Open-source Codex security plugin can threat-model code diffs and export to SARIF
reach_vb · x · 2026-07-23
Reintroducing the open-source Codex Security plugin for cyberdefense:
- Point it at a codebase or diff, and it can build a threat model, map attack paths, validate findings, and generate plus test fixes.
- The output can be exported to SARIF, GitHub, Jira, or Linear.
- The project is open sourced on GitHub.
Related event: Open-Source Codex Security Plugin Returns for Threat Modeling(4 posts)→
More from coding & agent
- Usage metering cheatsheet: one meter for product, finance, and ops in production AI apps — blaizedsouza · 2026-09-11
- User left Astra working overnight and it ran autonomously for 17+ hours on an app — LinusEkenstam · 2026-09-11
- GPT-6 Astra docs draw attention: async tool calling and mid-turn steering point to multi-agent use — MikkoH · 2026-09-11
- SlopCodeBench: Measuring how sloppy LLM-generated code really is — mitsuhiko · 2026-09-11
- Inbox dedup: how to stop webhook retries from triggering duplicate agent runs — blaizedsouza · 2026-09-11
- Microsoft paper: read-only verification tools lift agent memory pass rate from 39% to 73% — dair_ai · 2026-09-11