False positive: account flagged for cyber activity and routed to gpt-5.2
I understand this issue may be considered a duplicate, but I am submitting it because I have no visibility into whether cases like mine are actually reviewed unless explicitly reported.
I am the founder and technical lead of a small startup (currently the only engineer). I was setting up an Ubuntu server development environment for a new team member and working on routine backend integration tasks.
During that process, I discussed Feishu-related token handling in Codex. It appears that the term “token” may have triggered an automated risk classification. However, as the conversation progressed, Codex itself clarified the misunderstanding — I was referring to an internal project token used within my own system, not any official Feishu API credential or external service token.
Shortly afterward, my account was flagged and my access was restricted.
I have uploaded the rollout of the relevant session. The content clearly reflects what I described above. After reviewing it, I believe this restriction is the result of an obvious false positive.
There was no attempt to bypass safeguards, relay credentials, or misuse any service. This was standard backend development work.
Session ID:
019c70a5-e905-7ad2-b42d-b44bebe3d52d
I expect this case to be reviewed based on the actual content of the session.
This issue has 2 comments on GitHub. Read the full discussion on GitHub ↗