False positive cybersecurity-risk warning during benign consulting-documentation project work
What version of Codex CLI is running?
0.128.0
What subscription do you have?
Pro
Which model were you using?
gpt-5.5
What platform is your computer?
Windows 10 x64
What terminal emulator and version are you using (if applicable)?
PowerShell
What issue are you seeing?
Codex showed the warning:
“Your conversations have multiple flags for possible cybersecurity risk. Responses may take longer because extra safety checks are on. To get authorized for security work, join the Trusted Access for Cyber program.”
This happened in a benign consulting-documentation project. The task was ordinary authorized work with my own project files: moving some folders to another local disk with more free space and preparing a monthly report about the project.
The conversation was about document management, project organization, local file operations, and project reporting. It was not a cybersecurity conversation and did not involve penetration testing, exploitation, malware, credential access, network scanning, unauthorized systems, evasion, or security research.
The warning appears unrelated to the actual task and looks like a false positive, possibly caused by broad account-level or multi-conversation flagging.
What steps can reproduce the bug?
Uploaded thread: 019e036f-838d-7b12-8874-ea0887e90837
- Open or continue a Codex conversation for a consulting-documentation project.
- Ask Codex to help with ordinary authorized project maintenance, such as moving some project folders to another local disk with more free space.
- Ask Codex to prepare a monthly project report based on the project work.
- Observe that Codex shows the cybersecurity-risk warning even though the task is normal document-management and project-reporting work, not cybersecurity work.
What is the expected behavior?
Codex should not show cybersecurity-risk warnings or apply extra cyber-safety latency to ordinary authorized work with local project folders, consulting documentation, file organization, and monthly project reports.
If a safety warning is shown, it should be tied to a specific current request and should distinguish normal local file/document management from cybersecurity activity.
Additional information
This is another example of the same persistent false positive pattern. Similar warnings have also appeared in unrelated benign conversations, including business/game-design documentation and work-log/lab-journal prompts.
In this case, the relevant context was consulting documentation, local disk space, folder movement, and monthly project reporting. These are normal project-management and document-management activities.
The issue causes unnecessary latency and makes Codex harder to use for routine authorized work. Please review the flag, recalibrate the classifier, and avoid treating benign file-management, reporting, logging, or project-organization terminology as cybersecurity risk by itself.
This issue has 2 comments on GitHub. Read the full discussion on GitHub ↗