False positive: Codex cyber-safety flag during normal UI/dev work
Resolved 💬 3 comments Opened Feb 18, 2026 by locotoki Closed Feb 20, 2026
- What happened: Codex showed the “flagged for potentially high-risk cyber activity” warning and routed me to gpt-5.2
fallback.
- When: 2026-02-18 (include approximate time + timezone).
- Where: Codex session on Ubuntu/WSL; workspace root /home/locot/projects.
- What I was doing (legit): Frontend/product work for internal repos: control-plane, ai-agency/apps/adp, openclaw_setup
(ADP UI completeness: task detail timeline/artifacts, agent registry view, repo/adapter health panel).
- What I was NOT doing: No pentesting, scanning, exploitation, malware, credential harvesting, or instructions to break
into systems.
- Exact prompt(s): Paste the prompt that immediately preceded the warning (and 1–2 prior prompts if relevant).
- Repro steps: “Start Codex session → run <command> / ask <prompt> → warning appears.”
- Attachments: Screenshot of the banner; any request/conversation IDs shown in the UI.
Example description (short)
“On 2026-02-18 (ET), in a Codex session on Ubuntu/WSL with cwd /home/locot/projects, I received the ‘potentially high-risk
cyber activity’ banner and was routed to GPT-5.2. I was only doing normal product dev: verifying ADP UI routes and
implementing control-plane dashboard views (task timeline/artifacts, agent registry heartbeats, repo health panel) in
control-plane, ai-agency/apps/adp, and openclaw_setup. No security testing or malicious content. Triggering prompt:
<paste>.”
This issue has 3 comments on GitHub. Read the full discussion on GitHub ↗