openai / openai/codex

Unexplained Cyber Abuse account warning during software development: possible false positive and unacceptable lack of actionable evidence

Open
#43,185 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app bug safety-check
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What issue are you seeing?

I received an account-level warning identifying "Cyber Abuse" in Codex while using it for software development. The email threatens possible loss of access if violations continue, but does not identify a request, session, timestamp, action, or specific policy provision that would let me understand the allegation.

I strongly object to this opaque and intimidating enforcement experience. Threatening a paying user's access without providing an actionable explanation is unacceptable. I believe this warning may be a false positive and request a substantive human review, not another generic policy reminder.

For accuracy: this is a warning of possible deactivation, not a claim that my account has already been banned.

Task context

I was maintaining Pure Live, an open-source live-streaming application. Recent work included backup-import validation, settings-data integrity fixes, and local tests. My purpose was legitimate application maintenance, not attacking third-party systems or abusing OpenAI's services.

I had also recently changed local Codex instructions and agent settings: model/reasoning selection, delegation, concurrency, and reducing redundant work. I subsequently restored my earlier configuration and empty global AGENTS.md. These changes were not intended to bypass safety systems. I do not know whether they are related to the warning and am not presenting timing alone as proof of causation.

The warning itself does not establish that the Pure Live task, rather than another account activity, triggered it. That lack of attribution is precisely the problem.

Warning text

The email was displayed in Chinese. Its substantive message, translated into English, is:

OpenAI has identified activity in Codex that is not permitted under its policies: Cyber Abuse. Continued violations may result in further action, including deactivation of access. An appeal button is provided if the recipient believes this is an error.

This is a translation/summary, not an exact English quotation. Account identifiers and the private case reference are intentionally omitted from this public report.

Environment
  • Codex desktop on Windows; ChatGPT Pro.
  • Main model configuration: GPT-6 Astra, medium reasoning.
  • Separately installed Codex CLI: 0.153.4. This is not asserted to be the desktop app version.
  • Warning reported on September 6, 2026 (Asia/Shanghai). Exact triggering request and enforcement timestamp were not provided in the notice.
Reproduction

I cannot provide a reliable minimal reproduction because the notice does not identify the triggering activity. I can provide the original warning and relevant redacted session details through a private support channel. I will not publish raw session logs or credentials here.

Expected behavior and requested action
  1. Conduct a human review and withdraw the warning if the classification was mistaken.
  2. Identify the relevant request/session or time range, and explain the concerning behavior sufficiently for the user to locate it, without disclosing detection internals.
  3. Clarify whether any account restrictions currently apply.
  4. Explain whether local instruction/configuration changes could be relevant in this case, rather than leaving users to guess and roll back unrelated settings.
  5. Improve these notices and the appeal process so legitimate developers are not left with a serious accusation and no practical way to understand or contest it.

I understand that a public GitHub issue cannot replace a private account appeal. This report concerns the product's lack of actionable enforcement information and the possibility of misclassification.

Related reports
  • #30271: reported Cyber Abuse warning during work on the user's own devices.
  • #31032: reported account warning during a job-application workflow.
  • #40421: repeated cybersecurity content blocks during a scientific-software audit; a different enforcement surface, included only as related context.

These are other users' reports, not proof that OpenAI has confirmed my case as a false positive. My request is for evidence-based review and a clear explanation.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The report names no repository file, test, or code entry point; start by reading related issues #30271, #31032, and #40421 alongside this request. Done would require an actionable enforcement explanation, a clear appeal path, and clarification of account restrictions, making this a product and policy effort rather than a self-contained code change.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.