Cybersecurity false positive blocks legitimate C software quality testing

Open
#35,139 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
35/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Quiet
Tech stack
c, postgresql, rust

Research direction

Start by reviewing uploaded thread 019f5123-7a4e-7a53-b5e1-cc76fb3ca2f3 and the Codex CLI 0.145.0 behavior it documents. Reproduce the classification with the described libFuzzer, sanitizer, coverage, parser-robustness, and compiler-verification work; done means legitimate software-quality testing proceeds without being blocked.

Written by the indexing model from the issue text.

Description

bug CLI safety-check subagent
What version of Codex CLI is running?

0.145.0

What subscription do you have?

Pro

Which model were you using?

gpt-5.6-sol

What platform is your computer?

No response

What terminal emulator and version are you using (if applicable)?

No response

Codex doctor report

What issue are you seeing?

While implementing standard C software quality tests for a private PostgreSQL Bot project, legitimate work involving libFuzzer, sanitizers, code coverage, parser robustness tests, and compiler verification was repeatedly classified as
cybersecurity-related content.

The system displayed “This content can't be shown” multiple times and terminated legitimate subagent turns. The work does not involve attacks, vulnerability exploitation, malware, credential access, network scanning, or third-party systems.

Expected behavior: Normal software quality and robustness testing should proceed without triggering the cybersecurity classifier.

Uploaded thread ID: 019f5123-7a4e-7a53-b5e1-cc76fb3ca2f3

What steps can reproduce the bug?

Uploaded thread: 019f5123-7a4e-7a53-b5e1-cc76fb3ca2f3

What is the expected behavior?

No response

Additional information

No response

Dominant language
Rust
Stars
125k
Forks
19.5k
Avg merge
1m
Merged PRs (30d)
1k

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from openai/codex

All issues in openai/codex

Similar issues

More Rust issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.