Android root module development made Codex flagged as cybersecurity

Resolved 💬 6 comments Opened May 18, 2026 by MicrosoftPro12 Closed May 18, 2026
💡 Likely answer: A maintainer (github-actions[bot], contributor) responded on this thread — see the highlighted reply below.

What version of Codex CLI is running?

v 0.130.0

What subscription do you have?

Plus/Free

Which model were you using?

gpt-5.5 xhigh

What platform is your computer?

Android 16

What terminal emulator and version are you using (if applicable)?

Termux, Codex in udocker with Ubuntu:22.04

Codex doctor report

What issue are you seeing?

I have seen "ⓘ This chat was flagged for possible cybersecurity risk" for 6+ times and I finally had enough and now I'm here.

What steps can reproduce the bug?

Uploaded thread: 019e15fb-756f-7941-bf59-87bb8617a6e3

In case you guys unable to receive this due to my network issue, here's the thing:
I'm currently working on a thing which is a module for Android rooting community.
Then I finally says: "You create a ssh key, so you can push things into my repo. And I don't have to manually download artifacts."
It works.
Test passed on running device (so that's why my running environment is Android).
Then I need to support it in older devices.
I use Termux on it, installed sshd.
Asked Codex to do debugging on it.
Then, bam. Flagged.
And now even pushing and confirming actions workflow also pops flagged message SO I FINALLY HAD ENOUGH and files an issue here.
Just, please, I'm working on several projects and really tired. I don't want to deal with this.

What is the expected behavior?

I donno, maybe just stop complaining about this.

Additional information

How is this being triggered while every step are so reasonable.

View original on GitHub ↗

6 Comments

github-actions[bot] contributor · 2 months ago

Potential duplicates detected. Please review them and close your issue if it is a duplicate.

  • #22043
  • #22988
  • #23220
  • #22554
  • #22568

Powered by Codex Action

MicrosoftPro12 · 2 months ago

I JUST DON'T UNDERSTAND SINCE THE SSH TARGET IS JUST 192.168.\.\ and github AND YOU GUYS FLAGGED AS "DOING CYBER THINGS".

Anyways, guess the possible checkpoints are

  • creating an SSH key for GitHub push/artifact workflow
  • SSHing into my own LAN Android/Termux test device
  • collecting pstore/crash logs after module load tests
  • checking GitHub Actions runs/artifacts (this is done via Python requesting to api.github.com)

But flagging these just made Codex hard to use
for legitimate Android modding work. Do I really need to copy log and artifact files for EVERY device?
Remember, I'm doing on MY devices.

etraut-openai contributor · 2 months ago

Please use /feedback to upload your session details. This will help us refine our cyber-risk classifier.

MicrosoftPro12 · 2 months ago
Please use /feedback to upload your session details. This will help us refine our cyber-risk classifier.

Err I do use /feedback. So plz check that session id.
If not there then guess is my udocker network issue. Notify me and I will try do feedback again.

etraut-openai contributor · 2 months ago

My bad — I missed the thread ID in your bug report above.

jyongchul · 2 months ago

Related affected account / thread for the same unresolved false-positive cyber-risk classifier problem.

cc @etraut-openai: you asked the reporter above for /feedback / thread details, and then noted that the thread ID in their report had been missed. I am adding our current affected thread details here because our own reports keep getting closed without a visible resolution explanation, while the problem is still actively blocking work.

Affected OpenAI / ChatGPT account: jyongchul@live.com

Current affected Codex thread/session ID:

019e39d4-e755-7cb0-9fbc-d255c92f85d0

Session metadata from the local Codex session log:

cwd: /home/charles/projects/Gov_Support_Automation
cli_version: 0.130.0
originator: codex-tui
source: cli
model_provider: openai
session timestamp: 2026-05-18T06:45:14.709Z
reproducing activity timestamp: 2026-05-18T23:38:55Z / 2026-05-19 08:38 KST

The false-positive warnings were still visible on 2026-05-19 Asia/Seoul during normal professional work in Gov_Support_Automation: checking project files, reviewing current changes, inspecting support/submission tracker files, and searching official government-support application IDs such as PBLN_000000000121663. This is authorized admin/development work on repositories and systems I own. It is not offensive security work.

Screenshots from 2026-05-19 showing the issue still active:

!2026-05-19 08:37 repeated cyber-risk warnings

!2026-05-19 08:43 repeated cyber-risk warnings

Prior related reports from this account:

The current support state is unacceptable for paid developer workflow: reports are being closed as duplicates, but there is no visible confirmation that the classifier problem has been resolved for the affected account, no explanation of why the reports were closed while the warnings still reproduce, and no concrete remediation path. Please review the thread ID above, confirm whether it was received through /feedback, and provide an official active tracking path rather than closing each report without a visible resolution.