Android root module development made Codex flagged as cybersecurity
What version of Codex CLI is running?
v 0.130.0
What subscription do you have?
Plus/Free
Which model were you using?
gpt-5.5 xhigh
What platform is your computer?
Android 16
What terminal emulator and version are you using (if applicable)?
Termux, Codex in udocker with Ubuntu:22.04
Codex doctor report
What issue are you seeing?
I have seen "ⓘ This chat was flagged for possible cybersecurity risk" for 6+ times and I finally had enough and now I'm here.
What steps can reproduce the bug?
Uploaded thread: 019e15fb-756f-7941-bf59-87bb8617a6e3
In case you guys unable to receive this due to my network issue, here's the thing:
I'm currently working on a thing which is a module for Android rooting community.
Then I finally says: "You create a ssh key, so you can push things into my repo. And I don't have to manually download artifacts."
It works.
Test passed on running device (so that's why my running environment is Android).
Then I need to support it in older devices.
I use Termux on it, installed sshd.
Asked Codex to do debugging on it.
Then, bam. Flagged.
And now even pushing and confirming actions workflow also pops flagged message SO I FINALLY HAD ENOUGH and files an issue here.
Just, please, I'm working on several projects and really tired. I don't want to deal with this.
What is the expected behavior?
I donno, maybe just stop complaining about this.
Additional information
How is this being triggered while every step are so reasonable.
6 Comments
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action
I JUST DON'T UNDERSTAND SINCE THE SSH TARGET IS JUST 192.168.\.\ and github AND YOU GUYS FLAGGED AS "DOING CYBER THINGS".
Anyways, guess the possible checkpoints are
But flagging these just made Codex hard to use
for legitimate Android modding work. Do I really need to copy log and artifact files for EVERY device?
Remember, I'm doing on MY devices.
Please use
/feedbackto upload your session details. This will help us refine our cyber-risk classifier.Err I do use /feedback. So plz check that session id.
If not there then guess is my udocker network issue. Notify me and I will try do feedback again.
My bad — I missed the thread ID in your bug report above.
Related affected account / thread for the same unresolved false-positive cyber-risk classifier problem.
cc @etraut-openai: you asked the reporter above for
/feedback/ thread details, and then noted that the thread ID in their report had been missed. I am adding our current affected thread details here because our own reports keep getting closed without a visible resolution explanation, while the problem is still actively blocking work.Affected OpenAI / ChatGPT account:
jyongchul@live.comCurrent affected Codex thread/session ID:
Session metadata from the local Codex session log:
The false-positive warnings were still visible on 2026-05-19 Asia/Seoul during normal professional work in
Gov_Support_Automation: checking project files, reviewing current changes, inspecting support/submission tracker files, and searching official government-support application IDs such asPBLN_000000000121663. This is authorized admin/development work on repositories and systems I own. It is not offensive security work.Screenshots from 2026-05-19 showing the issue still active:
!2026-05-19 08:37 repeated cyber-risk warnings
!2026-05-19 08:43 repeated cyber-risk warnings
Prior related reports from this account:
The current support state is unacceptable for paid developer workflow: reports are being closed as duplicates, but there is no visible confirmation that the classifier problem has been resolved for the affected account, no explanation of why the reports were closed while the warnings still reproduce, and no concrete remediation path. Please review the thread ID above, confirm whether it was received through
/feedback, and provide an official active tracking path rather than closing each report without a visible resolution.