5 ms·
Hey looks cool. I tried to run this on a small oss library and here's what happened: $ codex-security scan . [00:00] Preparing scan [00:00] Authenticatio
by ryanto 2mo ago
Hey looks cool. I tried to run this on a small oss library and here's what happened:
$ codex-security scan .
[00:00] Preparing scan
[00:00] Authentication: stored Codex credentials.
[00:01] Preparing scan
[00:42] Running scan
[00:42] Preflight: worker delegation supported (up to 8 worker slots).
[41:03] Running scan
codex-security: This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber
codex-security: Partial output was kept at /Users/ryan/.codex/state/plugins/codex-security/scans/framework/codex-security-framework-z7eNfr.
Just some feedback, but it ran for over 40 minutes and during that time I had no idea what was happening, thought it was frozen or in a bad state. Also, it ate through 25% of my weekly credits :(
- M4v3R 2mo agoSame thing happened to me. The partial output did contain some useful signal but I was disappointed to see it didn’t finish.
- jbstack 2mo agoIt halts and refuses to carry on after finding a security risk, which is exactly what it's supposed to do? What's the point of it then?
- maxloh 2mo agoIMHO, tokens should be refunded if the agent refuses to work. Charging users for a session that produced no final output is ridiculous.
- ryanto 2mo agooh i'm not worried about it. they have been so generous with the resets these last few weeks.
- matheusmoreira 2mo agoI was going to switch to OpenAI and away from Anthropic because of "safety" nonsense like this. Really disappointed to discover it's just gonna be more of the same. Looks like Chinese models are the only ones without any of this safety bullshit.
- realusername 2mo agoI've switched to Kimi personally and it has way less guard nonsense like this.
- ryanto 2mo agoyou should give openai a try. ive been really happy with them these last few weeks
- ramigb 2mo agoSame happened to me. Very disappointing, this should be mentioned before the user even authenticates in the onboarding phase of the product asking the user if they have acquired the whitelisting from OpenAI and want to proceed or not! But running for 35+ minutes plus to give such a response is very disappointing and very awkward! Not to mention the lost weekly tokens!