openai / openai/codex

Detailed work on binary file formats is unnecessarily flagged as security-adjacent or malevolent

Open
#43,843 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug CLI model-behavior safety-check
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What version of Codex CLI is running?

Latest

What subscription do you have?

Pro or Max

Which model were you using?

Astra High

What platform is your computer?

NixOS

What terminal emulator and version are you using (if applicable)?

Blink on iOS, herdr multiplexer

Codex doctor report
I’m actually on an iPad and my SSH client is making it difficult to copy output so I will attach this to the resulting report when I can
What issue are you seeing?

I’m doing low level work on validating various binary file formats (see the project pmarreck/validate) and I keep getting flagged when I am not doing anything malevolent, which is frustrating

What steps can reproduce the bug?

UpLoaded7.20thread:7.2001a077be-5a17-7da1-8aa5-5597322f6f21

What is the expected behavior?

The expected behavior is continued assistance on my work

Additional information

I’m not an official cybersecurity researcher in any capacity, but file format validation is perhaps uniquely security-adjacent since malformed inputs are often a feature in breaches; it would be nice if this type of work was recognized for the value it is, and not the threat it can pose.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file, test, or complete reproduction is identified; the issue only describes assistance being blocked during binary-format validation. Start by reviewing the attached report or thread and the relevant safety-classification behavior, then define a reproducible validation scenario and an expected result before implementation.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
cli, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.