OpenAI Open-Sources Codex Security to 3.7K Stars — and HN Immediately Reports Scans Burning Half a Week's Token Quota
OpenAI released Codex Security, a CLI and TypeScript SDK with 13 pre-built security skills that scans repos, reviews diffs, tracks findings over time, and runs in CI; it requires Node 22+ and Python 3.10+ and has reached 3.7k stars, 206 forks, and 111 commits. The 525-point, 190-comment HN thread is largely negative on economics and guardrails: one user burned 25% of weekly Pro credits on a ~40-minute scan that failed, another lost half a week's tokens to a 50-minute scan with no output, and the tool repeatedly refuses to report vulnerabilities it finds as a 'cybersecurity risk' unless you have Trusted Access for Cyber. Code is uploaded to OpenAI for analysis, ruling it out for data-residency-constrained orgs, and there is no resume for interrupted scans.
↳ Follow the thread