OpenAI’s Codex app is being framed as a step toward more autonomous work on the computer, but the real story is governance: once an AI can touch files, shell commands, browsers, and local apps, control becomes the product.
A seemingly useful npm package for OpenAI Codex became a supply-chain trap, showing how developer convenience can double as credential exposure.
Codex is being pushed beyond a cloud coding helper into a broader workstation-style agent, and that shift turns permissions, browser access, and human approval into the real security story.
A new credential model for OpenAI Codex spotlights a bigger security shift: coding agents should borrow access for a task, not keep secrets in their memory.
OpenAI’s Codex Security agent has flagged over 10,000 high-severity vulnerabilities in a sweeping scan of software repositories, raising questions about the future of automated cyber defense.