OpenAI Codex and security: risks to verify in code generated by agents
OpenAI Codex is not just a static language model; it is the engine powering a new generation of coding agents capable of operating directly on repositories, planning multi-file changes, and proposing entire Pull Requests (PRs). When a Codex-based agent is tasked with “implementing a new module” or “refactoring session management,” the primary risk shifts from the isolated snippet to the logical integrity of the entire system.
The central problem with Codex-based agents is not syntactic correctness (which is often excellent), but “Excessive Agency”: the agent’s ability to make broad and plausible changes that exceed established trust boundaries, introducing silent vulnerabilities in authorization flows, data handling, or deployment configurations.
In summary: this article analyzes the specific risks of Codex-based agents and provides a validation protocol for automatically generated Pull Requests to ensure that AI autonomy does not compromise the security of the final product.
Protect your organisation with Code Review.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
Do not miss the best of cybersecurity.
Weekly expert analysis, real attacks and practical solutions in one newsletter.
Subscribe to Cyber WeeklyOperational delegation: broad Pull Requests and misleading tests
A coding agent can execute complex tasks in sandbox environments, but the final result must be integrated into a real repository that handles real data and users. This transition introduces critical risks:
- Broad and opaque Pull Requests: The agent can produce diffs that touch dozens of files simultaneously. Human review tends to suffer from fatigue when faced with such extensive changes, leading to the bulk acceptance of modifications that might contain security bypasses or “invisible” logical regressions.
- Test-only validation (Auto-validation): The agent can generate code that “passes the tests” simply because it updated or rewrote the tests themselves to reflect the new behavior. This can hide the removal of essential security controls that the agent considered “impediments” to completing the task.
- Incorrect assumptions about business context: Even if the agent has access to the codebase, it may misunderstand unwritten authorization policies or architectural constraints, proposing solutions that are functional but vulnerable (e.g., BOLA/IDOR) because they are based on a superficial interpretation of user roles.
Specific risks in Codex-based agents
AGENTS.md instructions and project rules
If the instructions provided to the agent (e.g., via AGENTS.md files) are incomplete or permissive, the agent might systematically adopt insecure patterns. It is essential to use these files to impose strict constraints: the obligation to use validated middleware, the prohibition of direct queries, and centralized secret management.
Context exposure and intellectual property leaks
During repository analysis, the agent might include sensitive files, private keys, or comments containing credentials in the context sent to the models. Without proper exclusion filters, the agent’s “reasoning” can unintentionally expose your intellectual property or corporate secrets to the AI vendor.
Dependency manipulation and Supply Chain
In an attempt to fix a bug or implement a feature, the agent might suggest adding new libraries or modifying lock files (package-lock.json). Without a manual review of the suggested package, it is easy to introduce silent supply chain risks or unmaintained dependencies.
Permission bypass and logical Sandbox Escape
Even if the agent operates in a sandbox during development, the code it generates for production might contain instructions to bypass controls or expose unprotected administrative interfaces, based on the false assumption that the sandbox isolation is also present in the real production environment.
Validation checklist for Codex-generated PRs
- Action Plan Review: Before looking at the code, has the plan followed by the agent been validated? Does it respect the project’s security constraints?
- Negative Test Verification (Abuse cases): Have tests been added that verify failure (e.g., an unauthorized user is blocked)?
- Dependency Audit: Have new packages been added? Are the suggested libraries reliable and up-to-date?
- Trust Boundary Analysis: Do the changes touch authentication middleware, authorization policies, or database connections?
- Secret Scanning: Has a scan been performed to ensure no secrets were pasted or generated in the code?
When professional independent verification is needed
When a Codex agent has autonomy over large portions of code, security responsibility cannot be entirely delegated to automated tools. External verification is necessary to ensure that the agent has not introduced logical or architectural flaws.
| Operational Scenario | Primary Risk | Recommended ISGroup Service |
|---|---|---|
| Agent-generated PRs | Logical regressions, auth bypass | Code Review |
| AI-generated new APIs | BOLA, IDOR, Injection | WAPT |
| AI-modified architecture | Incorrect security assumptions | Secure Architecture Review |
| AI Coding Governance | Lack of secure processes | Software Assurance Lifecycle |
FAQ
- Is code that passes automated tests secure?
- No. Automated tests demonstrate functionality (“it does what it should”). They do not demonstrate security (“it does not do what it shouldn’t”), especially regarding authorizations and logical abuses.
- How can I limit the autonomy of a Codex agent?
- By using
AGENTS.mdfiles with strict rules, limiting accessible files, and requiring explicit human approval for every shell command or structural change. - Can Codex find and fix vulnerabilities?
- It can identify known patterns, but its fixes must be validated: an incorrect suggestion might resolve a superficial bug but introduce a deeper logical vulnerability.
Protect your organisation with Code Review.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
Do not miss the best of cybersecurity.
Weekly expert analysis, real attacks and practical solutions in one newsletter.
Subscribe to Cyber Weekly