False positive cyber-safety routing. gpt-5.3-codex usage

Resolved 💬 2 comments Opened Feb 18, 2026 by Daimon04 Closed Feb 20, 2026

Context: I’m a software engineer using Codex CLI for legitimate development work. I ran the ai-factory skill ($ai-factory) from https://github.com/lee-to/ai-factory on a work repository to generate project tasks/docs.

What happened: After running $ai-factory, every Codex CLI request shows:
"Your account was flagged for potentially high-risk cyber activity and this request was routed to gpt-5.2 as a fallback..."

I did not request or perform offensive security, exploitation, malware, phishing, credential theft, or any unauthorized scanning. This was a defensive/engineering workflow (project automation / codebase review). Please review and remove the flag or advise what to change to avoid triggering it.

Time (local): 2026-02-18 16:25 (MSK)
Environment: codex-cli on macOS
Repo type: internal work repo (can’t share code)
Skill invoked: $ai-factory

Thread: 019c70f2-2ee8-7bc0-a256-cb17638af079

View original on GitHub ↗

This issue has 2 comments on GitHub. Read the full discussion on GitHub ↗