# OpenAI ‘open-sourced’ its AI security scanner. The scanner is still locked up.

> Source: <https://thenextweb.com/news/openai-codex-security-cli-open-source-appsec-anthropic>
> Published: 2026-07-29 18:52:16+00:00

OpenAI has open-sourced an AI tool that hunts for security holes in your code. There is a catch: the part that does the hunting is still locked behind its approval.

The company quietly released the [Codex Security CLI](https://x.com/openai/status/2082263717916586117) this week, before it had even announced it. The [code is public](https://github.com/openai/codex-security), under an open licence. It scans repositories, validates the flaws it finds, suggests fixes, and slots into the automated pipelines developers ship code through.

## Open wrapper, gated engine

The “open source” label needs an asterisk. The command-line tool and its code are public, but access to the underlying scanner remains a limited beta for approved customers, [RuntimeWire reported](https://runtimewire.com/article/openai-open-sources-codex-security-cli-typescript-sdk). Any generated patches still need a human to sign off. So this is open plumbing bolted to a gated engine.

It was not always called Codex Security. Inside OpenAI it was “Aardvark,” and it launched as a research preview in March, [The Decoder reported](https://the-decoder.com/openai-open-sources-codex-security-cli-to-help-developers-find-and-fix-vulnerabilities-from-the-command-line/). By April, OpenAI said it had helped fix more than 3,000 critical vulnerabilities. Those are the company’s own figures.

## A land grab in application security

The real move is distribution. OpenAI is dropping security into the same terminal and pipelines where its [Codex agent](https://thenextweb.com/news/openais-codex-app-when-your-ide-gets-a-brain) already runs. Codex passed five million weekly users in June. That points the tool straight at incumbents like Snyk, Semgrep and Veracode, and at GitHub’s own fix-it features.

It is also a direct shot at Anthropic. Its rival launched Claude Security to do much the same job, scanning code and proposing patches. Microsoft has shipped [its own cyber model](https://thenextweb.com/news/microsoft-project-perception-agentic-security-cyber-model) too. All of them are chasing the same budget, and the same fear.

## Why now

The fear is that AI is arming the other side. [Automated attacks](https://thenextweb.com/news/ai-agent-security-four-attacks-one-flaw) are getting cheaper. This month alone, OpenAI’s own models featured in two of them. One escaped a sandbox, and another helped hack Hugging Face.

As [AI writes more of the code](https://thenextweb.com/news/veracode-2026-genai-code-security-56-percent-pass-rate), more of it ships with holes, and there are not enough humans to check. The irony sits close to the surface. The Codex ecosystem has already produced a tool that [quietly stole developer tokens](https://thenextweb.com/news/a-popular-openai-codex-tool-with-29000-weekly-downloads-has-been-quietly-stealing-developer-tokens-for-a-month). OpenAI is now selling the cure for the kind of problem its own boom helps create, and charging for the strongest dose.

## Get the TNW newsletter

Get the most important tech news in your inbox each week.
