Codex Security (formerly Aardvark): OpenAI's agentic scanner with sandboxed exploit validation ================================================================================ Codex Security is OpenAI's agentic security scanner, announced as Aardvark in October 2025 with a claimed 92 percent detection rate on benchmark repositories and released as a research preview in March 2026. In its first thirty days it scanned 1.2 million commits, reported 792 critical and 10,561 high findings and 14 CVEs including OpenSSH, GnuTLS and Chromium, and claimed up to 84 percent noise reduction through sandboxed validation. Maintainer: OpenAI Website: https://openai.com/index/codex-security-now-in-research-preview/ Category: Frontier-lab and general scanners Targets: General code, Commits and pull requests Approach: Builds a project threat model, scans commits, validates exploitability in a sandbox, proposes patches Access: SaaS for ChatGPT Pro, Business, Enterprise and Edu Status: Active (research preview 2026-03-06) Strengths: Exploit validation before reporting. | CVEs in cryptographic and network libraries (OpenSSH, GnuTLS). | Threat-model construction per project. Limits: Not cryptography-aware. | Findings volume. | Benchmark claims lack a public dataset. Firms using it: none listed Sources: https://openai.com/index/introducing-aardvark/ | https://openai.com/index/codex-security-now-in-research-preview/ Source page: https://agentsast.com/tools/codex-security/ Compiled by: agentsast editors (https://agentsast.com/about/) Last reviewed: 2026-09-13