Codex Security vs PentAGI
Codex Security (OpenAI) and PentAGI (VXControl) side by side on public data, as of Oct 10, 2026.
PentAGI has 2.3x the GitHub stars of Codex Security (25.4K against 11K). Codex Security shipped 30 stable releases in the past 90 days. PentAGI shipped 1 stable releases in the past 90 days.
Side-by-side numbers
| Metric | Codex Security | PentAGI |
|---|---|---|
| Gid Score | 73 | 31 |
| Overall rank | #10 | #196 |
| Downloads, last 7 days | — | — |
| Downloads, 7-day change | — | — |
| Downloads, 30-day change | — | — |
| VS Code installs | — | — |
| Marketplace rating | — | — |
| GitHub stars | 11K | 25.4K |
| Homebrew installs, 30 days | — | — |
| Hacker News mentions, 30 days | 204 | 0 |
| Latest stable release | 0.2.0 · 4d ago | 2.2.0 · 5d ago |
| Stable releases, 90 days | 30 | 1 |
| Terminal-Bench (best run) | — | — |
| Price | Free (OSS) | Free (OSS) |
| License | Apache-2.0 | MIT |
| First released | July 2026 | January 2025 |
| Interfaces | — | — |
| Models |
Trends
Codex Security
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
Pricing: Open source under the Apache-2.0 licence; check the website for any paid hosted plans.
Latest release 0.2.0:
- Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact…
- Scans now check for exposed credentials in source code, including unused code and tests, and distinguish suspected exposures from placeholders. This check runs offline, without trying discovered…
- Use --model and --effort when generating patches, validating findings, verifying fixes, or matching and comparing saved scans. Deep Scan workers and patches generated during a scan also respect…
- Patch, validation, and fix-verification commands now respect custom model providers and their authentication settings. Amazon Bedrock users get clearer authentication errors and cost estimates for…
PentAGI
A self-hosted multi-agent system that carries out penetration testing tasks in a sandboxed environment, written in Go and React and working with several model providers.
Pricing: Free and open source (MIT), self-hosted; users pay their own model costs.
Latest release 2.2.0:
- Reasoning the way each vendor expects it — adaptive thinking, effort levels, thinking budgets, and a real "off" are sent in each model family's native form. Combinations a vendor would reject are…
- Three new providers — MiniMax, Mistral, and xAI, for 13 provider types in total. Any other OpenAI-compatible endpoint works through the custom provider, which now also calls Azure OpenAI…
- Tested, not just listed — every built-in provider, plus example configurations for OpenRouter, DeepInfra, Ollama Cloud, self-hosted vLLM, and others, ships with a ctester report in examples/tests/…
- Current catalogues — GPT-6, Claude Opus 5.x and Fable 5.x, Gemini 3.x, Qwen 3.8, GLM 5.3, DeepSeek V4, and Grok 4.7, with prices checked against vendor pages. Agent chains are compacted to the…