OpenAI's Codex Security CLI: How Agent-Driven Vulnerability Scanning Handles Validation, Patching, and CI Integration OpenAI released Codex Security, an open-source TypeScript SDK that runs an agent-driven vulnerability scanning pipeline with parallel discovery workers, LLM-based validation, automated patch generation, and verification. The CLI requires Node.js 22.13.0+ or 24.x/26.x plus Python 3.10+, stores scan state locally in ~/.codex-security/scans/, and supports headless CI integration via OPENAI_API_KEY or CODEX_API_KEY with device-auth and SSH agent forwarding for remote runners. OpenAI just released Codex Security as an open-source TypeScript SDK with 11K+ stars. It's not another static analysis tool. It's an agent-driven security scanner that orchestrates parallel discovery workers, validates findings with LLM reasoning, generates patches, and verifies fixes autonomously. This is what happens when security tooling becomes agentic rather than rule-based. Traditional SAST tools run pattern matchers and dump alerts. Codex Security runs a multi-stage pipeline: discovery agents scan code, validation agents filter false positives, patch agents generate fixes, and verification agents confirm the patches work. Each stage has its own state management, tool boundaries, and failure modes. Here's how the plumbing works. Codex Security splits discovery into worker pools. When you run cs scan . on a repository, the CLI spawns multiple discovery workers that operate concurrently across different code paths. Each worker is a Node.js process running Python analysis tools underneath. The orchestration layer manages: ~/.codex-security/scans/ . The CLI requires Node.js 22.13.0+ within 22.x or 24.x/26.x, plus Python 3.10+. Python 3.10 also needs tomli for TOML parsing. This dual-runtime requirement exists because the discovery layer uses Python-based security tools likely Semgrep, Bandit, or similar while the orchestration and LLM integration run in TypeScript. // Simplified worker coordination pattern interface ScanWorker { id: string; targetPaths: string ; findings: CandidateFinding ; } async function runDeepScan repoPath: string : Promise