OpenAI releases Codex Security, an agent-driven vulnerability scanner
OpenAI open-sourced Codex Security, a TypeScript SDK for agent-driven vulnerability scanning. Its pipeline of discovery, validation, patch and verification agents scans code in parallel, filters false positives, generates patches and tests them. It requires Node.js 22.13+ and Python 3.10+.
- The TypeScript SDK has already passed 11,000 stars on GitHub
- Discovery workers scan the repository in parallel and deduplicate findings
- The patch agent proposes diffs but never commits them without human review
- Findings export to SARIF, JSON/CSV and Linear issues
Read next
Security