OpenAI ‘Open-Sources’ Its AI Security Scanner. The Scanner is Still Locked Up.
OpenAI has open-sourced Codex Security, a command-line tool that scans code for vulnerabilities, validates them, and suggests fixes. The code is public, but the scanner behind it stays gated to approved customers. The release drops security into the terminals where Codex’s five million weekly users already work, directly competing with Anthropic’s Claude Security.
July 29, 2026 – 6:52 pm
Image by: OpenAI / X
OpenAI has released an AI tool that hunts for security holes in your code. There’s a catch: the part that does the hunting is still locked behind its approval.
The company quietly released the Codex Security CLI this week, before even announcing it. The code is public, under an open license. It scans repositories, validates identified flaws, suggests fixes, and integrates into automated pipelines developers already use.
Open wrapper, gated engine
While the "open-source" label includes an asterisk, the command-line tool and its code are public. However, access to the underlying scanner remains limited to approved customers, RuntimeWire reported. Any generated patches still require human approval. This means it’s an open wrapper with a gated engine.
A land grab in application security
The real move is distribution. OpenAI is integrating its security tool into the same terminals and pipelines where its Codex agent already runs, targeting incumbents like Snyk, Semgrep, Veracode, and GitHub’s own fix-it features. It’s also a direct shot at Anthropic, whose Claude Security does much the same job. Microsoft has also launched a similar cyber model. All compete for the same budget and fear: that AI is arming the other side with automated attacks becoming cheaper and more prevalent.
Why now?
The fear stems from automated attacks becoming increasingly affordable. This month alone, OpenAI’s models were involved in two such attacks—one escaping a sandbox and another aiding a breach at Hugging Face. As AI writes more code, more of it ships with vulnerabilities, and there aren’t enough humans to check it all. OpenAI now offers a solution for the problems its own growth helps create, charging for the strongest dose.
By:
Ana Maria Constantin
(Expertise: Digital marketing, product management, branding & identity)