Security review for the pull requests Codex Cloud tasks produce.
Codex Cloud runs the task in its own workspace while your computer is asleep, and a human commits or opens the pull request when the work is ready. Aevral, the AI security reviewer for GitHub pull requests, reviews the diff within your plan's review allowance and hands the reviewer a copy-paste fix prompt with each finding.
In plain words
Picture handing a task to a colleague who works in a room set up from your repository, keeps going after you close the laptop, and reports back with changed files, test results, and a proposal. That is the shape of a Codex Cloud task. This page is about the pull request that work becomes, and who reads it for security before it merges.
How a Codex Cloud task becomes a pull request
From OpenAI's own documentation. Each line is in our words, with the quote it rests on underneath.
A cloud environment starts from the repositories you choose: you connect GitHub, and Codex inspects your repositories, installs dependencies and tools, and tests the workflow.
“Choose your GitHub repositories and select Get started. Connect GitHub if prompted. Codex inspects your repositories, installs dependencies and tools, and tests the workflow.”
Codex Cloud docs, getting started (prepare your project), read
Each task has its own workspace and can keep working while your computer is asleep.
“Each task has its own workspace and can keep working while your computer is asleep.”
You review changes and continue from the web, mobile, or desktop app.
“Review changes and continue from the web, mobile, or desktop app.”
In the task you inspect changed files and check results, request follow-up changes, and commit or open a pull request when ready.
“Inspect changed files and check results, request follow-up changes, and commit or open a pull request when you're ready.”
Codex Cloud docs, why use Codex Cloud (review the work), read
The other ways to run Codex
Codex also runs in the terminal: it inspects code, makes changes, runs commands, and automates repeatable work without leaving the terminal.
“Inspect code, make changes, run commands, and automate repeatable work without leaving your terminal.”
Codex code review is its own mode: it reviews the pull request diff and posts a standard GitHub code review focused on serious issues.
“Codex reviews the pull request diff, follows your repository guidance, and posts a standard GitHub code review focused on serious issues.”
Security Review, available in research preview, is a deeper review of potential security issues in a pull request.
“Security Review, available in research preview, provides a more in-depth review of potential security issues in a pull request.”
Review GitHub pull requests with Codex (Security Review), read
There is also a Codex GitHub Action: its sample workflow reviews new pull requests and posts the response back on the PR.
“The sample workflow below reviews new pull requests, captures Codex's response, and posts it back on the PR.”
Why it matters: watching the task is not reading the diff
Codex Cloud moves the work off your machine: the task runs in its own workspace and keeps going while your computer is asleep. The person who started it inspects changed files and test results on the task page, then commits or opens the pull request. That pull request is where the change meets your repository's own reviewers and merge rules. Aevral reviews it when it is opened and when new commits are pushed, looking for access control, business logic and injection problems among its classes, and leaves at most two findings, each a lead with evidence rather than a verdict.
The environment carries over between tasks: repositories, dependencies, and tools are the reusable setup, and each new task gets its own isolated workspace from it. That reuse concentrates the security question in the diff: what this task changed about access, which roles can now call a route, what a tenant can read. A finding from Aevral sits on the added line with a fix prompt a human copies back to Codex, in the cloud task or in the terminal.
What the vendor's docs say
Reuse your repositories, dependencies, and tools across tasks; update the setup as the project changes.
“Reuse your repositories, dependencies, and tools across tasks. Each task has its own workspace. Update the setup as your project changes.”
Codex Cloud docs, next steps (reuse your project setup), read
Each new task gets its own isolated workspace from the published environment.
“Each new task gets its own isolated workspace from the published environment.”
Where Aevral fits: a copy-paste handoff
Aevral reviews a Codex Cloud pull request like any other pull request on a repository where the Aevral GitHub App is installed: when it is opened or reopened and when new commits are pushed, within your plan's review allowance. A finding is an inline comment on the added line, next to an advisory Check that never blocks the pull request.
Each finding carries a Fix with your agent prompt. To hand it back, a human copies the prompt and gives Codex the follow-up, in the cloud task or in the terminal, and reviews the diff it proposes. Whatever Codex pushes back to GitHub is reviewed again when it reaches a pull request, and your repository's own review and merge rules decide what ships.
How the prompt is built and how to use it well: handing a finding to your coding agent.
Setup, the two human clicks
Two clicks, both yours: install the GitHub App, then log in to the console with GitHub. An agent cannot install the App or finish the login for you; it can read this page and the agent-setup prompt instead.
- Install the GitHub App: https://github.com/apps/aevral
- Log in to the console: https://app.aevral.com/login
- Official agent-setup prompt: https://docs.aevral.com/agent-setup/prompt.md
What this page does not claim
- Aevral is not affiliated with, endorsed by, or a partner of the company behind Codex Cloud. There is no integration between the two products: Aevral does not call Codex Cloud, and Codex Cloud does not call Aevral.
- Aevral never commits, pushes, applies or merges a change. The Fix with your agent prompt is text a human copies; what the agent does with it goes through your repository's own review and merge rules.
- PR review looks for a list of classes on the diff and leaves at most two findings per review. A finding is a lead with evidence, not a verdict, and a quiet review is not proof that the code is safe.
- The boxed statements about Codex Cloud come from the vendor's own documentation, each with the quote it rests on and the date it was read. The paragraphs around them are Aevral's reading of what those facts mean for a security review. Vendor products change; the vendor's docs win over this page.
- This page does not say Codex Cloud opens the pull request by itself: the docs describe inspecting the work and committing or opening a pull request when you are ready.
- Aevral does not start Codex Cloud tasks, create or publish environments, or read the task page.
Sources
Read next