Codex feedback: false positive cyber mitigation despite Trusted Access verification

Resolved 💬 1 comment Opened Apr 24, 2026 by EGONHOO Closed Apr 24, 2026

What version of Codex CLI is running?

codex-cli 0.124.0

What subscription do you have?

ChatGPT Pro 5x

Which model were you using?

gpt-5.5

What platform is your computer?

Microsoft Windows NT 10.0.26200.0 x64

What terminal emulator and version are you using (if applicable)?

Windows Terminal(PowerShell)

What issue are you seeing?

Summary
My Codex account is still being flagged for potentially high-risk cyber activity even though I have already completed Trusted Access verification at https://chatgpt.com/cyber.

Codex shows this message:

Your account was flagged for potentially high-risk cyber activity. Requests may be slower while additional verification is applied. To regain faster access, apply for trusted access: https://chatgpt.com/cyber or learn more: https://developers.openai.com/codex/concepts/cyber-safety

The linked Trusted Access page says I am already verified.

Related account state issue
Before re-login, Codex also incorrectly showed a "Get Plus" prompt even though my account is already on ChatGPT Pro 5x.

After fully signing out and signing back in, the "Get Plus" prompt disappeared, which suggests Codex had stale or incomplete account entitlement state. However, the cyber mitigation message still appears after re-login.

Expected behavior
Because the account is already Trusted Access verified, Codex should recognize the verification state and should not continue prompting me to apply for Trusted Access to regain faster access.

Actual behavior
Codex still displays the high-risk cyber activity warning and says additional verification is being applied.

Context
The triggering workflow is defensive and authorized bug bounty workflow management for my local BountyRecon project. The task was to organize and prioritize candidate programs/targets for later manual review, not to perform unauthorized access, exploitation, malware work, credential theft, or live scanning.

DailyReview workflows in the same project did not trigger this warning. The warning appeared when working on candidate target/program triage.

Request
Please check whether my Trusted Access verification state is correctly linked to Codex, and whether this account-level cyber mitigation flag is a false positive.

Useful references:

Trusted Access page: https://chatgpt.com/cyber
Codex cyber safety page: https://developers.openai.com/codex/concepts/cyber-safety
Attachments/screenshots available:

Screenshot showing cyber warning in ChatGPT/Codex
Screenshot showing https://chatgpt.com/cyber says verified
Screenshot showing Codex previously displayed "Get Plus" despite Pro 5x
Evidence checklist
Included in this report:

<img width="636" height="103" alt="Image" src="https://github.com/user-attachments/assets/fdfd9cf8-292a-47e7-9e15-4da3d3568596" />
<img width="2560" height="1392" alt="Image" src="https://github.com/user-attachments/assets/e4f3462b-50ba-4747-8637-95b1770e5499" />

Affected thread ID: 019dbe98-2cb4-7740-a125-0aa082be20e5
Uploaded feedback logs thread ID: 019dbe9e-cede-7483-99f0-dc2644d8b200
Exact warning text shown by Codex
Confirmation that the Trusted Access page says the account is already verified
Confirmation that re-login fixed the stale "Get Plus" subscription prompt
Confirmation that the cyber warning still appears after re-login
Codex CLI version: codex-cli 0.124.0
High-level description of the triggering workflow

What steps can reproduce the bug?

Your account was flagged for potentially high-risk cyber activity. Requests may be slower while additional verification is applied. To regain faster access, apply for trusted access: https://chatgpt.com/cyber or learn more: https://developers.openai.com/codex/concepts/cyber-safety

The linked Trusted Access page says I am already verified.

<img width="1081" height="124" alt="Image" src="https://github.com/user-attachments/assets/e7a987e7-b572-4c37-b9db-9542cb428585" />

What is the expected behavior?

The triggering workflow is defensive and authorized bug bounty workflow management for my local BountyRecon project. The task was to organize and prioritize candidate programs/targets for later manual review, not to perform unauthorized access, exploitation, malware work, credential theft, or live scanning.

This project is a tool for passively scanning for HackerOne-licensed bounties, and all actions are strictly within the scope of the rules.

DailyReview workflows in the same project did not trigger this warning. The warning appeared when working on candidate target/program triage.

Additional information

_No response_

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗