{"_id":"@openai/codex-security","_rev":"2-3edbe1ad52bb621b5ea6e161588c03fb","name":"@openai/codex-security","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@openai/codex-security","version":"0.1.0","author":{"name":"OpenAI"},"license":"Apache-2.0","_id":"@openai/codex-security@0.1.0","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"homepage":"https://developers.openai.com/codex/security","bugs":{"url":"https://github.com/openai/codex-security/issues"},"bin":{"codex-security":"bin/codex-security.mjs"},"dist":{"shasum":"26faa1630b98abab0783b2a23d97529868f3d6af","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.0.tgz","fileCount":178,"integrity":"sha512-7pH2xQiyGsS/+cKkwFKZogAIJJgBsRk9dbEvtj15hFJk1jz6tSbgvvtZKlP8i0eh26pO3S51XCfH4ME5u10pfg==","signatures":[{"sig":"MEYCIQDQEncVYk+o8Vw40yCuJpF1AI1NRhxz/1VjBJIs1771lwIhAMY9l64NU+jW3/ha6XFU9AtsOgGBMh4KQojYKpgSxn0e","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2593327},"main":"./dist/index.js","type":"module","_from":"file:dist/openai-codex-security-0.1.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","build":"pnpm run clean && tsc -p tsconfig.build.json","clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","types":"pnpm run generate:models:check && tsc --noEmit","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","test:package":"node scripts/smoke-package.mjs","check:package":"node scripts/check-package.mjs","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check"},"_npmUser":{"name":"mdangelo-openai","email":"mdangelo@openai.com"},"_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.0.tgz","_integrity":"sha512-7pH2xQiyGsS/+cKkwFKZogAIJJgBsRk9dbEvtj15hFJk1jz6tSbgvvtZKlP8i0eh26pO3S51XCfH4ME5u10pfg==","repository":{"url":"git+https://github.com/openai/codex-security.git","type":"git","directory":"sdk/typescript"},"_npmVersion":"11.16.0","description":"TypeScript SDK and CLI for Codex Security","directories":{},"_nodeVersion":"24.18.0","dependencies":{"ajv":"8.20.0","incur":"0.4.13","fflate":"0.8.2","fast-uri":"3.1.4","papaparse":"5.5.3","smol-toml":"1.6.1","pdfjs-dist":"5.6.205","extract-zip":"2.0.1","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@inquirer/prompts":"8.3.0","@openai/codex-sdk":"0.144.6"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"prettier":"3.2.5","@types/bun":"1.3.13","typescript":"5.7.3","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4"},"_npmOperationalInternal":{"tmp":"tmp/codex-security_0.1.0_1785258588194_0.16017099624766207","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@openai/codex-security","version":"0.1.1","description":"TypeScript SDK and CLI for Codex Security","license":"Apache-2.0","author":{"name":"OpenAI"},"homepage":"https://developers.openai.com/codex/security","repository":{"type":"git","url":"git+https://github.com/openai/codex-security.git","directory":"sdk/typescript"},"bugs":{"url":"https://github.com/openai/codex-security/issues"},"type":"module","engines":{"node":">=22"},"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"bin":{"codex-security":"bin/codex-security.mjs"},"publishConfig":{"access":"public"},"dependencies":{"@inquirer/prompts":"8.3.0","@octokit/core":"7.0.6","@openai/codex":"0.144.6","@openai/codex-sdk":"0.144.6","ajv":"8.20.0","extract-zip":"2.0.1","fast-uri":"3.1.4","fflate":"0.8.2","incur":"0.4.13","papaparse":"5.5.3","pdfjs-dist":"5.6.205","smol-toml":"1.6.1"},"devDependencies":{"@types/bun":"1.3.13","@types/node":"22.19.17","@types/papaparse":"5.3.15","json-schema-to-typescript":"15.0.4","prettier":"3.2.5","typescript":"5.7.3"},"scripts":{"clean":"node -e \"require('node:fs').rmSync('dist',{recursive:true,force:true})\"","build":"pnpm run clean && tsc -p tsconfig.build.json","check:package":"node scripts/check-package.mjs","format":"prettier --check --ignore-path .gitignore --ignore-path .prettierignore \"**/*.{cjs,mjs,js,ts,json,md}\"","generate:models":"node scripts/generate-models.cjs","generate:models:check":"node scripts/generate-models.cjs --check","lint":"tsc --noEmit","test":"bun test --timeout 30000 ./tests-ts","test:package":"node scripts/smoke-package.mjs","types":"pnpm run generate:models:check && tsc --noEmit"},"_id":"@openai/codex-security@0.1.1","_integrity":"sha512-sNxULf7IyicJRgYnycguaEzO2ZeANEv3oyrupjMoKVq5TjRrmIhORpaa7U2LVIpEHJP7//icGZV37MRIlp9X/A==","_resolved":"/home/runner/work/codex-security/codex-security/dist/openai-codex-security-0.1.1.tgz","_from":"file:dist/openai-codex-security-0.1.1.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-sNxULf7IyicJRgYnycguaEzO2ZeANEv3oyrupjMoKVq5TjRrmIhORpaa7U2LVIpEHJP7//icGZV37MRIlp9X/A==","shasum":"2ed585c8d2dfd7b0ebccf94753921913b8402061","tarball":"https://registry.npmjs.org/@openai/codex-security/-/codex-security-0.1.1.tgz","fileCount":178,"unpackedSize":2613965,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@openai%2fcodex-security@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFNejgQYBCFBJhluKx8XUjOL4YYW9pWZ0QVD66NZChvOAiAxIIsKGlsd2cEpdTqrWV8qKmU1UKe4PN/BHM1B6/TzwQ=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b02dfa53-e25f-4e9e-9779-377048bff249"}},"directories":{},"maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/codex-security_0.1.1_1785282503386_0.6889273776243623"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-28T17:09:48.017Z","modified":"2026-07-28T23:48:24.117Z","0.1.0":"2026-07-28T17:09:48.381Z","0.1.1":"2026-07-28T23:48:23.585Z"},"bugs":{"url":"https://github.com/openai/codex-security/issues"},"author":{"name":"OpenAI"},"license":"Apache-2.0","homepage":"https://developers.openai.com/codex/security","repository":{"type":"git","url":"git+https://github.com/openai/codex-security.git","directory":"sdk/typescript"},"description":"TypeScript SDK and CLI for Codex Security","maintainers":[{"name":"openai-publisher","email":"oai-package-publish-npm@openai.com"},{"name":"tino-openai","email":"tino@openai.com"},{"name":"dylan-hurd-openai","email":"dylan.hurd@openai.com"},{"name":"moustafa-openai","email":"moustafa@openai.com"},{"name":"tylersmith-openai","email":"tylersmith@openai.com"},{"name":"mdangelo-openai","email":"mdangelo@openai.com"},{"name":"victor-openai","email":"victor@openai.com"},{"name":"jbeckwith-oai","email":"jbeckwith@openai.com"},{"name":"atty-openai","email":"atty@openai.com"},{"name":"tibo-openai","email":"tibo@openai.com"},{"name":"dkundel-openai","email":"dkundel@openai.com"},{"name":"mbolin-openai","email":"mbolin@openai.com"},{"name":"fouad-openai","email":"fouad@openai.com"},{"name":"easong-openai","email":"easong@openai.com"},{"name":"aibrahim-openai","email":"ahmedibrhm32@gmail.com"},{"name":"apcha-oai","email":"apcha@openai.com"},{"name":"seratch-openai","email":"seratch@openai.com"}],"readme":"# `@openai/codex-security`\n\nOpen-source TypeScript SDK and CLI for running Codex Security scans. The\nESM-only package includes TypeScript declarations, the `codex-security`\nexecutable, and the matching Codex runtime.\n\n> [!NOTE]\n> This package follows semantic versioning. Its public API may change between\n> minor versions before `1.0.0`.\n\n## Install\n\n```bash\nnpm install @openai/codex-security\nnpx codex-security --version\n```\n\nThe package supports macOS, Linux, and Windows and requires Node.js 22 or\nlater. Scanning and exporting findings also require Python 3.10 or later. If\nyou use Python 3.10, install the `tomli` package. Select another interpreter\nwith `--python`, `pythonPath`, or `PYTHON` when needed.\n\n## Run a scan from TypeScript\n\nSign in with `npx codex-security login` or set `OPENAI_API_KEY` or\n`CODEX_API_KEY`. Then create a client and scan a repository you own or have\npermission to assess:\n\n```ts\nimport { CodexSecurity } from \"@openai/codex-security\";\n\nconst security = new CodexSecurity();\n\ntry {\n  const result = await security.run(\"/path/to/repository\", {\n    outputDir: \"/path/outside/repository/results\",\n  });\n\n  console.log(result.reportPath);\n  console.log(result.findings.findings.length);\n} finally {\n  await security.close();\n}\n```\n\nThe SDK supports repository, path, committed-diff, and working-tree targets.\nUse `security.preflight()` to validate local inputs, `onWorkerStatus` and\n`onReconnect` to observe long-running scans, and an `AbortSignal` to cancel a\nscan.\n\nResults can contain source excerpts, vulnerability details, and reproduction\nsteps. Keep result directories and saved reports outside the repository and\nlimit access to authorized reviewers.\n\n## Authentication\n\nFor local use, sign in with ChatGPT:\n\n```bash\nnpx codex-security login\nnpx codex-security scan .\n```\n\nOn a remote or headless machine, use device authentication:\n\n```bash\nnpx codex-security login --device-auth\n```\n\nFor CI, set `OPENAI_API_KEY` or `CODEX_API_KEY`. To store an API key instead,\npass it on stdin:\n\n```bash\nprintenv OPENAI_API_KEY | npx codex-security login --with-api-key\n```\n\nOn Windows, set the API key in PowerShell:\n\n```powershell\n$env:OPENAI_API_KEY = \"<your-api-key>\"\nnpx codex-security scan C:\\code\\repository\n```\n\nCheck or remove the stored sign-in with `npx codex-security login status` and\n`npx codex-security logout`. Codex Security reuses an existing file-based Codex\nsign-in. If Codex stores credentials in the system keyring, run\n`npx codex-security login` once before scanning.\n\nAn environment API key takes precedence over a stored sign-in by default.\nWhen both a stored ChatGPT sign-in and an environment API key are available, an\ninteractive scan asks which credential to use. JSON output, dry runs, CI, and\nother noninteractive scans never prompt and retain automatic API-key\nprecedence. Select the credential source explicitly with `--auth`:\n\n```bash\nnpx codex-security scan . --auth chatgpt\nnpx codex-security scan . --auth api-key\n```\n\n`--auth chatgpt` uses the stored sign-in and ignores `OPENAI_API_KEY` and\n`CODEX_API_KEY`. `--auth api-key` requires one of those environment variables.\nOmit `--auth`, or pass `--auth auto`, to preserve automatic API-key precedence\nfor existing CI and unattended scans. The SDK accepts the same selection as\n`security.run(repository, { auth: \"chatgpt\" })` and\n`security.preflight(repository, { auth: \"chatgpt\" })`.\n\nTo make the stored ChatGPT sign-in the automatic default instead, unset any\nconfigured API-key variables:\n\n```bash\nunset OPENAI_API_KEY CODEX_API_KEY\n```\n\nThe interactive choice applies only to the current scan and is not persisted.\n\nWhen an environment key is configured, ChatGPT login and\n`codex-security login status` identify the effective scan credential source\nwithout printing its value, including when no stored sign-in exists.\n\n## CLI\n\n```bash\nnpx codex-security scan /path/to/repository\nnpx codex-security scan /path/to/repository --model gpt-5.6-terra\nnpx codex-security scan /path/to/repository --path src --path tests\nnpx codex-security scan /path/to/repository --knowledge-base /path/to/threat-models --knowledge-base /path/to/architecture.pdf\nnpx codex-security scan /path/to/repository --diff origin/main --json\nnpx codex-security scan /path/to/repository --output-dir /path/outside/repository/results\nnpx codex-security scan /path/to/repository --output-dir /path/outside/repository/results --archive-existing\nnpx codex-security scan /path/to/repository --dry-run\nnpx codex-security scan /path/to/repository --fail-on-severity high\nnpx codex-security scan /path/to/repository --max-cost 5\nnpx codex-security install-hook\nnpx codex-security bulk-scan\nnpx codex-security bulk-scan repositories.csv --output-dir /path/outside/repositories/security-scans --workers 4\nnpx codex-security scans list /path/to/repository\nnpx codex-security scans list --scan-root /path/outside/repository/results\nnpx codex-security scans show SCAN_ID\nnpx codex-security scans rerun SCAN_ID\nnpx codex-security scans match PREVIOUS_SCAN_ID CURRENT_SCAN_ID\nnpx codex-security scans match --all\nnpx codex-security scans compare PREVIOUS_SCAN_ID CURRENT_SCAN_ID\nnpx codex-security export /path/outside/repository/results --export-format sarif --output /path/outside/repository/results.sarif\nnpx codex-security export /path/outside/repository/results --export-format csv --output /path/outside/repository/findings.csv\nnpx codex-security export /path/outside/repository/results --export-format json --output /path/outside/repository/findings.json\nnpx codex-security validate /path/outside/repository/findings.json \"Possible SQL injection in src/query.ts:42\"\nnpx codex-security patch /path/outside/repository/findings.json \"Missing authorization check in src/routes.ts:18\"\n```\n\nRun `npx codex-security --version` for the installed CLI version or\n`npx codex-security info --json` for the package, bundled plugin, Codex runtime,\ndefault model, reasoning effort, and first-scan command. A scan with `--dry-run`\nalso reports its effective model and reasoning effort, including `--codex`\noverrides, without starting Codex or contacting the network.\n\n`install-hook` scans staged and unstaged changes before each commit. It respects\n`core.hooksPath`, does not replace an existing hook, and blocks high-severity\nfindings or failed scans. Set `--fail-on-severity` to change the threshold.\n\n`--path` scopes a scan to one or more paths, `--diff` scans committed changes,\nand `--working-tree` scans staged and unstaged changes. Deep scans support\nrepository and path targets. The output directory must be outside the scanned\ndirectory and any enclosing Git worktree. When SARIF is produced, it is written\nto\n`<scan-dir>/exports/results.sarif`.\n\nRepeat `--knowledge-base PATH` for multiple files or directories. Directories are\nsearched recursively for Markdown, text, PDF, and Word (`.docx`) files.\n\nOn macOS/Linux, an existing output directory must be private to the current\nuser (`chmod 700`).\n\nIf the output directory already contains results, add `--archive-existing`.\nThe CLI moves them to `<output-dir>.previous-<timestamp>-<id>` and starts the\nscan in a new, empty directory at the original path. Add `--dry-run` to see\nthe destination without moving files.\n\nScans are report-only by default. Use `--fail-on-severity` in CI to exit 1 when\na completed scan contains a finding at or above the selected severity.\nIncomplete coverage and CLI/runtime errors exit 2 so they cannot be mistaken\nfor a passing policy. Incomplete scans still write the available human or JSON\nresult to stdout and a coverage warning to stderr, including in report-only\nmode.\n\nScans use `gpt-5.6-sol` with extra-high reasoning effort by default. Use\n`--model gpt-5.6-terra` to switch models. Use repeatable `--codex KEY=VALUE`\noptions for other Codex settings, such as\n`--codex 'model_reasoning_effort=\"high\"'`.\n\nScan progress identifies the requested paths and reports actual ranking,\nfile-review, validation, and attack-path phases as they become available.\nCompletion summarizes findings, severity, coverage, elapsed time, available\ntoken and worker counts, estimated cost, the results directory, and the next\nuseful command.\nProgress and summaries use stderr; structured scan results remain on stdout.\n\nEach scan records its model, tokens, and estimated cost in its JSON result,\nscan history, and bulk-scan receipt. Estimates use\n[standard API token prices](https://developers.openai.com/api/docs/models/compare),\nincluding cached input and cache writes; fees and surcharges are not included.\n\nUse `--max-cost USD` to stop a scan, including its delegated workers, when its\nrunning cost exceeds the limit. Partial results are preserved. Requests\nalready in progress can finish above the limit.\n\nRun `npx codex-security scan --help` or `npx codex-security bulk-scan --help`\nfor the complete CLI references.\n\nSign in with `gh auth login`, then run `npx codex-security bulk-scan` to discover\nGitHub repositories pushed in the last 90 days. Archived\nrepositories and forks are excluded. Search the repository list, select the\nrepositories to scan, and confirm before scanning.\nPrivate checkouts reuse your GitHub CLI sign-in without changing your global Git\nconfiguration. The selected repositories are saved to\n`<output-dir>/repositories.csv` for review or resumption.\n\nTo use an existing repository list or run in CI, pass a CSV with required `id`,\n`repository`, and `revision` columns. Revisions must be full commit hashes;\noptional `scope` and `mode` columns narrow individual scans:\n\n```csv\nid,repository,revision,scope,mode\nservice,https://github.com/acme/service.git,0123456789abcdef0123456789abcdef01234567,src,standard\n```\n\n`--workers` limits concurrent scans and `--max-attempts` retries failures.\nResults remain under `--output-dir`; rerun the same command to resume.\n\n### Scan history and reruns\n\n`npx codex-security scans list` lists scans for the current repository. Pass a\nrepository path to inspect another checkout, `--scan-root DIR` to list scans\nwhose artifacts are under a particular root. `scans show SCAN_ID` includes the\nscan configuration, results, coverage, and artifact locations.\n\nEvery scan history command accepts a full scan ID or a unique prefix of at\nleast eight characters.\n\nScan history uses the existing Codex Security workbench database at\n`$CODEX_HOME/state/plugins/codex-security/workbench.sqlite3`. Set\n`CODEX_SECURITY_STATE_DIR` to place the database elsewhere. Scan credentials\nare never stored in the scan configuration.\n\nThe scan sandbox permits writes to the selected state directory so SQLite can\nmaintain its database and journal files. If the host itself cannot write to the\ndefault directory, select a writable directory outside the scanned repository:\n\n```bash\nexport CODEX_SECURITY_STATE_DIR=/path/to/writable/codex-security-state\n```\n\n`scans rerun SCAN_ID` repeats the original configuration against the current\ncheckout so a fixed vulnerability can be checked again.\n\n`scans match BEFORE_SCAN_ID AFTER_SCAN_ID` links findings with the same root\ncause; `scans match --all` matches all completed scans of the current repository,\nincluding other worktrees and clones. Saved matches appear in `scans show` and\nare reused unless `--force` is passed. Scans without sealed artifacts are skipped.\n\n`scans compare BEFORE_SCAN_ID AFTER_SCAN_ID` reads saved matches and reports\nfindings as new, persisting, reopened, resolved, or unknown. Missing findings\nare not treated as resolved when the later scan is incomplete or does not cover\ntheir original scope.\n\nThe CLI uses [Incur](https://github.com/wevm/incur) for agent-friendly discovery\nand structured output. Inspect the command manifest with `--llms`, inspect a\ncommand schema with `scan --schema --format json`, register the CLI as an MCP\nserver with `mcp add`, sync agent skills with `skills add`, or generate shell\ncompletions with `completions bash|zsh|fish`. Scan results support\n`--format toon|json|yaml|jsonl` and `--full-output`.\nUse `info --json` for SDK and bundled-plugin metadata. MCP exposes only this\nread-only metadata command; scans, bulk repository scans,\nauthentication, exports, validation, and patching remain CLI-only because the\nMCP transport cannot cancel active scans.\n\nFor CI, save machine-readable output outside the checked-out repository and\napply a severity policy. Incomplete coverage and runtime errors still exit\nnonzero:\n\n```bash\nSCAN_ROOT=\"$(mktemp -d)\"\nnpx codex-security scan . \\\n  --diff origin/main \\\n  --output-dir \"$SCAN_ROOT/results\" \\\n  --json \\\n  --fail-on-severity high > \"$SCAN_ROOT/findings.json\"\n```\n\nJSON scans never use interactive terminal controls, even when stderr is a TTY.\nThe `validate`, `patch`, `login`, and `logout` commands reject `--json` because\nthey do not produce structured CLI output. Sign-in commands remain interactive.\nCSV exports cannot be written to stdout while JSON output is requested.\n\nUse `export` to create CSV, JSON, or SARIF from a completed, sealed scan without\nstarting Codex or loading credentials. JSON preserves the sealed findings\ndocument. CSV uses the portable findings columns, marks findings as open, and\ndoes not include local workbench triage state. The exporter validates the seal\nbefore writing, accepts `--output -` for stdout, and can use\n`--source-root /path/to/repository` with SARIF to add source-line fingerprints.\nRun `npx codex-security export --help` for all export options.\n\nUse `validate` to run the bundled validation skill on candidate findings and\n`patch` to run the bundled fix-finding skill on security issues. Each positional\ninput can be either a file, whose contents are read into the request, or literal\ntext. Both commands operate on the current directory, use the scan model\nand reasoning defaults, ignore unrelated user configuration and plugins, and\nprint the final response without the underlying Codex event stream. Override\nthe model or reasoning effort with `--codex 'model=\"gpt-5.6-sol\"'` or\n`--codex 'model_reasoning_effort=\"high\"'`. Inputs are limited to 64 items and\n1 MiB total.\n\nCanonical scan documents are limited to 16 MiB for the manifest, 128 MiB for\nfindings, and 32 MiB for coverage. Oversized scans are rejected before sealing.\n\nExit codes are `0` for a completed report-only scan or a passing policy, `1`\nfor a completed policy violation, `2` for invalid input, incomplete coverage, or\na runtime/export error, `130` for interruption, and `143` for termination.\n\nUse `--dry-run` or `await security.preflight(...)` to validate the repository,\ntarget, mode, output location, and Codex overrides without initializing the\nruntime or loading credentials. Dry runs do not inspect the plugin or probe its\nPython interpreter. The preflight result includes the selected authentication\nmethod and, for an environment API key, its variable name. Authentication and\nmodel access remain unverified until a real scan starts.\n\nScan progress identifies the selected credential source before Codex starts.\nTerminals and noninteractive CI logs also show how to retry with\n`--auth chatgpt` when an environment API key overrides the stored sign-in.\nProgress remains on stderr so JSON output stays machine readable. Network\nfailures and rate limits remain retryable; definitive authentication and model\nauthorization failures stop immediately.\n\n## Documentation and security\n\n- [CLI quickstart](https://developers.openai.com/codex/security/cli)\n- [TypeScript SDK guide](https://developers.openai.com/codex/security/sdk)\n- [GitHub issues](https://github.com/openai/codex-security/issues) for bugs and\n  feature requests\n- [Security policy](https://github.com/openai/codex-security/blob/main/SECURITY.md)\n  for private vulnerability reporting and safe operation\n","readmeFilename":"README.md"}