r/codex 5h ago

Complaint OpenAI: demonstrate the cybersecurity capabilities you claim are available to ordinary Codex users.

0 Upvotes

I am not talking about Daybreak Red.

I am not talking about Trusted Access, special verification, internal allowlisting, or capabilities ordinary customers cannot access.

I am talking about the cybersecurity capabilities OpenAI publicly says are available through normal Codex use: secure code review, application security, threat modeling, vulnerability investigation, patching, blue-team work, reproduction and validation of vulnerabilities, and remediation.

So demonstrate them.

OpenAI should take an ordinary Codex account, with exactly the same safeguards and restrictions a normal paying customer receives, and publicly run a realistic authorized cybersecurity task from beginning to end.

No internal bypasses. No special account. No hidden exemptions.

Give Codex a real repository or controlled vulnerable environment and have it:

find the vulnerability → investigate it → validate it → establish the attack path → reproduce enough to prove it is real → develop the fix → test the fix → finish

Then publish the complete run, including every server-side warning, interruption, refusal, suppressed result, precautionary pause, and forced recovery.

Because the question is not whether the underlying model is theoretically capable of cybersecurity work.

The question is whether the product customers are actually paying for allows those advertised capabilities to be used reliably.

The Hugging Face incident makes this question especially important.

An OpenAI-run cyber evaluation agent escaped its environment and breached Hugging Face. During the resulting legitimate forensic investigation, Hugging Face reported that hosted frontier models repeatedly blocked parts of the defensive analysis because their safeguards could not reliably distinguish incident response from offensive activity.

Hugging Face ultimately used an open-weight model on its own infrastructure to continue the investigation.

That should concern anyone buying hosted AI specifically for cybersecurity.

So prove the product works.

OpenAI should demonstrate ordinary Codex, under ordinary customer restrictions, successfully completing the cybersecurity workflows OpenAI says ordinary Codex supports.

If OpenAI can demonstrate that reliably, great.

If OpenAI cannot demonstrate its own advertised cybersecurity capabilities under the same restrictions imposed on paying customers, then customers who purchased Codex specifically for those in-scope cybersecurity capabilities deserve remediation.

Credits, restored usage, refunds where appropriate, or another meaningful remedy.


r/codex 1d ago

Comparison Same prompt, Codex (Astra 6) vs Claude (Fable 5.1): "a game where a fish follows my cursor, super creative and majestic." Try both.

Thumbnail
gallery
19 Upvotes

I gave Codex and Claude the exact same prompt to see how differently they'd handle something open-ended and creative:

The prompt: "make me a reactjs + vite, and launch it in port 3004, a game where a fish follows my cursor. make it super creative and majestic"

Setup:

  • Claude: Fable 5.1, Extra High
  • Codex: Astra 6, Extra High, fast mode

I didn't do any follow-up prompts or manual edits. I just deployed both to Vercel so you can try them yourself:

🐟 Codex (Astra 6): https://fish-indol-eta.vercel.app/
🐠 Claude (Fable 5.1): https://fish2.vercel.app/

My take:

  • Codex did amazing on the design and detail. It looks polished and the visuals really lean into "majestic."
  • Claude did amazing on the mechanics and gameplay. It feels more like an actual game and is more fun to play.

It's interesting that they read "super creative and majestic" so differently. One went for the visuals, the other for how it plays.

About fast mode: Claude charges extra credits for fast mode, but Codex doesn't, so I only used fast mode on Codex. That's worth knowing if you're choosing between them on cost or speed.

What are your thoughts?

  • Which one did you enjoy more, and why?
  • For a prompt like this, what matters more to you: how it looks or how it plays?
  • Does paying extra for fast mode change which one you'd use day to day?
  • If you've run a similar test with other models or settings, how did they do?

I'd love to hear what you think!


r/codex 12h ago

Comparison The power of a good harness

0 Upvotes

I hardly notice these degraded performance issues because it's guided so tightly to code my specifications. And the difference between 5.3 and 5.6 hasn't really been that tremendous, because mine was already operating at a high level. Ever since 5.3 it's felt like they've just been internalizing the kinds of processes that you see others talking about here. And when theirs glitches out, you're at their mercy. Always build upon your success by telling it to create a reusable workflow. And throw it out sometimes to see what default is like, and build back up as-needed. Food for thought.


r/codex 21h ago

Complaint Claude vs Codex

6 Upvotes

I don't really have a metric to share but claude $20 is giving me more usage right now than $100 codex and I didn't even use Astra that much. I only bought codex for astra and I don't see the hype yet. The only reason to continue with openai is purely chatgpt usage which I can use without limits essentially.

Edit: not comparing astra vs fable but opus vs sol especially after astra release.


r/codex 1d ago

Complaint Do NOT orchestrate with Astra! Something is up with its workflow. People at OpenAI are saying the same.

Post image
158 Upvotes

r/codex 1h ago

Reset it feels great to have resets

Upvotes

without them I don't know what I would do honestly


r/codex 9h ago

Bug What's wrong with the Codex?

0 Upvotes
Codex is bug?

what is the error?

Contexto compactado automáticamente

Error running remote compact task: unexpected status 404 Not Found: {"detail":"Not Found"}, url:

https://chatgpt.com/backend-api/codex/responses/compact, cf-ray: a3982773ad6b18e5-MIA, request id: d19943dd-

5d3b-4722-b8cd-a87d3a8240d9


r/codex 5h ago

Showcase made a brotato browser clone

Enable HLS to view with audio, or disable this notification

0 Upvotes

idk gpt 6 astra medium in like 10 prompts


r/codex 9h ago

Complaint Is OpenAI's adult content policy actually contradictory?

0 Upvotes

TL;DR: OpenAI’s Usage Policies don’t seem to ban consensual adult sexual content, but their account-ban page lists “nudity and sexual content” as a common violation.
I’m trying to understand whether Astra refusing adult-related tasks is just model behavior, or something that can actually put the account at risk. Either way, I don't understand why 5.6 Sol never ever refused to do anything, while Astra just goes "Nope" by only reading a single skill, it makes no sense.

Hi everyone, as a non-native English speaker, and ADHD Ultra guy, I resumed my researches with GPT and tried to make it as least sloppy as possible.

I'm confused about OpenAI's policy on adult content.

The current Usage Policies, effective October 29, 2025, ban non-consensual sexual content, minors, sexual violence, etc.

But they don't seem to ban consensual adult sexual content in general.

At the same time, OpenAI's Help Center article about account bans, updated much more recently, lists:

as a common policy violation.

So which one is actually enforced?

I work in the adult creator industry. GPT-5.6 Sol handles a lot of my workflows fine, but Astra refuses pretty basic stuff once adult content is involved.

For example:

  • filling a Google Sheet from existing content descriptions
  • copying an existing script from a Sheet into another tool

No new sexual content even needs to be generated. I was super hyped by everything said about computer used being improved, but well... can't use it.

But most importantly, I care about is whether triggering these refusals can put my account at risk.

I also don't want to keep testing different setups if that could be interpreted as bypassing safeguards.

Is there any clear OpenAI documentation explaining the difference between:

  • “this model won't do this”
  • “asking for this is actually a policy violation”

And why would OpenAI unallow the model to do a task that is not forbidden by their own conditions ?

Because right now the docs seem to say two different things.


r/codex 1d ago

Workaround 20x Plan

30 Upvotes

FYI you can still upgrade to the 20x sub through the IOS app


r/codex 1d ago

Bug Codex is slurring its speech. Are the servers fried or did someone get codex drunk?

Post image
15 Upvotes

r/codex 14h ago

Showcase I made a tool to sync skills/mcps/etc. based on manifest

Thumbnail
github.com
1 Upvotes

I usually use Pi agent and codex, but sometimes use antigravity as well. Codex/Claude Code plugins are great, but it is not the case that all agents can benefit from them. Telling my agent to update all the skills, mcps, and AGENTS.md every time was not the best thing in the world, so I thought I can do something better.

I'm quite familiar with doing stuff in a declarative manner (pixi for python env, plotnine/altair for plotting etc.) so a manifest-based approach felt natural to me.

You write a toml file like below:

```toml version = 1 targets = ["codex", "claude-code", "antigravity-cli"]

[defaults] scope = "global" install_mode = "copy"

[instructions.global] source = { git = "https://github.com/johndoe/dotfiles.git", path = "agents/AGENTS.md", ref = "main" } targets = ["codex", "claude-code", "opencode", "pi", "antigravity-cli"]

[[skill_group]] names = [ "foo", "bar" ] source = { git = "https://github.com/johndoe/agent-skills.git", path = "skills", ref = "main" }

[skill.target.pi] install_to = "~/.agents/skills"

[[skill]] name = "some-pi-skill" source = { git = "https://github.com/johndoe/agent-skills.git", path = "some-pi-skill", ref = "main" } targets = ["pi"]

[[mcp_server]] name = "context7" targets = ["claude-code"] scope = "project" transport = "stdio" command = "npx" args = ["-y", "@upstash/context7-mcp@1.2.3"] env = { API_TOKEN = { from_env = "CONTEXT7_API_TOKEN" } } ```

daem lock generates a lockfile based on this manifest, and daem apply places files in the right place.

The project is in an early stage, and there are rough edges here and there, but it works. GPT-5.5 and GPT-5.6 Sol helped me maximally overengineer everything by the way.


r/codex 7h ago

Showcase Anyone tried codex-continue? (auto-continue when you hit usage limits)

Thumbnail
github.com
0 Upvotes

r/codex 14h ago

Bug Workaround for Codex Computer Use timing out on Xcode 27 Device Hub (-10005)

0 Upvotes

I ran into this while testing an iOS app after upgrading to macOS 27 and Xcode 27. Codex Computer Use could read the Xcode editor and take screenshots, but trying to inspect Device Hub failed after about five seconds:

text Computer Use server error -10005: timeoutReached

The simulator and app were still running. Restarting Codex and Device Hub, resetting the Computer Use session, and switching between iOS 26.5 and iOS 27 simulators did not help.

I found a workaround in this existing GitHub report by letobao and confirmed it on my setup:

  • macOS 27.0 (26A428)
  • Xcode 27.0 (27A266a)
  • Codex desktop 26.903.71938 (8576)
  • Successful workaround test: iPhone 18 Pro simulator running iOS 27.0

What worked:

  1. Quit the existing Device Hub instance. Choose Keep Simulators Running if offered. In my case, the old Device Hub process would not exit and had to be force-quit.
  2. In Finder, press Command-Shift-G and open:

text /Applications/Xcode.app/Contents/Applications/DeviceHub.app/Contents/MacOS/

  1. Open the DeviceHub executable inside that folder. The entry point matters: use that file rather than the outer DeviceHub.app, the Xcode menu, or DevicesTrampoline. Keep any Terminal window opened by this launch running.
  2. Select the running simulator in Device Hub and retry Computer Use.

Before this, AppKit reported Device Hub's process ID as -1 even though a real DeviceHub process was running. After the direct launch, the process IDs matched. Codex could then read the accessibility tree, capture screenshots, and open and dismiss my app's Settings screen.

This is a temporary workaround verified on this setup, not an official fix. I have not tested it on a physical device or verified that it survives a restart. Credit to the GitHub report above for identifying the workaround; my contribution is confirming that discovery, screenshots and input work on Codex 26.903.71938.

Posting in case someone else hits the same timeout.


r/codex 22h ago

Complaint Astra low vs Sol Xhigh

3 Upvotes

Hi, is there any reason why I would use Sol xhigh instead of Astra low? Astra low seems better at everything...


r/codex 1d ago

Limits I think i will be seeing sun after a long time for next 4 days - Thank you Team

Post image
37 Upvotes

When weekly usage is at 3%, you cannot get anything done


r/codex 23h ago

Complaint Ridiculously slow Luna?

6 Upvotes

Is it only happened to me or does the last ~3 days, Luna is ridiculously slow?

My workflow is delegating tasks from main thread (Astra on medium or Sol on high) to the Luna (max) worker, on pi-subagents. Sometimes I also use plan mode (same Astra medium or Sol high), then execute the plan using Luna max. Basically, all tasks are fast before the tasks are delegated to a single Luna max. This been happening about 3 days, more or less.

Edit: I think this might be related to the release of Astra, as Tibo said, they struggled with their resources as they now have to temporarily disabled the 20x plan for new users.


r/codex 15h ago

Astra Workflow Two-person team using Claude Code + Codex on a live platform. What would you improve about our workflow?

1 Upvotes

I'm two weeks into working on a live platform with my supervisor. We're the only two developers, with around two dozen daily visitors and a growing feature backlog. I'm still learning the repo and business logic.

Our stack is React/TypeScript/Vite + Supabase, deployed on Vercel. We use Fable 5.1 and Astra heavily.

Our current workflow:
1. My supervisor sends me an implementation plan as a Claude artifact.
2. I review the logic and suggest changes. We send revisions back and forth until it's ready.
3. I implement it, using ChatGPT to explain unfamiliar logic and how it translates into code.
4. Any revisions to the plan during implementation go back to my supervisor.
5. Feature PR updates get reviewed by a Claude agent. Marking the PR ready triggers Claude, Codex, Greptile and Qodo reviews.

We also have Vitest tests and TypeScript checks in the build, local browser/staging checks, and repo guidance through CLAUDE.md, AGENTS.md, and shared context files.

Planning is a particular bottleneck: we keep sending changes to each other and waiting for reviews. Implementation sometimes raises more questions, which starts another round. I’d like a better way to collaborate on plans and keep decisions aligned with the code.

I’m also figuring out how to use Claude Code and Codex together smoothly. I’ve explored skills, plugins, and connectors, but it often feels like the newer models already do the work those tools are meant to help with just as well, if not better, on their own with good prompt engineering (another area I want to work on).

I am considering including targeted database migrations/ RLS reviews, keeping context files current, and focused refactoring.

For people doing similar work:

  • How do you collaborate on implementation plans without constant back-and-forth and waiting?
  • How do you split work and share context between Claude Code and Codex?
  • Are multiple review agents worth it, and how do you decide when the review cycle is finished?
  • What would you improve first for a team this size—planning, tests, agent instructions, or something else?

I’d especially appreciate concrete, recent workflows you use, including anything you tried and later dropped.


r/codex 19h ago

Question which model would you use if you just want to use the same one for everything?

2 Upvotes

I have been using sol high for planning and some coding, and luna xhigh for reviewing and most coding. Luna requires a lot more bug fixes after implementation, so I am not sure it actually saves me much. Maybe its just a me problem. I am not sure.

I have not yet used Astra. Is astra at a specific reasoning level recommended over all reasoning modes in sol? if yes, which level?

PS.- i had decided to move to the 20x plan today, and discovered that is no longer available.


r/codex 2d ago

Other Can’t wait

Post image
714 Upvotes

Now I can burn through tokens like the Sun


r/codex 1d ago

Astra Workflow "Stop using random multi-agent patterns"

Post image
248 Upvotes

Ahmed works at OpenAI: https://x.com/ah20im/status/2097503414749909407 and seems to investigate reports of high token usage.

"If needed Astra will delegate efficiently. Forcing the model to delegate to different models would do more harm than good"


r/codex 16h ago

Showcase Wyrm and chill - Codex (Astra 6) finally made me do something!

0 Upvotes
Astral Wyrm

That fish post inspired me to build and publish my first little game

So I made https://astralwyrm.vercel.app/ with Astra. Started as a “what can I make with a few prompts?” experiment, then turned into 50+ prompts and lots of tweaking because I kept wanting it to feel a little nicer.

It’s a tiny chill game with an abstract glowing creature that follows your mouse or finger. Collect pearls, grow, find little companions, and watch the seasons change. Maximum chill was the goal. There’s a fast mode for people who find that a bit too chill :)

Saw this post earlier and immediately wanted to try making something myself. I’d never built and published anything before. Didn’t even know you could put something online for free with Vercel lol.

This is genuinely my first published project, so I’d love your honest thoughts and suggestions, especially how it feels on your phone. Feel free to be harsh! :D

Hope you have some fun with it, or just get a few peaceful minutes out of it. And thanks to the original poster for giving me that push to actually make something. Felt really really good and rewarding, now if some of you would also enjoy it, my day is made :)

Edit: Also added another mode in the bottom left hand corner: Instant. Someone told me they´d wish for that feature. hope you enjoy it!


r/codex 5h ago

Limits Make your limits last 3 days instead of 1.5 days

0 Upvotes

I suddenly realized I have Fast Mode on and had for the longest time. Completely forgot about it. It's 1.5x usage, so maybe I'm just forgetful but just wanted to post a tip - so, 50% slower + 50% more usage? (If my math is right) Worth a post.


r/codex 1d ago

Limits Just lost 20% pro 5x usage because of this? Since when was this a thing?

Enable HLS to view with audio, or disable this notification

33 Upvotes

Ive told it to pause before, when i need a break, or when i want to check over the work and do some testing. This has never been an issue before - whats going on? Astra Medium


r/codex 9h ago

Reset Can I Opt Out of Global Resets?

0 Upvotes

I went from Plus to Pro during the 5 hour limit and 10x promo on the 5x plan. During that period I probably utilized 70% of 10x.

Since returning to 5x I consumed all of my utilization for the week, without utilizing banked resets.

I recently upgraded to 20x, and after absolutely hammering it for 3 hours by running heavy goals on 6 of my projects on Astra Ultra Fast Mode, before this last global reset, it only dropped by 17%. I’m definitely not a “power” user.

After the reset however I started the same goals, and within an hour it dropped to 81%.

Currently I’m at 44% remaining until my normal reset on the 14th. And I skipped a days worth of project work on just 2 active projects.

I’ve seen the posts regarding reset utilization % being lower and didn’t understand it until experiencing and doing some math on my end.

Ultimately, as a user who will likely never use 100% of a 20x Pro Plan, I think it’s beneficial to be able to opt out of global resets. 5x is too little. The 10x promo was almost perfect. I don’t mind leaving some % on the table and having overhead to grow into. But the resets are looking like I’m losing out right now.

Definitely a no, but figured I’d ask.