According to Beating, OpenAI has open-sourced the Codex Security command-line tool and TypeScript SDK on July 29, allowing developers to scan code repositories, check new commits, and log detected issues. The tool can identify potential vulnerabilities and attempt to reproduce them in an isolated environment before generating fix recommendations for developer review.
The open-sourced component covers task management and scanning execution only. The core analysis, vulnerability verification, and patch generation remain operated by OpenAI. Users must log in with an OpenAI account and obtain Codex Security permissions to access full functionality. The service is currently in research preview, available to ChatGPT Pro, Business, Edu, and Enterprise users, with enterprise accounts potentially requiring admin approval.