openai / openai/codex

Repeated cybersecurity blocks despite verified Trusted Access for Cyber (TAC)

Open
#45,751 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app bug safety-check
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What version of the Codex App are you using (From “About Codex” dialog)?

26.908.9136.0 (installed Windows package version)

What subscription do you have?

ChatGPT Pro (20x)

What platform is your computer?

Windows 11 Pro — Version 10.0.26200, Build 26200, x64

What issue are you seeing?

I have verified Trusted Access for Cyber (TAC) and extensive experience working in cybersecurity and bug bounty programs. However, Codex repeatedly interrupts my authorized security work with the following error:

“This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber”

The message directs me to enroll in TAC even though I am already verified.

Context:
I am working within an authorized bug bounty program. The initial task was to identify live subdomains using curl, without installing additional tools. Target details are omitted from this public report.

Actual behavior:

  • Three consecutive attempts failed after approximately 15, 21, and 27 seconds.
  • The task was marked as systemError, and each failed turn recorded the cybersecurity-risk message above.
  • The interruptions prevent the analysis from progressing.
  • In one attempt, the assistant described the interruption as time spent reviewing previous analysis, while the recorded error showed a cybersecurity block. This made the cause difficult to understand.

Expected behavior:
My verified TAC access should be recognized for the applicable account, workspace, model, and product surface. If an action remains restricted, the app should clearly explain the applicable restriction rather than only displaying a generic invitation to enroll in TAC.

Requested investigation:
Please verify whether TAC is correctly provisioned and applied to this session, and investigate whether these repeated blocks are false positives. I understand that TAC does not remove all safety restrictions.

Diagnostics were submitted through the app’s feedback feature.

Feedback ID / affected task:
01a0975d-6722-79b2-886e-927d5e2b15ca

Observed on September 15, 2026.

What steps can reproduce the bug?

Observed steps in the affected session:

  1. Use the Codex desktop app on Windows with a ChatGPT Pro account verified for Trusted Access for Cyber (TAC).
  2. Work in an existing task for an authorized bug bounty program. The initial request was to identify live subdomains using only curl, without installing additional tools.
  3. Ask Codex to continue the analysis.
  4. The turn stops with:
    “This content was flagged for possible cybersecurity risk.”
    The error also directs the user to join TAC, despite already being verified.
  5. Retry or ask why the analysis stopped. In this session, three consecutive attempts failed after approximately 15, 21, and 27 seconds with the same error.

This was observed in an existing conversation; reproduction in a fresh task has not been confirmed.

Session / feedback ID:
01a0975d-6722-79b2-886e-927d5e2b15ca

Environment:

  • Codex Windows package version: 26.908.9136.0
  • Windows 11 Pro, build 26200, x64
  • ChatGPT Pro with verified TAC

Exact context usage and token usage at the time of failure are unknown. Diagnostic logs were submitted through the in-app feedback feature. Target details are omitted from this public report.

What is the expected behavior?

Codex should recognize my verified TAC status and allow security work covered by my approved access to proceed without repeated false-positive interruptions.

If a request remains restricted, the app should clearly explain the restriction or access issue and provide an appropriate support path, rather than repeatedly directing an already verified user to enroll in TAC.

The task should accurately report the cause of an interruption instead of presenting a security block as ordinary analysis progress.

Additional information

I have extensive experience in cybersecurity and bug bounty programs. These repeated interruptions are disrupting my professional work.

Please investigate whether my TAC access is correctly applied to the affected account, workspace, model, and session, and whether the blocks are false positives.

Diagnostic logs were submitted through the in-app feedback feature:
Feedback ID: 01a0975d-6722-79b2-886e-927d5e2b15ca

I understand that TAC does not remove all safety restrictions. I am requesting consistent application of my approved access and actionable error messages.

If additional account or target details are required, please provide a private support channel.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No repository files, tests, or entry points are identified. Start by reviewing the submitted diagnostic record for feedback ID 01a0975d-6722-79b2-886e-927d5e2b15ca and the documented reproduction steps. Done means determining whether TAC provisioning reaches the affected account, workspace, model, and session, and whether restrictions produce an accurate actionable message.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
authorization, desktop, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.