Who it is for
Engineering teams folding security review into their existing repository and pull request workflow.
Security scanning workflows for code and diffs
Overview
Codex Security is OpenAI's bundle of repeatable security workflows for source code. It can sweep a whole repository, or narrow the pass to a change set: a pull request, a single commit, a branch comparison, or an uncommitted patch in the working tree.
The skill list shows how far the coverage runs. Alongside scanning there is finding discovery, triage of results that already exist, attack path analysis, proposals for hardening, fix drafting, and defining a security policy for later passes to check against.
Capabilities on the record include read and write access plus interactive use, so it is built to act on a codebase rather than only report on it. Its keywords place the app in application security, code review, and threat modeling.
Engineering teams folding security review into their existing repository and pull request workflow.
It ships a defined set of named skills, from attack path analysis to fix drafting, rather than one generic scan.
Availability
Codex Security is listed in the ChatGPT apps directory only. OpenAI has no connector under the same domain in the Claude directory; 392 of the 3,150 products here are on both marketplaces, and this is not one of them.
ChatGPT apps are built on MCP, and the same server can back a Claude connector, so the absence is a distribution decision rather than a technical one.
ChatGPT listing
Codex Security declares 13 named skills, which puts it in the 6.7% of ChatGPT-listed apps that do.
Same company
iOS development workflows for SwiftUI and Xcode
ChatGPT
macOS app development, debugging, and packaging guidance
ChatGPT
Frontend web app building with testing and payments
ChatGPT
Design and build browser-based charts and dashboards
ChatGPT
Nearby
Compliance posture and evidence review inside chat
ChatGPT
Domain email authentication and DNS security checks
ChatGPT
Internal SaaS app catalogue and access requests
ChatGPT
Read-only explainer for data broker exposure
ChatGPT
VPN server picks and connection troubleshooting
ChatGPT
Resident management for smart locks
ChatGPT
This is an independent catalogue entry compiled by Node8 from Codex Security's public marketplace listing as it stood in August 2026. Listing facts come from the marketplaces; the comparisons against the rest of the directory and any live-endpoint measurements are Node8's. Node8 is not affiliated with OpenAI, and inclusion here is not an endorsement.
Node8 builds MCP servers end to end: deciding which tools are worth exposing, the authentication and permission model, the review submissions, and the onboarding that gets them used. One server serves ChatGPT, Claude, and Microsoft Copilot.