← Codex SecurityCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
removed
removed
removed
removed
Update to Codex Security
Snapshot Oct 4, 2026 · 12:03 UTC · version 0.1.31
Package or technical metadata updated
Algorithm: removed “RSA_PKCS1_SHA256”.
Observed in package metadata. These changes alone do not establish a new customer-facing feature.
Algorithm
Before
RSA_PKCS1_SHA256
After
Not present
Key id
Before
lITLhD2sQMkzmyYdQoOlErlyCSOM0m1gJ5jYZyzq3iQ
After
Not present
Sha256
Before
5cffee6f24001e77d3917795f89e61a4a6e925ba4769d02f0e7ccf8061ef88e8
After
Not present
Signature
Before
KdWxEd+cq1g98TuK3FZypL17hxGPZVRmEkSYJF1Njaa/W6F19pXmoCE/tx04BRvQgxQ7e0C7PsBQm0bH0hUee3AeAjgTS7jSkedkwZ4ExTpzbyHytCyZUkbiyJ9pidw+zl73H0WNwTiBABSOJ0VYW3Lrrt9TQFN35oY1KN2WG/2GgIo5ExBgRQlBQEciDYU89i9F4YpQn4xXKwqBioaJjAM3BLZr0Iaof7oKUq33idqF7...
After
Not present
Compare saved observations
Download comparison JSONFull technical diff · 4 changed fields
removed /release/algorithm
BEFORE
"RSA_PKCS1_SHA256"
AFTER
Field is absent
removed /release/key_id
BEFORE
"lITLhD2sQMkzmyYdQoOlErlyCSOM0m1gJ5jYZyzq3iQ"
AFTER
Field is absent
removed /release/sha256
BEFORE
"5cffee6f24001e77d3917795f89e61a4a6e925ba4769d02f0e7ccf8061ef88e8"
AFTER
Field is absent
removed /release/signature
BEFORE
"KdWxEd+cq1g98TuK3FZypL17hxGPZVRmEkSYJF1Njaa/W6F19pXmoCE/tx04BRvQgxQ7e0C7PsBQm0bH0hUee3AeAjgTS7jSkedkwZ4ExTpzbyHytCyZUkbiyJ9pidw+zl73H0WNwTiBABSOJ0VYW3Lrrt9TQFN35oY1KN2WG/2GgIo5ExBgRQlBQEciDYU89i9F4YpQn4xXKwqBioaJjAM3BLZr0Iaof7oKUq33idqF706MW2UHgAQ46rIPgUOl0Cc7K5Cws7Wh5iGjC/vlcvdG1EILuIan8ZzeDUNNnL8UPKKVBo3rlw4n5WK11yoD8kHSgO2XaVGOwTUKcRskXg=="
AFTER
Field is absent
Full snapshot data
{
"canonical_app_id": null,
"connector_id": null,
"created_at": "2026-05-14T00:26:39.198654Z",
"discoverability": "LISTED",
"id": "Plugin_1e648473be9c8191a91ac3947151af55",
"is_template": false,
"name": "codex-security",
"release": {
"app_ids": [
"asdk_app_69a089a326dc8191b32a3f2553f5be2c",
"connector_76869538009648d5b282a4bb21c3d157",
"connector_692de805e3ec8191834719067174a384"
],
"app_manifest": {
"apps": {
"atlassian": {
"capabilities": [
"read",
"write"
],
"category": "Work Tracking & Coordination",
"id": "connector_692de805e3ec8191834719067174a384"
},
"github": {
"category": "Code Hosting & Security Findings",
"id": "connector_76869538009648d5b282a4bb21c3d157"
},
"linear": {
"category": "Work Tracking & Coordination",
"id": "asdk_app_69a089a326dc8191b32a3f2553f5be2c"
}
}
},
"app_templates": [],
"description": "Codex Security workflows for security scans, analysis, and investigation.",
"display_name": "Codex Security",
"id": "pluginrel_6ab6b60d3b288191b945643ce5b4070c",
"interface": {
"brand_color": "#111111",
"capabilities": [
"Interactive",
"Read",
"Write"
],
"category": "Security",
"composer_icon_dark_url": null,
"composer_icon_url": "https://files.openai.com/content?id=file_00000000f73c81f583df4c30fb524aa6",
"default_prompt": "Run a Codex Security scan on this repository.",
"default_prompts": [
"Run a Codex Security scan on this repository.",
"Run a Codex Security diff scan on this PR, commit, branch diff, or working-tree patch.",
"Triage existing security findings against this repository."
],
"developer_name": "OpenAI",
"logo_url": "https://files.openai.com/content?id=file_00000000e6e081f58c772f187325eb6a",
"logo_url_dark": null,
"long_description": "Codex Security packages reusable workflows for security scans, analysis, validation, and investigation across code, diffs, and related artifacts.",
"plugin_category_id": "security",
"privacy_policy_url": "https://openai.com/policies/row-privacy-policy/",
"screenshot_urls": [],
"short_description": "Security scanning for your codebase",
"terms_of_service_url": "https://openai.com/policies/row-terms-of-use/",
"website_url": "https://openai.com/"
},
"keywords": [
"security",
"code-review",
"diff-review",
"appsec",
"threat-modeling"
],
"mcp_servers": [
{
"key": "codex-security",
"metadata": {
"args": [
"--stdio"
],
"command": "./scripts/launch_codex_security_mcp",
"cwd": ".",
"env_vars": [
"CODEX_HOME",
"CODEX_SQLITE_HOME",
"CODEX_API_KEY",
"CODEX_SAFETY_IDENTIFIER",
"CODEX_BROWSER_USE_NODE_PATH",
"CODEX_CLI_PATH",
"CODEX_ELECTRON_RESOURCES_PATH",
"CODEX_MANAGED_PACKAGE_ROOT",
"CODEX_MCP_NODE_PATH",
"OPENAI_API_KEY",
"OPENROUTER_API_KEY",
"FIREWORKS_API_KEY",
"AWS_BEARER_TOKEN_BEDROCK",
"AWS_ACCESS_KEY_ID",
"AWS_SECRET_ACCESS_KEY",
"AWS_SESSION_TOKEN",
"AWS_PROFILE",
"AWS_REGION",
"AWS_DEFAULT_REGION",
"AWS_CONFIG_FILE",
"AWS_SHARED_CREDENTIALS_FILE",
"AWS_ROLE_ARN",
"AWS_ROLE_SESSION_NAME",
"AWS_WEB_IDENTITY_TOKEN_FILE",
"AWS_CONTAINER_CREDENTIALS_RELATIVE_URI",
"AWS_CONTAINER_CREDENTIALS_FULL_URI",
"AWS_CONTAINER_AUTHORIZATION_TOKEN",
"AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE",
"PYTHON",
"PYTHONUTF8",
"CODEX_SECURITY_KNOWLEDGE_BASE",
"CODEX_SECURITY_CONFIG_PATH",
"CODEX_SECURITY_DEEP_SCAN_CONFIG_PATH",
"CODEX_SECURITY_SCAN_ROOT",
"CODEX_SECURITY_STATE_DIR",
"CODEX_SECURITY_SURFACE",
"HTTP_PROXY",
"HTTPS_PROXY",
"ALL_PROXY",
"NO_PROXY",
"SSL_CERT_FILE",
"REQUESTS_CA_BUNDLE",
"NODE_EXTRA_CA_CERTS",
"XDG_CACHE_HOME"
],
"startup_timeout_sec": 120,
"tool_timeout_sec": 349200
}
}
],
"onboarding_skill_name": null,
"requires_local_executor": true,
"skills": [
{
"description": "Assess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility. Use for generated patch files, provider pull-request diffs, or commit ranges when reviewers need evidence about affected runtime paths, contracts, tests, and recoverability. This skill is read-only and does not generate, edit, apply, push, or merge the patch.",
"interface": {
"brand_color": null,
"default_prompt": "Use $assess-patch-risk to trace this exact patch's program impact, regression protection, counterexamples, recoverability, and merge recommendation.",
"display_name": "Assess Patch Risk",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Assess patch impact and merge risk"
},
"name": "assess-patch-risk",
"plugin_release_skill_id": "pluginrsk_6ab6b60e77d081919b5ef3e16c062cb2"
},
{
"description": "Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.",
"interface": {
"brand_color": null,
"default_prompt": "Use $attack-path-analysis to trace a given security finding from source to sink and calibrate severity accordingly.",
"display_name": "Attack Path Analysis",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Perform attack-path analysis for a security finding"
},
"name": "attack-path-analysis",
"plugin_release_skill_id": "pluginrsk_6ab6b60e77d88191bc2a8ff9936d931f"
},
{
"description": "Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.",
"interface": {
"brand_color": null,
"default_prompt": "Use $codex-security:deep-security-scan to run a deep Codex Security scan.",
"display_name": "Deep Security Scan",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Run a deeper security scan"
},
"name": "deep-security-scan",
"plugin_release_skill_id": "pluginrsk_6ab6b60e77dc819190dcf7addbb89e3d"
},
{
"description": "Define, review, or update SECURITY.md guidance for a repository or component. Use when the user wants to clarify what Codex Security should review, what is out of scope, which security properties must hold, or whether existing guidance still matches the code.",
"interface": {
"brand_color": null,
"default_prompt": "Define or update this repository's SECURITY.md and show the proposed diff.",
"display_name": "Define Security Policy",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Define scoped SECURITY.md scan guidance"
},
"name": "define-security-policy",
"plugin_release_skill_id": "pluginrsk_6ab6b60e77e4819185c6cb897bc5e1ae"
},
{
"description": "Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.",
"interface": {
"brand_color": null,
"default_prompt": "Use $finding-discovery to discover security findings in the current repository or a given code change.",
"display_name": "Finding Discovery",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Discover security findings"
},
"name": "finding-discovery",
"plugin_release_skill_id": "pluginrsk_6ab6b60e77e8819196717fabff323894"
},
{
"description": "Use only when the user explicitly asks to fix and verify a validated or plausible security vulnerability. Do not use for ordinary bug fixes, correctness or design review findings, general validation, or full PR, commit, branch, patch, or repository scans.",
"interface": {
"brand_color": null,
"default_prompt": "Use $fix-finding to fix a given security finding and verify the issue no longer reproduces.",
"display_name": "Fix Security Finding",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Fix and verify a given security finding"
},
"name": "fix-finding",
"plugin_release_skill_id": "pluginrsk_6ab6b60e77f0819196c2e43664c8a4a0"
},
{
"description": "Develop evidence-backed structural and architectural security hardening proposals from vulnerability disclosures, supplied findings, incident or assessment documents, source code, or a completed Codex Security scan. Use when a user asks for systemic improvements, alternatives beyond per-finding patches, before-and-after security architecture views, engineering tradeoff analysis, or an implementation-ready plan for a selected hardening option. Also use automatically after a Codex Security scan with reportable findings when the top-level scan workflow requests final-report hardening guidance.",
"interface": {
"brand_color": null,
"default_prompt": "Use $propose-security-hardening to develop and compare structural security hardening options from these disclosures, findings, or scan results.",
"display_name": "Propose Security Hardening",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Design evidence-backed security hardening options"
},
"name": "propose-security-hardening",
"plugin_release_skill_id": "pluginrsk_6ab6b60e77f481919aa34e68f556e424"
},
{
"description": "Review a pull request, commit, branch diff, or working-tree patch for security vulnerabilities.",
"interface": {
"brand_color": null,
"default_prompt": "Run a Codex Security diff scan on this PR, commit, branch diff, or working-tree patch. Cover all in-scope changed files and complete the required scan phases.",
"display_name": "Security Diff Scan",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Run security review on a Git diff"
},
"name": "security-diff-scan",
"plugin_release_skill_id": "pluginrsk_6ab6b60e77f88191a633da16185e813b"
},
{
"description": "Use for a standard, single-pass security audit of an entire repository or a scoped path, package, folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR, commit, branch, or working-tree diffs, or for deep, multi-pass scans.",
"interface": {
"brand_color": null,
"default_prompt": "Run a Codex Security scan on this repository or scoped path using subagents. Cover all in-scope files and complete the required scan phases.",
"display_name": "Security Scan",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Run repository or scoped-path security scan"
},
"name": "security-scan",
"plugin_release_skill_id": "pluginrsk_6ab6b60e77fc81918386ba570ed3230d"
},
{
"description": "Use when Codex is already in the threat-modeling phase of a security scan, the user explicitly invokes $threat-model, or the user explicitly asks to create, update, or persist a repository threat model. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.",
"interface": {
"brand_color": null,
"default_prompt": "Use $threat-model to build a repository threat model.",
"display_name": "Threat Model",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Build a repository threat model"
},
"name": "threat-model",
"plugin_release_skill_id": "pluginrsk_6ab6b60e78008191a31bdba36ec4f6f5"
},
{
"description": "Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use it for scans or fixes.",
"interface": {
"brand_color": null,
"default_prompt": "Track validated Codex Security findings. Show a reviewable dry run before writing.",
"display_name": "Track Findings",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Track findings in Linear, Jira, GitHub issues, or draft advisories"
},
"name": "track-findings",
"plugin_release_skill_id": "pluginrsk_6ab6b60e78048191b8c92f2509f66851"
},
{
"description": "Use when the user supplies or imports existing security findings, vulnerability reports, or security/vulnerability Jira/Linear tickets from scanners, advisories, GitHub, Atlassian Rovo, Linear, or similar backlog sources and wants static repo-impact triage. Do not use for discovery, duplicate-bug triage, validation, or fixes.",
"interface": {
"brand_color": null,
"default_prompt": "Use $triage-finding to triage supplied or imported security findings against <repo/path>. For Jira, use Atlassian Rovo only as an intake connector to import Jira issues matching <JQL or project/search>; for Linear, use Linear only as an intake connector for supplied issue URLs/IDs or search results. Return one static-evidence verdict per finding: confirmed, not_actionable, or needs_review. Finding(s) or source: <paste SARIF, CVE/GHSA/advisory text, scanner ticket, Jira/Linear security or vulnerability tickets, bug bounty report, Codex Security artifact, or GitHub finding source here>.",
"display_name": "Triage Finding",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Import security or vulnerability tickets from Jira/Linear, scanners, advisories, or GitHub"
},
"name": "triage-finding",
"plugin_release_skill_id": "pluginrsk_6ab6b60e78088191a2f0ddd3b79a89d6"
},
{
"description": "Use when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.",
"interface": {
"brand_color": null,
"default_prompt": "Use $validation to determine whether a given security finding is valid.",
"display_name": "Validation",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Validate a security finding"
},
"name": "validation",
"plugin_release_skill_id": "pluginrsk_6ab6b60e780c8191808b0534edd59550"
},
{
"description": "Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability. Do not invoke automatically while implementing fixes, reviewing ordinary code changes, or running tests. Do not use for non-security fixes, candidate finding validation, or full repository scans.",
"interface": {
"brand_color": null,
"default_prompt": "Use $verify-fix to verify that a reported security vulnerability is fixed without modifying the repository.",
"display_name": "Verify Fix",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Verify security fixes without changing code"
},
"name": "verify-fix",
"plugin_release_skill_id": "pluginrsk_6ab6b60e78108191b58c20f27fe5b941"
},
{
"description": "Turn vulnerability notes, disclosure reports, PoCs, source code, or Codex Security findings into self-contained, sceptically validated, natural-sounding vulnerability reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional.",
"interface": {
"brand_color": null,
"default_prompt": "Use $vulnerability-writeup to turn a corpus of vulnerability notes into polished, source-backed disclosure reports.",
"display_name": "Vulnerability Writeup",
"icon_large_url": null,
"icon_small_url": null,
"iconography": null,
"short_description": "Write up a vulnerability into a polished, self-contained, source-backed report."
},
"name": "vulnerability-writeup",
"plugin_release_skill_id": "pluginrsk_6ab6b60e78148191b3da17034dde6e5d"
}
],
"version": "0.1.31"
},
"scope": "GLOBAL",
"share_url": "https://chatgpt.com/plugins/codex-security?open_in_app",
"status": "ENABLED"
}SHA-256 of public snapshot: 39e41584f6b1b27eb991f9cf8548214d98f93d3cca982b5f725a39948fd87776