← Back to blog

Codex Security Cloud still waits for you to open the pull request

Codex Security Cloud is the cloud plugin in OpenAI’s Codex Security product: it scans GitHub repositories you connect, in Codex cloud, while your laptop can be closed. OpenAI’s docs put it in research preview on the web and in the desktop app. It is not the local Codex Security plugin, and it does not merge its own patches.

The load-bearing control is the button you have to press: Create draft pull request.

Two plugins, one name

OpenAI’s overview splits the product on purpose. The Codex Security plugin runs local scans inside a Codex task, with a desktop Security workbench, a CLI, and a TypeScript SDK published as @openai/codex-security. Codex Security Cloud is a separate plugin. It scans connected GitHub repositories in Codex cloud. Install it from Plugins, then follow cloud setup to connect GitHub and start a scan.

Access is a workspace entitlement. If the plugin is missing, OpenAI tells you to ask a workspace admin. The public docs do not publish a plan matrix or a token price for a large monorepo scan. Do not invent one.

The loop

The cloud FAQ describes four stages:

  1. Analysis builds a threat model: project overview, entry points, trust boundaries, auth assumptions, risky components.
  2. Scanning is either a one-shot Repository scan or Commit changes, which watches new commits and can look at existing history.
  3. Validation tries to reproduce a likely issue in an ephemeral container. A successful reproduction is what gets marked validated. A failed reproduction stays unvalidated, with the logs of the attempt.
  4. Remediation is guidance and, when the model can produce one, a proposed patch. You review it, then choose Create draft pull request. The FAQ says the patch does not modify your branch by itself.

Each analysis and validation job clones the repo into an ephemeral Codex container and tears that container down when the job ends. A compile is not required to produce findings. During validation, Codex may try to build the project inside the container if that helps reproduce the issue.

OpenAI is explicit that this complements SAST. It does not replace deterministic scanners, and it does not replace a human threat assessment. For a monitored repo you can edit the generated threat model under Monitoring settings as the architecture changes. You can also pause monitoring without disconnecting the repo.

What is not in the docs

There is no independent false-positive bake-off in the sources for this post. OpenAI does not publish how Codex Security Cloud compares with a named SAST vendor on a shared corpus. Scan duration is “it depends,” with progress on the Scans screen. Billing for deep history and large monorepos is not specified on the FAQ. Those are open questions, not missing paragraphs to fill from memory.

Monday

  • Confirm the workspace actually has Codex Security Cloud before you promise a pilot.
  • Connect one low-stakes repo. Use a Repository scan before you turn on commit monitoring.
  • Read the threat model before you trust the ranking. Edit it if the entry points are wrong.
  • Treat “validated” as “reproduced in their container,” then run your own tests before anyone merges the draft PR.
  • Keep the SAST you already have. OpenAI says this product does not replace it.

Sources

← Back to blog