openai / openai/codex

Possible false-positive cybersecurity block stops independent local fix review before any tool call

Open
#43,823 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app bug safety-check subagent
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What version of the Codex App are you using (From “About Codex” dialog)?

The About-dialog build was not captured. Incident session metadata records Codex Desktop, core/CLI 0.153.3, model gpt-6-astra. A later check of the installed compatibility CLI returned 0.142.5; that is not asserted to be the incident runtime version.

What subscription do you have?

Not verified in this report.

What platform is your computer?

macOS / Apple Silicon. Current uname -mprs: Darwin 25.6.0 arm64 arm.

What issue are you seeing?

A native independent review subagent was blocked while reviewing an existing fix and regression evidence in the user's own, explicitly authorized local project. The work concerns defensive access-control validation using only synthetic local test data, not external targets or real customer data.

The review turn began at 2026-09-08 12:11:56.774 UTC. The subagent announced that it would begin at 12:12:01.682 UTC, then the parent received this terminal error at 12:12:13.728 UTC:

This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

There were zero tool calls in this failed review turn. Earlier implementation/testing and an earlier independent review had run; their results are not being represented as successful completion of this blocked review.

What steps can reproduce the bug?

Observed sequence, not a deterministic reproduction of the classifier:

  1. Implement a user-authorized fix in a local synthetic-data lab.
  2. Freeze the candidate and stop the implementer's writes.
  3. Ask an independent native subagent to review the existing finding, fix diff and regression evidence, with local-only scope and no source edits.
  4. The subagent acknowledges the task, then terminates with the error above before invoking a tool.

The refused request has not been retried to provoke another block or circumvent safeguards.

Feedback upload ID / parent task: 01a08092-2df6-7f91-a285-79a83f62cd5a
Review subagent task: 01a080e4-fcdb-7221-9ded-40ce73f6151a
Review turn: 01a080ee-9ddb-7381-ac16-ad05ad4bf51f
Local dispatch call: call_A1tSloY4j0RSXGvhveGXnRu7

The app displayed “Feedback uploaded” with the ID above. These identifiers are not asserted to be backend HTTP request or policy-event IDs.

What is the expected behavior?

Please investigate whether this is a false positive for authorized defensive patch review. If additional entitlement is required, please identify the officially supported authorization/recovery path for the actual account and product surface. We are not requesting that safeguards be disabled or that review requirements be waived.

Additional information

The candidate and previous failure evidence remain preserved; independent review and acceptance are still pending. No account/model substitution, safeguard disabling, or repeated rephrasing was attempted.

Incident metadata uses the logical provider name custom; actual backend routing, account entitlement and the classifier rule were not established. No backend root cause is claimed.

This public report intentionally excludes project source, repository identifiers, credentials, local paths, school/customer data, screenshots and full session logs. An exact-feedback-ID search found no existing issue for this incident. Other cybersecurity-refusal reports do not establish a shared root cause.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the documented reproduction sequence and the preserved feedback, parent-task, subagent-task, review-turn, and dispatch identifiers. Compare the blocked review turn with the earlier implementation/testing and independent-review evidence, noting that no tool call occurred. Done means determining whether the refusal is a false positive and identifying the supported authorization or recovery path without disabling safeguards.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos
Domain
ai, cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.