openai / openai/codex

Suspected false positive: additional cybersecurity safeguard blocked authorized read-only Codex task

Open
#46,362 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app bug safety-check
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

Summary

An authorized, read-only engineering task for a private repository was repeatedly blocked by Codex's additional automated cybersecurity safeguard. The task was intended to perform independent exact-SHA acceptance and deployment-readiness checks and to stop before any credential access, production change, public traffic, or device upload.

Environment

  • Product surface: ChatGPT Desktop / Work-Codex on macOS
  • Installed app version: 26.915.31029 (build 9771)
  • Codex session/CLI version: 0.153.4
  • Model shown: GPT-5 (Codex; exact alias not exposed)
  • Daybreak / Trusted Access for Cyber: not used
  • Thread/session ID: 01a0aa22-258b-7d33-b2c3-40c92498a3f3
  • Intended GitHub identity for this report: AnnISIS

Exact safety notice

“This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber”

Observed timestamps (UTC)

  • 2026-09-18T01:59:56.071Z
  • 2026-09-18T02:01:21.111Z
  • 2026-09-18T02:06:03.173Z

Redacted task description

The task requested read-only independent exact-SHA acceptance and deployment-readiness checks for repository controls, registry prerequisites, host compatibility, and a WeChat release path. All real-user, real-audio, provider-egress, publication, deployment, device-upload, and production-traffic gates were required to remain disabled until their own machine Gate and independent acceptance passed.

No exploit execution, credential retrieval, public traffic, or production mutation was requested.

What happened immediately before the block

No engineering tool output was produced. Codex returned the automated safety notice above.

Evidence available

  • Redacted app-log excerpts from the macOS Codex log directory around the three UTC timestamps. The local app log did not contain the banner sentence itself; it appeared in the Codex response/tool error.

  • Sanitized JSONL session excerpt for the thread. The first line is:

    {"timestamp":"2026-09-16T12:12:40.611Z","type":"session_meta_redacted","payload":{"product_surface":"ChatGPT Desktop / Work-Codex","model":"GPT-5 (Codex; exact alias not exposed)","thread_id":"01a0aa22-258b-7d33-b2c3-40c92498a3f3","session_id":"01a0aa22-258b-7d33-b2c3-40c92498a3f3","originator":"Codex Desktop","source":"[redacted]","cli_version":"0.153.4","model_provider":"openai","cwd":"[redacted]"}}

  • No request ID was shown.

  • No /feedback session ID was generated because Feedback was not available from the slash-command UI.

  • Raw session and application logs were retained locally and are not attached because they contain unrelated private data.

Request

Please investigate whether this was a false positive and advise whether any additional diagnostic identifier or supported feedback path is available for this desktop build.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the redacted macOS Codex app-log excerpts and sanitized JSONL session excerpt around the listed timestamps, then compare the safety notice with the request context. Done means determining whether the block was a false positive and documenting any supported diagnostic identifier or feedback path for this desktop build.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos
Domain
desktop-dev, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.