Agent Plugins Marketplace
← All plugins

codex-security

v0.1.95

Codex Security workflows for security scans, analysis, and investigation.

Codex15 Skills1 MCP serverstdio

By OpenAILicense: Apache-2.011k GitHub starsUpdated 5 hours ago

Directory evidence

Runtimes
Codex
Parsed components
16 skill or MCP entries
Source updated
Oct 4, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Get the plugin

git clone https://github.com/openai/codex-security

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/codex-security/.

Compatibility: the page URL and API slug “codex-security-3” remain stable.

  • Codex: Legacy selector codex-security-3@agent-plugin-marketplace remains documented for migration; install from source for this runtime.

This plugin's manifest name conflicts with another source for the same runtime. The source remains indexed, but this directory does not generate mismatched -2/-3 install commands.

Plugin files

plugins/codex-security/
├── .codex-plugin/plugin.json
├── skills/assess-patch-risk/SKILL.md
├── skills/attack-path-analysis/SKILL.md
├── skills/deep-security-scan/SKILL.md
├── skills/define-security-policy/SKILL.md
├── skills/finding-discovery/SKILL.md
├── skills/fix-finding/SKILL.md
├── skills/propose-security-hardening/SKILL.md
├── skills/security-diff-scan/SKILL.md
├── skills/security-scan/SKILL.md
├── skills/threat-model/SKILL.md
├── skills/track-findings/SKILL.md
├── skills/triage-finding/SKILL.md
├── skills/validation/SKILL.md
├── skills/verify-fix/SKILL.md
├── skills/vulnerability-writeup/SKILL.md
└── .mcp.json

Included Skills15

assess-patch-riskskills/assess-patch-risk/SKILL.md

Assess an immutable patch artifact's program impact, regression risk, and auto-merge eligibility. Use for generated patch files, provider pull-request diffs, or commit ranges when reviewers need evidence about affected runtime paths, contracts, tests, and recoverability. This skill is read-only and does not generate, edit, apply, push, or merge the patch.

attack-path-analysisskills/attack-path-analysis/SKILL.md

Use when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

deep-security-scanskills/deep-security-scan/SKILL.md

Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide or scoped-path Codex Security scan. Run repeated complete independent Standard scans with the Codex Security deep-scan tool, which aggregates their validated findings and prepares the canonical artifacts; then complete the same scan once. Do not use for PRs, commits, branch diffs, or working-tree diffs.

define-security-policyskills/define-security-policy/SKILL.md

Define, review, or update SECURITY.md guidance for a repository or component. Use when the user wants to clarify what Codex Security should review, what is out of scope, which security properties must hold, or whether existing guidance still matches the code.

finding-discoveryskills/finding-discovery/SKILL.md

Use when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

fix-findingskills/fix-finding/SKILL.md

Use only when the user explicitly asks to fix and verify a validated or plausible security vulnerability. Do not use for ordinary bug fixes, correctness or design review findings, general validation, or full PR, commit, branch, patch, or repository scans.

propose-security-hardeningskills/propose-security-hardening/SKILL.md

Develop evidence-backed structural and architectural security hardening proposals from vulnerability disclosures, supplied findings, incident or assessment documents, source code, or a completed Codex Security scan. Use when a user asks for systemic improvements, alternatives beyond per-finding patches, before-and-after security architecture views, engineering tradeoff analysis, or an implementation-ready plan for a selected hardening option. Also use automatically after a Codex Security scan with reportable findings when the top-level scan workflow requests final-report hardening guidance.

security-diff-scanskills/security-diff-scan/SKILL.md

Review a pull request, commit, branch diff, or working-tree patch for security vulnerabilities.

security-scanskills/security-scan/SKILL.md

Use for a standard, single-pass security audit of an entire repository or a scoped path, package, folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR, commit, branch, or working-tree diffs, or for deep, multi-pass scans.

threat-modelskills/threat-model/SKILL.md

Use when Codex is already in the threat-modeling phase of a security scan, the user explicitly invokes $threat-model, or the user explicitly asks to create, update, or persist a repository threat model. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

track-findingsskills/track-findings/SKILL.md

Track validated Codex Security findings in Linear, Jira, GitHub issues, or draft GitHub security advisories. Use it for one finding or an explicitly selected batch of up to 25 findings tracked as Linear, Jira, or GitHub issues. Includes duplicate checks, exact previews, approval-gated writes, and readback. Do not use it for scans or fixes.

triage-findingskills/triage-finding/SKILL.md

Use when the user supplies or imports existing security findings, vulnerability reports, or security/vulnerability Jira/Linear tickets from scanners, advisories, GitHub, Atlassian Rovo, Linear, or similar backlog sources and wants static repo-impact triage. Do not use for discovery, duplicate-bug triage, validation, or fixes.

validationskills/validation/SKILL.md

Use when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

verify-fixskills/verify-fix/SKILL.md

Use only when the user explicitly requests verification that a security fix remediates a reported vulnerability. Do not invoke automatically while implementing fixes, reviewing ordinary code changes, or running tests. Do not use for non-security fixes, candidate finding validation, or full repository scans.

vulnerability-writeupskills/vulnerability-writeup/SKILL.md

Turn vulnerability notes, disclosure reports, PoCs, source code, or Codex Security findings into self-contained, sceptically validated, natural-sounding vulnerability reports. Use for one vulnerability or a disclosure campaign; a Codex Security scan is optional.

MCP servers1

codex-securitystdio
command
./scripts/launch_codex_security_mcp
args
--stdio
cwd
.

Plugin manifests1

plugins/codex-security/.codex-plugin/plugin.json
{
  "name": "codex-security",
  "version": "0.1.95",
  "description": "Codex Security workflows for security scans, analysis, and investigation.",
  "author": {
    "name": "OpenAI"
  },
  "homepage": "https://developers.openai.com/codex/security",
  "repository": "https://github.com/openai/codex-security",
  "license": "Apache-2.0",
  "keywords": [
    "security",
    "code-review",
    "diff-review",
    "appsec",
    "threat-modeling"
  ],
  "skills": "./skills/",
  "apps": "./.app.json",
  "mcpServers": "./.mcp.json",
  "interface": {
    "displayName": "Codex Security",
    "shortDescription": "Security scanning for your codebase",
    "longDescription": "Codex Security packages reusable workflows for security scans, analysis, validation, and investigation across code, diffs, and related artifacts.",
    "developerName": "OpenAI",
    "category": "Security",
    "capabilities": [
      "Interactive",
      "Read",
      "Write"
    ],
    "websiteURL": "https://openai.com/",
    "privacyPolicyURL": "https://openai.com/policies/row-privacy-policy/",
    "termsOfServiceURL": "https://openai.com/policies/row-terms-of-use/",
    "defaultPrompt": [
      "Run a Codex Security scan on this repository.",
      "Run a Codex Security diff scan on this PR, commit, branch diff, or working-tree patch.",
      "Triage existing security findings against this repository."
    ],
    "brandColor": "#111111",
    "composerIcon": "./assets/logo.png",
    "logo": "./assets/logo.png",
    "screenshots": []
  }
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[codex-security on Agent Plugins Marketplace](https://pluginsmp.com/plugins/codex-security-3)