Codex Security

Run OpenAI's agentic security scanner (`@openai/codex-security`) over a repo, PR, or diff, then triage, patch, and gate on its findings. Use for 'run a codex security scan', 'find vulnerabilities in this PR', 'export findings as SARIF', 'fix that security finding', 'compare this scan to the last one', or when a pattern sweep came back thin. Not for dependency CVEs, secrets, or licenses (code-audit-scripts, bun audit).

b-open-io Updated

File contents

b-open-io/prompts/tree/main/modules/review/skills/codex-security commit 6b6389f773

Frequently asked questions

npx skillmds@latest add b-open-io-prompts/codex-security