Codex Security is OpenAI's application security agent: scans from the Security workbench, the @openai/codex-security CLI and SDK, and cloud, plus Security Review on GitHub pull requests, per OpenAI's docs.
Codex Security runs security and deep scans from the Security workbench, bulk and CI scans through the @openai/codex-security CLI and SDK, and cloud scans of connected GitHub repositories commit by commit (cloud in research preview); its Security Review adds a security-focused PR review (research preview, as of September 7, 2026), per OpenAI's docs. Aevral is built for a reading of its own: does this diff widen who has access to what. Both read pull requests for security: Codex Security with its reviews, and Aevral's PR review, live and opt-in, on the same pull request.
Codex Security focuses on
Aevral adds alongside
Let Codex Security run OpenAI's scans and Security Review; let Aevral add the authorization and business-logic reading of the same pull requests, with the opt-in add-on.
Codex Security and Aevral, in depth; Aevral PR security review.
Also alongside
One GitHub App. A report with evidence. A prompt for the agent you already use.