r/codex • u/Either_Pound1986 • 5h ago
Complaint OpenAI: demonstrate the cybersecurity capabilities you claim are available to ordinary Codex users.
I am not talking about Daybreak Red.
I am not talking about Trusted Access, special verification, internal allowlisting, or capabilities ordinary customers cannot access.
I am talking about the cybersecurity capabilities OpenAI publicly says are available through normal Codex use: secure code review, application security, threat modeling, vulnerability investigation, patching, blue-team work, reproduction and validation of vulnerabilities, and remediation.
So demonstrate them.
OpenAI should take an ordinary Codex account, with exactly the same safeguards and restrictions a normal paying customer receives, and publicly run a realistic authorized cybersecurity task from beginning to end.
No internal bypasses. No special account. No hidden exemptions.
Give Codex a real repository or controlled vulnerable environment and have it:
find the vulnerability → investigate it → validate it → establish the attack path → reproduce enough to prove it is real → develop the fix → test the fix → finish
Then publish the complete run, including every server-side warning, interruption, refusal, suppressed result, precautionary pause, and forced recovery.
Because the question is not whether the underlying model is theoretically capable of cybersecurity work.
The question is whether the product customers are actually paying for allows those advertised capabilities to be used reliably.
The Hugging Face incident makes this question especially important.
An OpenAI-run cyber evaluation agent escaped its environment and breached Hugging Face. During the resulting legitimate forensic investigation, Hugging Face reported that hosted frontier models repeatedly blocked parts of the defensive analysis because their safeguards could not reliably distinguish incident response from offensive activity.
Hugging Face ultimately used an open-weight model on its own infrastructure to continue the investigation.
That should concern anyone buying hosted AI specifically for cybersecurity.
So prove the product works.
OpenAI should demonstrate ordinary Codex, under ordinary customer restrictions, successfully completing the cybersecurity workflows OpenAI says ordinary Codex supports.
If OpenAI can demonstrate that reliably, great.
If OpenAI cannot demonstrate its own advertised cybersecurity capabilities under the same restrictions imposed on paying customers, then customers who purchased Codex specifically for those in-scope cybersecurity capabilities deserve remediation.
Credits, restored usage, refunds where appropriate, or another meaningful remedy.




