Skip to content
Agents tracked: 378 Downloads (7d): 244M down 5.7% GitHub stars: 8.4M VS Code installs: 151M Releases (7d): 407 Agent status: 1 with issues Updated Oct 10, 2026
Release GitHub Releases

Codex Security 0.2.0 released

Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact…; Scans now check for exposed credentials in source code, including…

What changed

  • Threat models are now saved with Standard, Deep, and Diff scan results and generated security policies. Export a saved model without another model call using codex-security export --artifact…
  • Scans now check for exposed credentials in source code, including unused code and tests, and distinguish suspected exposures from placeholders. This check runs offline, without trying discovered…
  • Use --model and --effort when generating patches, validating findings, verifying fixes, or matching and comparing saved scans. Deep Scan workers and patches generated during a scan also respect…
  • Patch, validation, and fix-verification commands now respect custom model providers and their authentication settings. Amazon Bedrock users get clearer authentication errors and cost estimates for…
  • Scans include previously overlooked C++ headers (.hh and .hxx), server-rendered templates (EJS, ERB, and PHTML), and Vyper source files when selecting code to review. (#1079, #1197,
  • On Unix, scans check that the sandbox works before starting paid model calls. Completed results are kept if you cancel follow-up work. CSV exports can now be reimported without rejecting multiple…
  • If your integration reads threat models, check SecurityPolicyDraft.threatModelPath for null before opening the file. Policy generation now writes threatmodel.md instead of THREATMODEL.md; use the…
  • Findings service clients must send Content-Type: application/json to POST /v1/bulk/findings and POST /v1/dedupe-groups. Missing or other content types return HTTP 400 invalidrequest. A charset…

Generated from AgentGid's daily data on public sources. How we collect it.

The agent in this story

More about Codex Security

  1. New on AgentGid AgentGid

    74 agents added to AgentGid