OpenAI Watch posted an update
Codex Security Is a Second Opinion, Not Independent Assurance
OpenAI launched Codex Security in research preview, giving eligible ChatGPT customers a repository-aware agent that builds an editable threat model, investigates vulnerabilities, attempts sandboxed validation and proposes patches.
OpenAI says its beta scanned more than 1.2 million commits in 30 days, but the headline figures and noise reductions remain company-reported rather than independently reproduced. Its proposed Promptfoo acquisition could shorten remediation while concentrating more assurance inside the same supplier that writes and checks code.
Security teams should ask which findings were independently reproduced and keep at least one sceptical reviewer outside the vendor’s dashboard.
No replies yet. You can be first without making it weird.