False positive cybersecurity risk when fuzz testing my own library

Resolved 💬 2 comments Opened May 5, 2026 by eaftan Closed May 5, 2026

What version of Codex CLI is running?

codex-cli 0.128.0

What subscription do you have?

ChatGPT Pro

Which model were you using?

gpt-5.5 medium

What platform is your computer?

Linux 6.6.87.2-microsoft-standard-WSL2 x86_64 x86_64

What terminal emulator and version are you using (if applicable)?

Windows Terminal (WSL)

What issue are you seeing?

I am getting repeatedly "flagged for possible cybersecurity risk" while doing normal development work. In this case I am fuzzing my own regular expression library to find bugs, see https://github.com/eaftan/safere/tree/main/safere-fuzz. None of this is security related.

What steps can reproduce the bug?

Uploaded thread: 019df63a-e6ca-75d1-b900-ff247506d8df

What is the expected behavior?

Shouldn't be flagged for cybersecurity risk

Additional information

_No response_

View original on GitHub ↗

This issue has 2 comments on GitHub. Read the full discussion on GitHub ↗