False-positive cybersecurity risk verification triggered in Codex with GPT-5.5

Resolved 💬 2 comments Opened May 5, 2026 by zyb1031 Closed May 5, 2026

What version of the IDE extension are you using?

Codex IDE extension v26.429.30905

What subscription do you have?

ChatGPT Pro

Which IDE are you using?

VS Code

What platform is your computer?

_No response_

What issue are you seeing?

Codex in the IDE extension is repeatedly showing a possible cybersecurity risk verification message when I use GPT-5.5 for normal development work.

The message shown is:

This content was flagged for possible cybersecurity risk. If this seems wrong, try rephrasing your request. To get authorized for security work, join the Trusted Access for Cyber program: https://chatgpt.com/cyber

I believe this is a false positive.

Context:

  • I am an individual user.
  • I am working on my own authorized project/repository.
  • The task is normal software development / defensive maintenance.
  • I am not asking Codex to exploit a system, steal credentials, bypass authentication, create malware, perform phishing, establish persistence, evade detection, or access anything unauthorized.

I submitted feedback through /feedback and received this feedback/thread ID:

019df5d7-570a-78e0-b1bf-114623434cf1

The issue seems specific to using GPT-5.5/Codex. The same or similar coding task does not appear to be malicious, but it triggers the verification warning.

What steps can reproduce the bug?

Uploaded thread: 019df5d7-570a-78e0-b1bf-114623434cf1

  1. Open the Codex IDE extension.
  2. Select GPT-5.5 as the model.
  3. Open my own authorized project/repository.
  4. Ask Codex to help with a normal coding task.

What is the expected behavior?

Codex should treat this as a normal authorized coding/debugging task, or provide a more specific explanation of what part of the request triggered the cybersecurity safety check.

If the classifier believes the request is risky, it would be helpful to show actionable guidance so I can rephrase the task without losing normal coding assistance.

Additional information

  • Feedback/thread ID from /feedback: 019df5d7-570a-78e0-b1bf-114623434cf1
  • I am an individual user.
  • This happened while using GPT-5.5 in Codex.
  • The project/repository is my own authorized codebase.
  • No offensive security, malware, credential theft, phishing, evasion, persistence, or unauthorized access was requested.
  • Please let me know if there is a better place to report false-positive cyber-safety flags for individual Codex users.

View original on GitHub ↗

This issue has 2 comments on GitHub. Read the full discussion on GitHub ↗