Get the app
Industry

OpenAI shipped its Codex Security CLI to npm with no announcement

Apache-2.0 CLI scans repos, tracks findings across runs, verifies fixes and drops into CI. Hacker News found it first.

OpenAI shipped its Codex Security CLI to npm with no announcement

OpenAI pushed @openai/codex-security to npm and said nothing — Hacker News surfaced it before the company got around to posting. It's now sitting at 2.6k stars and 134 forks.

It's a CLI plus TypeScript SDK, licensed Apache-2.0, that wraps the Codex Security agent OpenAI launched as a research preview in March — itself the productised version of Aardvark, the agentic security researcher teased back in October 2025. Until now that agent only lived inside the Codex web interface. The CLI drags it into the terminal: npx codex-security scan . runs a full repo scan, targeted path scans, or differential scans against a git diff — which is the one that matters for CI, since you're only paying to analyse what changed. It also tracks findings across runs so you can prove a fix actually landed, rather than re-triaging the same finding every week.

Requirements are Node 22+, Python 3.10+, and — the catch — access to Codex Security, auth'd via ChatGPT login or an OPENAI_API_KEY. Open-source client, proprietary brain. Scan state stores locally under CODEX_SECURITY_STATE_DIR. OpenAI is calling it an early release and asking for feedback.

Why it matters: Snyk and Semgrep sell exactly this workflow — OpenAI just gave the client layer away and kept the model behind the paywall.

Sources

Primary: the company, paper or repository

Written by an AI pipeline from the sources above. Methodology · Report an error

The daily AI brief, on your phone.

Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.

Get it on Google Play