openai/codex-security

Source
GitHub
First trending
Category
Security
GitHub stars
10,744
Main language
TypeScript
Website
developers.openai.com/codex/security (opens in a new tab)

This page introduces an external open-source repository. It is not an HDATF product.

openai/codex-security

What it does

Codex Security is a CLI and TypeScript SDK from OpenAI for defining security policy and for finding, validating and fixing vulnerabilities in code. It can also draft a SECURITY.md to guide later scans.

How it helps ATF

Its step of validating a finding before fixing it is a reference for how Harness checks a result with evidence. Keeping a written policy file that guides later scans is also worth comparing.

License

Apache-2.0 Permissive, with a patent grant. Commercial use is allowed; keep the notices and state your changes.

More in this category

  • guillaumemeyer/watermarks-remover
    An agent skill plus a Python service that strips AI provenance marks from content you own, such as invisible Unicode characters, statistical text watermarks and C2PA, EXIF or XMP metadata in files. The skill calls the service over HTTP.
  • usestrix/strix
    Strix runs AI agents that test an application the way attackers would: they execute the code, look for vulnerabilities and confirm them with working proofs of concept. It offers a CLI, multi-agent orchestration, suggested patches, reports and CI/CD use.
  • NationalSecurityAgency/ghidra
    Ghidra is a software reverse engineering framework created and maintained by the NSA Research Directorate. It analyzes compiled code with disassembly, decompilation, graphing and scripting, and supports many processor instruction sets and executable formats.
  • astrid-runtime/astrid
    A portable runtime, heading toward a standalone operating system, that runs WebAssembly capsules in a sandbox on macOS and Linux. Capsules talk through typed interfaces, and file, network, process and IPC access is checked at runtime boundaries.
  • cloudflare/security-audit-skill
    A coding-agent skill that runs a six-phase security audit of a repository. Isolated agents map the architecture, hunt for issues and try to disprove each candidate, and results are written as schema-validated findings and reports.

Only repositories in the ranked Trendshift lists are included, and the lists are used only to find candidates. We do not copy their ranks. Descriptions, licenses and star counts come from each GitHub repository. The notes are our own reading. We have not tested these projects, and a place on a trending list does not prove quality.

View on GitHub (opens in a new tab)