OpenAI Launches Codex Security Agent for Devs
Curated by the Inblix editorial team
OpenAI just dropped Codex Security, an application security agent that actually understands your project’s context. Instead of drowning you in false positives like most AI security tools, it finds real vulnerabilities by building a threat model of your system. It started as a private beta called Aardvark, where it caught critical issues like an SSRF and a cross-tenant auth flaw. The team slashed noise by 84% on one repo and cut over-reported severity by 90%+. Basically, it validates findings in sandboxed environments so you only see what matters. It’s rolling out to ChatGPT Pro, Enterprise, Business, and Edu users for free this month. Why it matters: As AI accelerates development, security review becomes the bottleneck—tools that ship high-confidence fixes could finally let teams move fast without breaking things.
💡 Key Takeaways
- Codex Security builds an editable threat model of your codebase to find context-aware vulnerabilities instead of generic false positives.
- The agent validates findings in sandboxed environments, reducing noise by over 84% and cutting false positive rates by more than 50%.
- It's available in research preview to ChatGPT Pro, Enterprise, Business, and Edu users with free usage for the first month.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.