Legitimate cryptography development incorrectly blocked by cyber safety classifier

Open
#33,675 2 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
38/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Quiet
Tech stack
rust

Research direction

Start by reviewing the uploaded thread 019f5181-8c92-7231-ba37-d76199765e7a and the reported behavior in Codex CLI versions 0.144.4 and 0.146.0. Compare the defensive cryptography scenario with the classifier response and verify that legitimate user-owned development is not hidden, while any needed verification is explained in the interface.

Written by the indexing model from the issue text.

Description

bug CLI safety-check
What version of Codex CLI is running?

0.144.4
and
0.146.0 (for 3b04c364-cf98-480e-9c5f-5d3d14aa6613 and f162cdca-a2d7-4855-b607-0a79472a02f5)

What subscription do you have?

Pro 20x

Which model were you using?

gpt-5.6-sol

What platform is your computer?

Fedora 43, x86_64, Kernel 7.1.3-100.fc43.x86_64

What terminal emulator and version are you using (if applicable)?

VTE 0.82.3

Codex doctor report

What issue are you seeing?

During legitimate defensive cryptography development, Codex displayed:
“This content can't be shown. We take extra caution with cybersecurity requests.”
The project is a private, local implementation of an elliptic-curve OpenSSL provider, including constant-time review, coverage-guided fuzzing, and portability testing on a user-owned Raspberry Pi. No scanning, exploitation, credential access, persistence, or third-party systems were involved. This appears to be a false positive caused by the combination of cryptography, SSH administration, side-channel review, and fuzz testing.

What steps can reproduce the bug?

Uploaded thread: 019f5181-8c92-7231-ba37-d76199765e7a

What is the expected behavior?

Legitimate defensive development and testing in a user-owned environment should continue normally. If additional verification is needed, the interface should explain that without hiding the response.

Additional information

No response

Dominant language
Rust
Stars
125k
Forks
19.5k
Avg merge
1m
Merged PRs (30d)
1k

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from openai/codex

All issues in openai/codex

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.