Codex Security Cloud reviews commits with the laptop closed
The most useful thing about OpenAI's upgraded security plugin is that it keeps working without you. According to OpenAI's announcement on X, Codex Security Cloud keeps scanning GitHub repos and reviewing new commits after you close the laptop, and it now includes access to cyber-capable models through Daybreak Blue by default.
At a glance
- Codex Security Cloud is a plugin for Codex desktop and web. It needs a workspace where Codex cloud is already set up and a GitHub connection to the repositories you want scanned.
- It either scans a whole repository or watches incoming commits, then investigates and deduplicates findings and shows each with affected code, validation evidence and remediation guidance before proposing a patch.
- The announcement does not say which models Daybreak Blue provides or what they cost, and every proposed fix still waits for a human review before becoming a draft pull request.
If you have not been following it, Codex Security is OpenAI's security review tool built around Codex, its coding agent. The documentation has a separate product overview and FAQ for the Cloud version, which runs on OpenAI's side instead of on your machine. OpenAI calls this release a major upgrade to that Cloud plugin.
Cyber-capable models through Daybreak Blue come with the plugin by default
The biggest change is model access. OpenAI says cyber-capable models reached through Daybreak Blue are included by default in Codex Security Cloud. The announcement names the access route, Daybreak Blue, but it does not name the models or describe what makes them cyber-capable.
The plugin does four jobs. It scans entire GitHub repositories, reviews new commits continuously, investigates and deduplicates what it finds, and prepares fixes for review. All of this runs in Codex cloud, and OpenAI's post points out that the work continues even when your laptop is closed.
Setup goes through the ChatGPT plugin marketplace and a Codex cloud environment
You start in ChatGPT. Open Plugins on the web or in the desktop app, search the marketplace for Codex Security Cloud, install and enable it, then open Security Cloud from your installed plugins or the sidebar. If you can't get access, the documentation says to ask your workspace administrator and check that Codex cloud is set up.
A new scan begins with a GitHub connection. You grant access to the repositories you want scanned, and if one doesn't appear, you check its connection and permissions. Next you pick the repository and a compatible Cloud environment, or create one if none exists. Under What to scan, Repository is the default. Start scan launches the job, and Scans shows its progress, findings and artifacts.
Each finding comes with validation evidence and an optional Fix with Codex patch
In Findings, each issue opens with the affected code, the validation evidence behind it and remediation guidance. When a finding offers Fix with Codex, selecting it generates a proposed patch. The documentation tells you to review that patch before you select Create draft pull request, so the most the plugin produces is a draft for someone to look at.
Continuous review is a second scan type. You choose New scan, pick the repository and Cloud environment, set What to scan to Commit changes and select Create. Monitoring settings, under Repositories, let you change the Cloud environment, choose how many days of history to review, and pause or enable monitoring. Save applies the changes.
An editable threat model steers how findings are prioritized
The plugin also generates a threat model, which you can review and edit under Project context before saving. OpenAI's guide on improving the threat model says it affects two things: the context a scan works from and the order in which findings are prioritized.
A threat model is a written description of what the software protects, who might attack it and through which entry points. Think of it as the brief an inspector reads before visiting a building. If the brief says the vault is in the basement, the inspector spends more time there and less on the lobby windows. Editing the brief is how you tell the scanner which findings matter for your system.
The announcement leaves out most of the numbers. It does not say which models sit behind Daybreak Blue, what the plugin costs, how many days of history you can review, or how deduplication decides that two findings are the same. In our view, putting every patch behind a review and a draft pull request is the right default for a tool that works while nobody is watching, even though it means the laptop has to open eventually.
Before the first Daybreak Blue scan
The documentation leaves access to workspace administrators and requires Codex cloud to be set up. The announcement gives no rollout schedule, no price and no list of Daybreak Blue models. Until OpenAI publishes those details, the best test is to run a first scan on one connected repository and count how many of its findings hold up under your own review.
Related stories
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
