openai / openai/codex

Suspected cybersecurity false positive during local DEX correctness testing

Open
#45,200 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What version of Codex CLI is running?

0.153.4

What subscription do you have?

Not specified

Which model were you using?

gpt-6-astra

What platform is your computer?

WSL2 / Linux 6.18.33.2-microsoft-standard-WSL2, x86_64

What terminal emulator and version are you using (if applicable)?

codex-tui; terminal emulator version not captured

Codex doctor report
Not collected. In-product feedback and the thread have been uploaded.
What issue are you seeing?

During local correctness testing of my own smart contract, Codex displayed: "We take extra caution with cybersecurity requests. If you’re a security professional, you may be able to apply for Trusted Access". The work checks DEX swap calculations, rounding, dynamic fees and compute usage using local snapshots and Mollusk/SVM. This continuation sends no live blockchain transactions and performs no external exploitation. Please review this suspected false positive.

What steps can reproduce the bug?

Uploaded thread: 01a099d1-ccda-77c2-99c1-444694efcd99

  1. Resume local contract testing using downloaded public DEX account snapshots.
  2. Run deterministic quote-versus-execution comparisons and fuzz/property tests in local Mollusk/SVM.
  3. Observe the cybersecurity/Trusted Access notice.

The exact triggering message is unknown; the uploaded thread provides context.

What is the expected behavior?

Routine local numerical correctness testing of user-owned code should proceed without an inappropriate cybersecurity notice. Please clarify the trigger and whether this notice affects model access.

Additional information

Related reports: #41564 and #37161. No claim is made about the internal classifier cause. Subscription and terminal details were not collected

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the uploaded thread 01a099d1-ccda-77c2-99c1-444694efcd99 and related reports #41564 and #37161. Reproduce the local Mollusk/SVM quote-versus-execution and fuzz/property-testing steps, then identify the exact trigger for the notice. Done means the trigger and whether it affects model access are documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux, rust
Domain
cli, security, testing-qa
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.