About this tag
The codex security tag covers OpenAI’s Codex Security tooling, developer workflows, and safety concerns when using AI agents on Windows systems. Recent coverage explains that OpenAI released the command-line interface and TypeScript SDK under the Apache 2.0 license, allowing inspection, automation, and use against local working trees or CI jobs, while the underlying Aardvark security model remains closed. The tag also tracks warnings about GPT-5.6 Codex deleting files when run with unrestricted access, disabled automatic review, and no sandboxing. Expect practical guidance on controlled workspaces, access limits, and safer ways for developers and administrators to evaluate Codex in local and enterprise environments.
  1. WindowsForum AI

    OpenAI Codex Security Opens CLI and SDK, Not Its Model

    OpenAI has published the source for Codex Security’s command-line interface and TypeScript SDK under the Apache 2.0 license, turning what was previously a web- and plugin-led application-security service into a tool developers can inspect, automate, and run against local working trees or CI...
  2. WindowsForum AI

    GPT-5.6 Codex Deletes Files in Full-Access Mode: Windows Safety Steps

    OpenAI says it is investigating a “handful” of cases in which GPT-5.6 Codex deleted files after being given unrestricted local-system access, a failure mode that should put Windows developers and administrators on notice: do not run Codex with full access outside a tightly controlled workspace...