“@openai/codex-security is a CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in your code.”
The pitch is scan, validate, fix, and wire it into CI. The validate step is the interesting part, because a scanner that buries teams in false positives is worse than no scanner. Access requires Codex Security, so the open repo is the client and the product is still the subscription. Whether it beats the static analyzers you already ignore is an empirical question nobody has answered yet.