#1079, #1197,
  • On Unix, scans check that the sandbox works before starting paid model calls. Completed results are kept if you cancel follow-up work. CSV exports can now be reimported without rejecting multiple…
0.1.30
  • bump the third-party group across 2 directories with 2 updates
  • bump ruff from 0.16.6 to 0.16.7 in /plugins/codex-security
  • bump the codex group across 3 directories with 2 updates
  • build the native runtime without the SDK
  • set up Python for Windows package verification
  • report full-output scan failures as errors
0.1.29
  • stream large saved scan JSON output
  • prefer complete saved rollout copies
  • support custom patch validation prompts
  • bump @opencode-ai/sdk from 1.18.29 to 1.18.30 in /plugins/codex-security/skills/triage-finding/evals in the third-party group across 1 directory
  • bump @linear/sdk from 93.0.1 to 94.0.0 in /sdk/typescript
  • seal drafts with empty artifact lists
0.1.28
  • use versioned conventional commit titles
  • share scan settings across the CLI and SDK
  • keep parameterized JUnit names unique
  • accept large saved post-scan prompts
  • make cost display optional
  • collect Desktop and worker session logs
0.1.26
  • Classify finding severity with custom rubrics and supporting context through
  • Match repeated findings across scan history, preserving confirmed identities
  • Open draft GitLab merge requests for verified patches with the existing
  • Report component scan progress in headless runs and exclude replayed usage
  • Preserve analytics settings in finding workflows and allow 120 seconds for
  • Require an explicit request before invoking the security fix verification
0.1.25
  • Preserve confirmed finding identities across scans and comparisons, and show
  • Improve deduplication with separate screening and pair reviews, validated
  • Generate synthetic Standard scan results with scan --mock or the SDK's
  • Increase a running scan's total budget from the interactive dashboard when
  • Recognize existing Codex authentication in CLI and SDK login status. SDK
  • Configure the findings service's full embeddings endpoint with

Codex Security popularity and usage data

The GitHub repository has 11K stars, 484 of them added in the last 30 days. The latest stable release is 0.2.0, published Oct 6, 2026; there were 4 stable releases in the past 30 days. It was mentioned in 204 Hacker News posts and comments over the last 30 days.

GitHub starsrunning total 11K
Hacker News mentionsposts and comments, rolling 7-day total 34 this week
Website rankTranco list; a lower rank means more traffic #105

Download the raw daily series: codex-security.csv

Gid Score breakdown

Adoption100
Community44
Attention58
Momentum52

Each component is scored 0 to 100 from public signals; a dash means no data for it. Methodology.

Codex Security FAQ

How much does Codex Security cost?

Open source under the Apache-2.0 licence; check the website for any paid hosted plans.

Is Codex Security open source?

Yes. Codex Security is open source, released under the Apache-2.0 license.

How popular is Codex Security?

The GitHub repository has 11K stars, 484 of them added in the last 30 days. The latest stable release is 0.2.0, published Oct 6, 2026; there were 4 stable releases in the past 30 days. It was mentioned in 204 Hacker News posts and comments over the last 30 days.

What is the latest version of Codex Security?

The latest stable release we track is 0.2.0, published on Oct 6, 2026.

What are the alternatives to Codex Security?

The closest alternatives in the same category by Gid Score are PentAGI, Strix, NodeZero, XBOW.

For the makers of Codex Security badges, corrections

Add a live badge to your README or site:

AgentGid: #1 in Security Gid Score: 73/100

[![AgentGid: #1 in Security](https://agentgid.com/badges/codex-security-rank.svg)](https://agentgid.com/agents/codex-security/)
[![Gid Score: 73/100](https://agentgid.com/badges/codex-security-score.svg)](https://agentgid.com/agents/codex-security/)

Something wrong or outdated on this page? Send a correction with a link to the official source. More for makers.

Where these numbers come from

GitHub: openai/codex-security. Site rank: openai.com on the Tranco list. See data sources for how each one is collected.

Product facts and pricing were checked against: developers.openai.com, github.com.