No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by openai · Codex Skill · ★ 10.0k
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is codex-security safe to install? View the security audit →
Codex Security is a CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in your code. See the Codex Security documentation for more details. Note: for best results, we recommend that your account is verified for Trusted Access. Quick start Requires Node.js 22.13.0 or later in the 22.x release line, Node.js 24.x, or Node.js 26.x; Python 3.10 or later; and access to Codex Security. For CI, set or instead of signing in. Environment API keys are passed directly to the current scan and are never stored in Codex's credential home or system keyring. Local sign-in honors Codex's configured credential backend, including a system keyring required by a managed device. Codex Security keeps login and scan credentials in the same private, persistent state directory. If both a ChatGPT sign-in and an API key are available, interactive scans ask which credential to use. CI and other noninteractive scans keep the existing API-key precedence. Select a credential explicitly when needed: To make your ChatGPT sign-in the aut
| Stars | 9,967 |
| Forks | 704 |
| Language | TypeScript |
| Category | Codex Skill |
| License | Apache-2.0 |
| Quality Score | 66.8550750017929/100 |
| Open Issues | 192 |
| Last Updated | 2026-08-19 |
| Created | 2026-07-13 |
| Platforms | cli, codex, node |
| Est. Tokens | ~14k |
These tools work well together with codex-security for enhanced workflows:
Looking for a codex-security alternative? If you're comparing codex-security with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Zero-Config Code Flow for Claude code & Codex
📦 Repomix is a powerful tool that packs your entire repository into a single, AI-friendly file. Perfect for w
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE
⌥ AI Coding agent for the terminal — hash-anchored edits, optimized tool harness, LSP, Python, browser, subag
Code search MCP for Claude Code. Make entire codebase the context for any coding agent.
AI Agent Engineering Platform built on an Open Source TypeScript AI Agent Framework
Explore other popular codex skill tools:
codex-security is OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security. It is categorized as a Codex Skill with 10.0k GitHub stars.
codex-security is primarily written in TypeScript. It covers topics such as ai-security, application-security, cli.
You can find installation instructions and usage details in the codex-security GitHub repository at github.com/openai/codex-security. The project has 10.0k stars and 704 forks, indicating an active community.
codex-security is released under the Apache-2.0 license, making it free to use and modify according to the license terms.
The top alternatives to codex-security on Agent Skills Hub include zcf, repomix, Anthropic-Cybersecurity-Skills. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.