openai / openai/codex

Codex Security plugin burned through 60–70% of my weekly quota on 200$ plan with no results

Open
#38,266 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app bug rate-limits skills
Dominant language
Rust
Stars
125k
Forks
19.5k
PR merge metrics
PR metrics pending

Description

What version of the Codex App are you using (From “About Codex” dialog)?

Powered by Codex & OWL Version 26.803.61601 Released Aug 9, 2026

What subscription do you have?

200

What platform is your computer?

Mac m4

What issue are you seeing?

Sorry for AI written post but it's better than I'm in explaining the issue clearly.

So today I launched the Security plugin in Codex and something went wrong.
I'm on the latest version of the desktop app, on mac.

At first, the security scan reported that my CLI was outdated. I updated the CLI and started the scan again.

It then ran for around 3 hours without returning results and at that point I steered the agent and told it to stop/close the scan if it couldn't return any results within the next 15 minutes.

15 minutes later, Codex told me it was no longer watching the process but the process itself apparently kept running in the background.

Eventually it reported that the process had terminated which happened due to my subscription usage limit being completely exhausted by it.

Before starting this, I had around 60–70% of my weekly quota left.

The usage dashboard says 91% of today's usage came from the SDK.

And after all of that, the security scan still didn't produce any result. Literally nothing. It;s just long scroll of "its still working" messages.

It looks like either the underlying process continued consuming tokens after the agent stopped watching it, or something got stuck in a runaway loop.

What steps can reproduce the bug?

Feedback ID: 019ff558-5195-72e3-929d-d02aa855af0d

What is the expected behavior?

No response

Additional information

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing feedback ID 019ff558-5195-72e3-929d-d02aa855af0d and the Security plugin's interaction with the CLI and SDK. Reproduce the scan from the reported Mac setup, checking whether work continues after the agent stops watching; done means the scan terminates cleanly and returns results without exhausting unrelated quota.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cli, tooling
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.