ALTIOR AI ADVANTAGEWhat to remember
Codex Security

A Security Scan Starts in Chat

OpenAI demonstrates four familiar actions for beginning a scan, but the evidence ends before access, coverage, quality, privacy or outcomes become clear.

Dense security infrastructure converges into a prepared chat and scan-start marker.

OpenAI has turned the visible start of a Codex Security scan into a familiar handoff: add the plugin, open the prepared chat, choose the folder containing our code and press Send.

That is a meaningful change in how the task is presented. It is not evidence that the scan itself is effortless, comprehensive or effective.

The product move

The Friction Has Moved

A specialist-looking setup begins with actions we already recognise from ordinary chat workflows.

Specialist setup burden contrasted with a prepared chat while security work continues.
The demonstrated change is in the starting experience: a prepared conversation replaces a more intimidating first step, while the security work remains unproven here.

Beginning a security review can feel like a task that demands tooling knowledge before any useful work starts. OpenAI’s demonstration brings that first move into Codex and gives us a prepared route into the scan.

The simplification belongs to the interface. The source does not establish what happens inside the scan or how well it performs.

The demonstrated path

Four Actions to Begin

OpenAI’s post supports a short sequence that ends when the scan starts.

Four-step roadmap from adding the plugin to sending the prepared scan prompt.
Add the plugin. Select Try in chat. Choose the folder containing the code. Press Send. The supported account stops as the scan begins.
Provider image: openai-codex-security-plugin.jpg
OpenAI’s official preview shows the Codex Security plugin and its Add plugin control; it supports the starting point, not the scan’s eventual findings.
1OpenAI X post
4demonstrated actions
1selected code folder
0demonstrated scan results

OpenAI says installation changes the plugin button to Try in chat. Selecting it opens a new Codex chat with a Codex Security scan prompt ready to run. We then choose a folder containing the code and press Send.

The order matters because it is the whole supported journey. Anything beyond the scan starting would extend the evidence past what OpenAI’s post demonstrates.

The primary evidence

What OpenAI Actually Says

One OpenAI X post documents the onboarding sequence in direct interface language.

“Press ‘Send’ to start the scan.”

OpenAI, @OpenAI

The wording is narrow and useful. OpenAI explains how to add the plugin and get started, then walks through the controls that lead to Send.

It does not show findings, a report or a remediation flow. Reading the source at its actual boundary gives us a clear onboarding story without turning it into a broader product verdict.

The evidence boundary

The Proof Stops at Send

The post shows the handoff into a scan, not what the scan discovers or delivers.

The preview substantiates the interface transition: after installation, Try in chat opens a prepared Codex Security conversation. That makes the starting mechanism visible.

It does not establish eligibility, pricing, supported code, scan duration, detection performance, privacy handling or the quality of any findings. Those questions remain open rather than negative.

Before the scan

The Request Takes Shape

Codex prepares the conversation; we provide the code location and the final instruction to begin.

Four-node request flow from selecting a code folder to starting the scan.
Select the code folder, open the prepared scan prompt, press Send, then reach the only supported endpoint: scan started.

The demonstrated flow separates preparation from consent. Codex opens the scan prompt ready to run, but we still choose the folder containing the code and press Send.

That distinction is useful: the interface prepares the request without the source revealing the prompt’s contents, the underlying system or any subsequent output.

Known and unanswered

A Clear Start, Then Questions

The onboarding path is visible; the practical boundaries of the service are not.

The demonstrated scan-start path contrasted with six unanswered product questions.
Known: four actions begin a scan. Unanswered here: eligibility, cost, supported code, scan quality, privacy and outcomes.

We know how OpenAI presents the start: add the plugin, move into chat, select the relevant code folder and send the prepared prompt. That is enough to understand the interaction model.

We do not know from this source who has access, what it costs, what code it supports, what data handling applies or how dependable its findings are. The honest conclusion is a boundary, not a forecast.

The stronger reading

The Interface Is the Move

Codex Security is introduced through a prepared conversation rather than a separate-looking security ritual.

The notable shift is not a proven security outcome. It is that beginning a security review now looks like starting a guided Codex conversation.

Synthesis grounded in OpenAI’s 17 July 2026 X post

That framing could matter because the first barrier to using a specialist tool is often knowing how to begin. OpenAI’s sequence gives us an immediate route from installation to a scan request.

But approachable packaging and trustworthy performance are different claims. The post establishes the first and leaves the second for later evidence.

Run a source-bounded security review

Use Codex Security to review the code folder selected in this chat. Do not modify any files. For every potential issue, report the severity, file path, relevant line or function, supporting code evidence, security consequence, confidence level and a specific remediation. Separate confirmed findings from items that require manual verification, identify anything the scan could not inspect, and state clearly if no evidence-backed findings are returned.
Ready to copy
ALTIOR AI ADVANTAGE
The practical takeaway

Test What Follows Send

Use the demonstrated path as the starting point, then record the access conditions, scope, findings, evidence and data-handling details the onboarding post does not answer.

Try the prompt

Evidence to Watch Next

  • Access and cost
  • Supported code
  • Finding quality
  • Privacy and outcomes