A security reviewer that lives inside Codex.
Codex gets a full security loop: scanning a repository, showing each finding with its evidence and patching the ones you approve.
What it is
The MCP server bundled inside the Codex Security plugin for Codex. Codex Security is OpenAI's application security agent for finding, confirming and fixing vulnerabilities. You get this server by installing the plugin in Codex; there is no separate command to add it to other AI tools. The npx @openai/codex-security command is a separate CLI built on the same scanner, not this server.
What you get
- Security scans of a repository or one folder, plus slower deep scans for broader review
- Code changes reviewed before you merge a pull request or branch
- An existing backlog of security findings triaged
- Approved findings fixed with small patches, and the fixes verified
- Findings exported or sent to tracking, and vulnerability reports written
- Security hardening proposed from scan results
Requirements
Codex, in the ChatGPT desktop app or the Codex CLI, with the Codex Security plugin installed and enabled. Running scans requires Codex Security access; OpenAI recommends an account verified for Trusted Access for Cyber. The plugin signs in with your Codex login or an OpenAI API key.
Setup effort
One command plus a key — Install the Codex Security plugin in Codex, then supply credentials