{"schema_version":"newruntime-agent-readable-v0.2","type":"post","stable_id":"post:codex-security-cli-scan-workbench","slug":"codex-security-cli-scan-workbench","title":"Codex Security CLI Turns Security Review Into a Scannable Workbench","description":"OpenAI's Codex Security CLI packages repository, diff, working-tree, export, validation, and patch flows into a security-review workbench rather than a single scanner command.","retrieval_nugget":"OpenAI's Codex Security CLI packages repository, diff, working-tree, export, validation, and patch flows into a security-review workbench rather than a single scanner command. OpenAI's Codex Security CLI is easy to misread as \"Codex, but for security.\" The useful signal is narrower and more operational: security review is being packaged as a workbench around source code, scan history, validation, patching, and.","status":"published","published_at":"2026-07-29","updated_at":"2026-07-29","record_date":"2026-07-29","date_kind":"published_at","topics":["security","coding-agents","developer-tools","codex"],"source_urls":["https://x.com/OpenAI/status/2082263717916586117","https://www.npmjs.com/package/@openai/codex-security","https://github.com/openai/codex-security"],"visuals":[{"id":"codex-security-cli-scan-workbench-nano-banana","kind":"editorial-diagram","role":"hero","src":"https://newruntime.com/images/posts/codex-security-cli-scan-workbench-nano-banana.webp","alt":"Hand-drawn security workbench diagram showing a repository and diff entering Codex Security scan, then findings moving through patch, export, and CI review gates.","caption":"Codex Security is most interesting as a review workbench: scan, compare, validate, patch, export, and gate the result.","credit":"New Runtime synthesis from public source inspection","source_url":"https://www.npmjs.com/package/@openai/codex-security","generated_with":"nano-banana-style-imagegen","width":1600,"height":900,"legend":[{"label":"Repo/diff","description":"The CLI can scope scans to repositories, paths, committed diffs, or the working tree."},{"label":"Findings","description":"Results can include source excerpts, vulnerability details, and reproduction steps."},{"label":"Export gate","description":"CSV, JSON, and SARIF exports let the scan become CI and audit infrastructure."}]}],"routes":{"html":"https://newruntime.com/posts/codex-security-cli-scan-workbench/","markdown":"https://newruntime.com/posts/codex-security-cli-scan-workbench.md","json":"https://newruntime.com/posts/codex-security-cli-scan-workbench.json"},"source_format":"markdown","next_reads":[{"type":"topic","path":"/topics/codex/","reason":"Explore the codex topic hub.","url":"https://newruntime.com/topics/codex/","title":"Codex - New Runtime","media_type":"text/html"},{"type":"topic","path":"/topics/coding-agents/","reason":"Explore the coding agents topic hub.","url":"https://newruntime.com/topics/coding-agents/","title":"Coding agents - New Runtime","media_type":"text/html"},{"type":"related_material","path":"/posts/codex-gpt-5-4-migration-boundary/","reason":"Shares codex and developer tools.","url":"https://newruntime.com/posts/codex-gpt-5-4-migration-boundary/","title":"Codex Gets A Model Migration Deadline","media_type":"text/html"},{"type":"related_material","path":"/posts/langchain-reviewbench-review-agent-evals/","reason":"Shares coding agents and developer tools.","url":"https://newruntime.com/posts/langchain-reviewbench-review-agent-evals/","title":"ReviewBench Turns Code Review Into An Agent Eval","media_type":"text/html"},{"type":"related_material","path":"/posts/simon-stateless-mcp-practitioner-reset/","reason":"Shares developer tools and security.","url":"https://newruntime.com/posts/simon-stateless-mcp-practitioner-reset/","title":"Stateless MCP Makes Small, Auditable Agent Tools Practical Again","media_type":"text/html"}]}
