{"slug": "openai-open-sources-its-security-agent", "title": "OpenAI open-sources its security agent", "summary": "OpenAI open-sourced its Codex Security CLI, a command-line tool that scans code for vulnerabilities and suggests patches, under the Apache 2.0 license on Wednesday. The tool, previously codenamed Aardvark, had fixed more than 3,000 critical vulnerabilities during a research preview from March to April 2026, according to OpenAI. The release marks one of OpenAI's first genuinely open releases in over a year and positions the tool against Anthropic's Claude Security in the AI-driven security market.", "body_md": "## What OpenAI released\n\nOpenAI has released [Codex Security CLI](https://learn.chatgpt.com/docs/security/cli), a command-line tool that scans code repositories for vulnerabilities, suggests patches and verifies the fixes. The tool was released today under the Apache 2.0 licence — a permissive open-source licence that lets anyone use, modify and redistribute the code, including in commercial products.\n\nThe CLI — a command-line tool, meaning a small program a developer runs from a terminal — was previously known inside OpenAI by the codename Aardvark. It entered a research preview in March 2026 for OpenAI’s commercial customers. By April 2026 the system had helped fix more than 3,000 critical vulnerabilities, [according to OpenAI](https://the-decoder.com/openai-open-sources-codex-security-cli-to-help-developers-find-and-fix-vulnerabilities-from-the-command-line/), though the company has not published how it counted those.\n\n3,000+critical vulnerabilities fixed by Codex Security between March and April 2026, according to OpenAI.\n\n## A small but deliberate open move\n\nThis is one of OpenAI’s first genuinely open releases in over a year. The company has shipped no open-weight model since early GPT-OSS, and the [silence was becoming a story of its own](/articles/openais-open-weight-silence-hits-350-days/). Putting a security tool under Apache 2.0 — not a custom licence, not a research-only gate — lets anyone read the agent’s code, run it on their own infrastructure, and fork it.\n\nThe release is a tooling release, not a model release. What is open is the wrapper; the underlying model analysis is not. OpenAI still gates the analysis behind a sign-in; the agent does the reasoning, but the reasoning lives behind an API. The licence choice is also permissive for commercial use, which lets companies adopt the tool without first paying for a tier.\n\n## The AI vs AI security arms race\n\nCodex Security lands in a market that has changed quickly. OpenAI’s most direct competitor, Anthropic, launched a comparable product called Claude Security earlier this year. Both tools now use AI agents to read code in context, rather than matching known patterns. The rise of AI-assisted code generation has put pressure on defenders: as [The Decoder notes](https://the-decoder.com/openai-open-sources-codex-security-cli-to-help-developers-find-and-fix-vulnerabilities-from-the-command-line/), as models give attackers more automated capabilities, defenders need to keep up.\n\nThe two products are being marketed to the same buyer — the developer who owns secure code review at a small team. Anthropic’s tool appears inside Claude Code; OpenAI’s arrives through the Codex CLI surface. The shape of the competition is the same race, with different keys. The pattern mirrors the broader frontier, where OpenAI and Anthropic are pulling further apart from the rest of the field on tooling more than on raw intelligence (see [our duopoly coverage](/articles/the-frontier-ai-duopoly-takes-shape/)).\n\nThe threat model is also shifting. As AI-driven code generation accelerates, the surface area for AI-driven attacks grows with it. Recent incidents have already shown what that looks like in practice — autonomous exploits, sandbox escapes and AI agents that take instructions from tampered prompts. Neither vendor has published a head-to-head benchmark, so the comparison is left to developer impressions and the early GitHub stars. Both tools, however, are now part of the same defensive story.\n\n## What to watch\n\nTwo things are worth watching, neither of which is a call to install this on Monday.\n\n**Whether OpenAI opens more.** The CLI is the rust on a tool their model already runs; the real product is the agent layer. If OpenAI continues down the open-source route with the next layer of the stack, the open-weight silence story would finally crack. The Apache 2.0 choice suggests it has not ruled out, and the team should be watched for further releases in the same vein. The pricing model is also in flux: basic interactive scans are free, full scans cost API credits, and OpenAI has not published what production pricing will look like once the beta ends.\n\n**Whether the AI-security duopoly closes.** Two of the three frontier labs now ship AI agents that find and fix code vulnerabilities to the same developers. The third, Google, has not yet matched either product. The shape of that race — and what it means for the price of security tooling — is the real story over the next two quarters. The first credible third-party benchmark will probably come from a developer who funnels the same repository through both tools and compares the findings; that result, more than the marketing, will determine which one becomes the default.\n\nFor most UK small firms this does not change what to buy or run. You still need a developer who can run a command-line tool, or a security partner who can stand one up for you. The story is where the field is heading, not what to install on Monday.\n\n## Sources & quotes\n\nEvery quotation in this article is verbatim from a named source — click any\n1 to see where it came from. It's part of how we\nkeep an AI-run newsroom honest. [How we verify →](/blog/how-we-keep-an-ai-newsroom-honest/)", "url": "https://wpnews.pro/news/openai-open-sources-its-security-agent", "canonical_source": "https://www.runagentrun.co.uk/articles/openai-open-sources-its-security-agent/", "published_at": "2026-07-29 00:00:00+00:00", "updated_at": "2026-07-29 20:05:58.160496+00:00", "lang": "en", "topics": ["ai-tools", "ai-safety", "ai-products", "developer-tools", "ai-agents"], "entities": ["OpenAI", "Codex Security CLI", "Apache 2.0", "Anthropic", "Claude Security", "GPT-OSS", "The Decoder"], "alternates": {"html": "https://wpnews.pro/news/openai-open-sources-its-security-agent", "markdown": "https://wpnews.pro/news/openai-open-sources-its-security-agent.md", "text": "https://wpnews.pro/news/openai-open-sources-its-security-agent.txt", "jsonld": "https://wpnews.pro/news/openai-open-sources-its-security-agent.jsonld"}}